Last updated: September 30, 2026
Privacy Policy
This policy explains what data AxioAPI (axioapi.com) collects when you use the website, the API and the Telegram bot, why we collect it, and the rights you have over it.
1. Data we collect
- Account details: display name, email address, password (stored only as a hash) and email verification status.
- Sign in with Google: your email address, whether it is verified, and the display name from your Google profile. We never receive your Google password.
- Telegram: if you use the bot, we store your Telegram ID, username and language to link your account.
- API usage: time of each call, endpoint, status code, latency, credits charged, IP address and request ID.
- Payments: amount, plan or pack purchased, transaction ID and the status returned by the payment gateway. Card, bank account and crypto wallet details are handled directly by PayPal, payOS or PayerScan; we do not store them.
- Security: two-factor authentication (TOTP) secrets and recovery codes, stored encrypted.
- Cookies: only the session cookie and the CSRF protection cookie needed to keep you signed in. We do not use advertising cookies.
2. How we use it
- To create and manage your account and authenticate sign-ins.
- To provide the API, enforce plan limits, and calculate and charge credits.
- To show you your own request logs and usage statistics.
- To send transactional email: account verification, payment confirmations, security and balance alerts.
- To detect and prevent fraud and abuse.
We do not sell personal data and do not use your data for advertising.
3. Data from Google
When you choose “Continue with Google”, AxioAPI requests only the openid, email and profile scopes. The information received is used only to create your account or sign you in to the account with the same email. We do not access Gmail, Drive, contacts or any other Google data, and we do not keep your Google access token after sign-in completes.
AxioAPI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sharing
We share data only where needed to run the service:
- Payment gateways (PayPal, payOS, PayerScan): what they need to create and reconcile a transaction.
- Upstream data providers: the parameters of your request (for example a domain, keyword or email address to check) are forwarded to the matching provider to produce the result. Your account details are not sent with them.
- Infrastructure: the hosting and email delivery services we use to operate the system.
- Authorities: when required by law.
5. Retention
- Account details: for as long as your account is active.
- Request logs: 7 to 365 days depending on your plan.
- Bulk email validation results: deleted automatically after 7 days.
- Payment records and invoices: as long as accounting law requires.
6. Security
Connections are encrypted with HTTPS. Passwords are hashed, two-factor secrets are encrypted at rest, and API keys can be revoked at any time. No system is perfectly secure; if an incident affects your data we will notify you by email.
7. Your rights
You can view and edit your account details in the customer portal, revoke API keys, remove AxioAPI's access in your Google account settings, and request an export or deletion of all your data by emailing [email protected]. We respond within 30 days.
8. Changes
When this policy changes materially we update the date at the top of this page and notify active accounts by email.
9. Contact
Privacy questions: [email protected].