Privacy policy
1. Who we are
AnswerLine (answerline.dev) is operated by the AnswerLine team, based in Hungary ("we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR) we are the data controller for the personal data described in this policy. Contact: support@answerline.dev.
2. What we collect
- Account data: email address, sign-in method (email link or Google), team and account membership, roles, and the names you give API keys.
- Billing data: plan, subscription status, credit ledger, invoices and payment history. Card details are collected and held by our payment processor, Stripe; we never see or store full card numbers.
- API usage metadata: timestamps, engine, country/geo parameter, request status, credits reserved and charged, request ids, and per-day usage rollups.
- Request payloads and results: the prompts and parameters you submit and the structured results we return, including async task payloads stored until the task completes and while the result is retrievable.
- Webhook configuration: the endpoints you register, delivery logs and rotated secrets (stored hashed where possible).
- Security and audit records: sign-in events with client IP, key creation and revocation, membership changes and other account actions, kept in an audit log.
- Support correspondence: emails and messages you send us.
The dashboard uses only the cookies needed to keep you signed in; we do not run advertising or third-party analytics trackers.
3. Why we process it (legal bases)
- To provide the service — running your requests, storing results for retrieval, delivering webhooks, managing your account and keys (performance of a contract, GDPR Art. 6(1)(b)).
- To bill you — metering usage, charging credits, invoicing, and meeting tax and accounting obligations (contract and legal obligation, Art. 6(1)(b), (c)).
- To keep the service secure — abuse prevention, rate limiting, audit logging, detecting compromised keys (legitimate interest, Art. 6(1)(f)).
- To support you and improve reliability — answering requests, diagnosing failures, monitoring capacity (legitimate interest, Art. 6(1)(f)).
4. How long we keep it
- Request payloads and results are stored for a fixed retention window (currently 30 days) so you can retrieve async results and history, then automatically deleted. Raw captures used for quality checks follow the same or a shorter window.
- Account data is kept while your account exists. When you delete your account, remaining personal details are erased after a 30-day grace window; see section 7.
- Billing and accounting records (ledger entries, invoices, payment records) are kept for the period required by Hungarian and EU accounting and tax law.
- Audit log and security records are kept for a limited period, then pruned.
5. Who we share it with
We use a small number of subprocessors acting on our instructions. We do not sell personal data.
- Stripe — payment processing and invoicing.
- Cloudflare — network delivery, DDoS protection and edge security for the dashboard, API and object storage.
- Hetzner — server hosting in the EU.
- Resend — transactional email (sign-in links, invoices, notifications).
Where a subprocessor is outside the EU/EEA, transfers are covered by adequacy decisions or standard contractual clauses.
We also disclose data where the law requires it, and to a successor if the business is sold or merged, subject to this policy.
6. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest. You can withdraw consent where processing relies on it. Many of these are self-service under Settings in the dashboard; for anything else contact support@answerline.dev.
You also have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or your local supervisory authority.
Download your data
Download my data saves a JSON file with your user (email address, sign-up time), your team memberships, your sessions (when each started and expires) and the notification emails we sent you, and for each account you own: its plan, API keys (names, prefixes and use times), members, invites, bonus claims, referral commissions and daily usage. It never contains API keys, sign-in links, session tokens, webhook secrets or their hashes. A few downloads per hour are allowed.
Sign out everywhere
Sign out everywhere ends every session of your user at once, on every device, including the one you use.
Delete your account
To delete your user, type your email address exactly under Delete account. Then:
- If you are the only owner of an account that has other members, deletion is refused until you make one of them an owner or remove them.
- You leave every account that has another owner; the account and its data stay with its team, and your email address is removed from its notifications and audit log.
- An account you are the only member of is deleted with you: its subscription is cancelled, its queued tasks are dropped and its API keys stop working (within about 30 seconds).
- Your sessions and sign-in links end, and your email address is replaced in our records at once.
- After a grace window of 30 days, a deleted account's remaining personal details are erased: its name, invite addresses and bonus claim links are overwritten, and its API keys and audit log are deleted. Until then, support can help if you deleted by mistake.
- We keep what accounting and the law require: the credit ledger, overage and referral commission amounts, and the invoices and payments our payment processor holds.
- We keep a SHA-256 hash of your mailbox (your address as your email provider delivers it, for example without the
+tag), used only so that signing up again with it does not grant the free plan's monthly credits a second time. - The prompts and results of your requests are deleted with the request result retention.
7. Changes and contact
We may update this policy and will post the new version here with a new "last updated" date; for material changes we will give notice by email or in the dashboard. Questions and requests: support@answerline.dev.