# Privacy Policy **Effective Date:** 2026-05-24 **Contact:** legal@leeworks.dev --- ## 1. Overview leeworks.dev ("we", "us") operates the ZIP Enrichment, Holidays, and Air Quality APIs. This Privacy Policy describes what data we collect when you use our Services, how we use it, and your rights regarding that data. ## 2. What Data We Collect ### 2.1 Request Logs When you make API calls, we log: - API key identifier (hashed/truncated — not the full key) - IP address of the requesting client - HTTP method and endpoint path - Response status code - Request timestamp - Response time (latency) **We do not log the full content of request or response bodies unless required for debugging.** ### 2.2 Account Data (via RapidAPI) If you subscribe through RapidAPI, your account data (name, email, billing information) is managed by RapidAPI, not by us. Please review [RapidAPI's Privacy Policy](https://rapidapi.com/privacy/). ### 2.3 Cookies and Tracking The API endpoints themselves do not use cookies. Our documentation site (`docs.leeworks.dev`) may use minimal session cookies for navigation only — no analytics or tracking cookies. ## 3. How We Use Your Data We use collected data to: - Monitor API health and uptime - Detect and prevent abuse (rate limit evasion, scraping) - Debug issues and improve service reliability - Generate aggregate usage statistics (anonymized) - Respond to support requests **We do not sell your personal data to third parties. Ever.** ## 4. Data Retention | Data Type | Retention Period | |-----------|-----------------| | Request logs (IP + endpoint) | 90 days | | Aggregated usage metrics | 12 months | | Billing records (via RapidAPI) | Per RapidAPI policy | After the retention period, logs are automatically deleted. ## 5. Data Sharing We share data only in the following circumstances: - **With RapidAPI**: billing and subscription management - **Legal requirements**: if required by law, court order, or government request - **Service providers**: hosting infrastructure providers (under data processing agreements) We do not share raw request logs with any third parties. ## 6. Security We take reasonable technical and organizational measures to protect your data: - API keys are transmitted over HTTPS only - Access to log storage is restricted to authorized personnel - Our cluster uses Kubernetes RBAC and network policies However, no system is 100% secure. If you discover a security vulnerability, please report it to legal@leeworks.dev. ## 7. Your Rights Depending on your jurisdiction, you may have rights to: - Access the personal data we hold about you - Request deletion of your data - Object to or restrict processing To exercise these rights, contact us at legal@leeworks.dev. We will respond within 30 days. ## 8. Children's Privacy Our Services are not directed at children under 13. We do not knowingly collect data from children. If you believe a child has submitted data, contact us and we will delete it promptly. ## 9. International Transfers Our services are hosted in the United States. By using the Services, you consent to the transfer and processing of your data in the US. ## 10. Changes to This Policy We may update this Privacy Policy periodically. We will notify users of material changes by updating the effective date above and posting a notice. Continued use of the Services after changes constitutes acceptance. ## 11. Contact For privacy inquiries: **legal@leeworks.dev**