Legal document
Privacy Policy
1. Overview
This Privacy Policy explains how Pipefork collects, uses, stores, shares, and protects personal data when you use Pipefork's website, dashboard, API builder, API runtime, documentation, support channels, and related services.
Pipefork is intended for professional, business, development, integration, and commercial use. It is not intended for personal, household, consumer, children's, medical, emergency, life-critical, or other high-risk use cases.
This Privacy Policy applies where Pipefork acts as a data controller. Where Pipefork processes personal data contained in Customer Content, API requests, API responses, logs, upstream data, or runtime configuration on behalf of a customer, Pipefork generally acts as a processor and the customer acts as controller.
If you use Pipefork on behalf of a company, customer, employer, or other organization, you are responsible for ensuring that your organization has provided any required notices to its own users, employees, customers, or other data subjects.
2. Personal Data We Collect
Pipefork may collect and process the following categories of personal data.
2.1 Account Data
- name;
- email address;
- authentication metadata;
- organization or workspace name;
- role and workspace membership;
- workspace invitations;
- account settings;
- login and session metadata.
2.2 Usage and Technical Data
- IP address;
- browser and device information;
- timestamps;
- pages and features used;
- audit and security events;
- API usage counters;
- request metadata;
- rate-limit and quota events;
- error messages and diagnostic data;
- legal document acceptance records, including document type, version, locale, content hash, action, context, timestamp, and limited acceptance metadata;
- browser performance measurements collected through Vercel Speed Insights, such as page route, browser and device type, country, and Web Vitals, without a visitor identifier in the reported data point;
- browser and security signals processed by Cloudflare Turnstile when a protected sign-in form is used.
2.3 API and Workspace Data
Depending on how you use the Service, Pipefork may process:
- API project names;
- endpoint paths and methods;
- request and response schemas;
- mapping and transformation configuration;
- environment names;
- API key metadata;
- upstream connection metadata;
- secret metadata, but not raw secret values in normal display or logs;
- logs and execution metadata;
- test payloads or sample data you provide.
2.4 Runtime and Log Data
When a published API is called, Pipefork may process runtime metadata such as:
- timestamp;
- workspace or tenant;
- API project;
- environment;
- endpoint;
- HTTP method;
- status code;
- duration;
- API key identifier;
- step-level success or failure;
- error messages;
- quota and rate-limit results;
- correlation IDs used for troubleshooting and support.
Depending on your configuration, logs, payloads, headers, query parameters, endpoint paths, or upstream responses may contain personal data. You are responsible for avoiding unnecessary personal data, secrets, credentials, payment card data, health data, national identification numbers, children's data, criminal offence data, special categories of personal data, or other highly sensitive data in logs and API payloads.
2.5 Billing Data
If you use paid features, Pipefork may process billing-related metadata such as:
- plan;
- subscription status;
- billing email;
- billing address and tax-related metadata where required;
- payment provider customer ID;
- invoices and payment status;
- refund, dispute, cancellation, and entitlement-repair metadata.
Full payment card details are normally processed by the payment provider and are not stored by Pipefork. Pipefork keeps the billing records needed to operate its plans and show billing activity. Stripe may hold additional payment and transaction data that is not stored in Pipefork.
2.6 Support and Communication Data
- messages you send to Pipefork;
- support requests;
- feedback;
- email communications;
- attachments or diagnostic details you provide for support;
- information needed to respond to your request.
2.7 AI Builder and Customer-Selected Providers
When you use AI Builder, Pipefork sends your prompt and relevant API descriptions, schemas, project context, and, where needed, previous generated results to the LLM provider selected for that request. The provider may be managed by Pipefork or configured by your workspace. A managed provider may route the request onward to the selected model provider. Pipefork stores AI usage information such as provider and model identifiers, token counts, cost and error metadata, and a prompt hash; the usage record does not store the full prompt. Generated API drafts and configurations remain in the workspace until deleted according to the normal workspace deletion and retention rules. Provider-side retention and model use depend on the selected provider and model terms.
If a workspace admin configures BYOK LLM providers, external secret providers, upstream APIs, or private runners, Pipefork may process metadata needed to connect those providers. The actual data sent to those providers depends on the customer's configuration and API definitions.
2.8 Sources of Personal Data
We receive account and support information from you, workspace invitations and role information from your organization's administrators, authentication information from Supabase and any sign-in provider you choose, and billing status from Stripe when billing is used. We collect technical and usage information from your browser, device, and use of the Service. Customer-controlled API requests and upstream responses may also contain personal data that we process on the customer's behalf rather than as controller.
3. Purposes and Legal Bases
Pipefork processes personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Creating and managing accounts | Contract |
| Providing the Service | Contract |
| Running API builder and runtime functionality | Contract |
| Legal acceptance records | Contract / legal obligation / legitimate interests |
| Authentication, access control, and security | Contract / legitimate interests |
| Logging, debugging, abuse prevention, fraud prevention, and service reliability | Legitimate interests |
| Usage metering, quotas, rate limits, and entitlement enforcement | Contract / legitimate interests |
| Billing, subscription management, invoices, refunds, disputes, and tax records | Contract / legal obligation |
| Customer support | Contract / legitimate interests |
| Product analytics and improvement | Legitimate interests / consent where required |
| AI Builder request handling, usage metering, and troubleshooting | Contract / legitimate interests for security and service reliability |
| Legal compliance and legal claims | Legal obligation / legitimate interests |
| Marketing communications | Consent or legitimate interests, depending on context |
Where Pipefork relies on legitimate interests, those interests include securing the Service, preventing abuse, enforcing plan limits, maintaining reliable operations, improving product functionality, supporting customers, protecting legal rights, and preventing fraud or misuse.
Where processing is based on consent, you may withdraw consent at any time without affecting processing that took place before withdrawal.
Some personal data is required to create an account, provide the Service, secure the Service, comply with legal obligations, or manage billing. If required information is not provided, Pipefork may be unable to provide some or all of the Service.
4. Customer Content and Processor Role
If you use Pipefork to process personal data belonging to your own users, customers, employees, partners, or third parties, you are responsible for ensuring that you have a lawful basis and the right to process that data through Pipefork.
For such Customer Content, Pipefork generally acts as your processor. You instruct Pipefork to process Customer Content only to provide, secure, maintain, and troubleshoot the Service in accordance with your configuration and documented instructions, and as otherwise required by law. Pipefork does not use Customer Content to train AI models. Service usage and performance information may be used to improve the Service as described in this Privacy Policy.
Pipefork provides a Data Processing Addendum for Customer Content processed on behalf of customers. The DPA forms part of the customer relationship where Pipefork processes Customer Content as processor, unless the parties agree otherwise in writing.
You must not use Pipefork to process special categories of personal data, criminal offence data, health data, payment card data, national identification numbers, children's data, or other highly sensitive data unless Pipefork has expressly approved that use in writing and you have a lawful basis and appropriate safeguards.
5. Cookies and Similar Technologies
Pipefork currently uses cookies and similar technologies needed for:
- authentication;
- session management;
- security, including protecting sign-in and other security-sensitive flows.
Pipefork does not currently use optional analytics or marketing cookies. Vercel Speed Insights collects browser performance measurements without cookies or persistent visitor identifiers. Cloudflare Turnstile processes browser and security signals when you use a protected sign-in form. These services are described in Section 6.
If Pipefork introduces non-essential cookies or similar tracking technologies, it will provide the required information and choices before using them where applicable law requires consent.
6. Subprocessors and Recipients
Pipefork uses the following providers in the current production configuration, for the stated purposes:
| Provider | Purpose and data that may be processed |
|---|---|
| Vercel | Website and control-plane hosting, network delivery, technical logs, and cookieless Speed Insights performance measurements. |
| Supabase | Authentication, database and storage for account, workspace, legal acceptance, API configuration, and operational records. |
| Google Cloud | Cloud Run API runtime, operational logs, and secret infrastructure; runtime requests and related metadata may pass through it. |
| Upstash | Shared rate limiting and runtime cache where configured; request and workspace identifiers, counters, and cached step outputs may be processed. |
| Cloudflare | Turnstile bot protection on protected sign-in forms; browser and security signals and verification tokens may be processed. |
| Kilo Code and OpenRouter | Pipefork-managed AI Builder requests where selected; prompts, relevant API context, generated results, and usage metadata may be processed and routed to model providers. |
| Stripe | Test-mode billing currently configured; billing contact and checkout information is processed when a test checkout or billing flow is used. |
Pipefork maintains a subprocessor registry with more detail about these providers. Professional advisers may also receive limited data where necessary for legal, accounting, tax, or compliance purposes. If Pipefork transfers its business or assets, personal data may be disclosed to the parties involved, subject to applicable law and appropriate safeguards.
Workspace-configured BYOK LLM providers, external secret providers, upstream APIs, and private-runner environments are customer-selected providers. Runtime LLM processing is disabled by default. If a workspace admin enables Runtime LLM processing and configures an LLM provider, LLM steps may send prompts, request-derived data, upstream response data, and generated outputs to that provider according to the customer configuration. Customers are responsible for their lawful basis, user notices, provider terms, and any transfer safeguards for those customer-selected providers. Google and GitHub sign-in, when chosen by a user, is also subject to the relevant sign-in provider's own privacy terms.
Pipefork does not sell personal data.
7. International Transfers
Some service providers may process personal data outside Finland, the EU, or the EEA.
Where personal data is transferred outside the EEA, Pipefork uses safeguards required by applicable data protection law, such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments where required, or other appropriate mechanisms. Information about the applicable safeguards or how to obtain a copy can be requested using the privacy contact below.
Customer-selected providers may process personal data in locations chosen by the customer or by that provider. Customers are responsible for assessing and configuring customer-selected providers appropriately.
8. Retention
Pipefork retains personal data only as long as necessary for the purposes described in this Privacy Policy, the Terms of Service, the Data Processing Addendum, applicable plan documentation, and applicable law.
Indicative retention periods:
| Data type | Retention |
|---|---|
| Account data | Until account deletion, plus limited backup/legal retention |
| Legal acceptance records | Document type, version, locale, content hash, action, context, and timestamps are retained while the account exists and longer only where needed for legal defense. IP address and User-Agent acceptance metadata are cleared after 180 days unless a legal/security hold applies |
| Workspace and API configuration | While workspace is active, unless deleted earlier. API drafts remain mutable; deployed API versions are immutable snapshots and are deleted through project/workspace deletion or purge flows rather than edited in place |
| Workspace secrets | Active until rotated, disabled, or deleted by workspace admins. Pipefork-owned encrypted secret values are overwritten on disable/delete; customer-owned external providers follow the customer's provider retention, version destruction, audit log, backup, and recovery-window configuration |
| Runtime request logs in the Pipefork database | Free: 7 days; Starter: 30 days; Pro: 90 days; Internal/admin workspaces: 365 days, unless a shorter workspace override applies |
| Runtime step response cache | Disabled by default in production unless explicitly enabled; when enabled, workspace/runtime TTL caps default to 5 minutes and never exceed 24 hours |
| AI Builder prompts and generated responses | Pipefork's AI usage record stores a prompt hash and usage metadata rather than the full prompt. Generated drafts follow workspace and API configuration retention; providers and downstream model hosts apply their own retention terms to content sent to them |
| Cloud provider console logs for Cloud Run and Vercel | 30 days or shorter for platform-owned production deployments, unless a legal hold or security incident exception applies |
| Security logs | As needed for security, abuse prevention, and legal protection; provider console security logs follow the 30-day cloud log cap unless an exception applies |
| Billing records | As required by accounting and tax law |
| Support messages and internal support notes | Support messages are retained as needed for support history and legal protection. Internal workspace support notes expire after 730 days unless a legal or security hold applies |
| Support notes and admin audit logs | Free-text fields are minimized before storage where practical. Admin audit logs are retained for up to 7 years unless a longer legal or security hold applies |
| Backups | Deleted or overwritten according to backup rotation |
Runtime cloud logs are minimized by default and should not contain request bodies, response bodies, headers, API keys, raw secrets, raw request paths, query strings, or user-controlled upstream error text. Request-log payload/body debug logging, if enabled for troubleshooting, should be explicit, short-lived, and disabled for production by default.
Runtime step response caching can store full upstream step outputs. It is disabled by default for production runtimes unless explicitly configured, uses short TTL caps, and is invalidated when related secrets or project deployments are withdrawn or deleted.
Workspace secret values are write-only in Pipefork. Creating or updating an existing secret rotates the stored value and records a non-sensitive lifecycle audit event. Disabling a Pipefork-owned encrypted secret overwrites the encrypted value. When a workspace uses a customer-owned external secret provider, Pipefork requests provider-native deletion where supported; remaining provider versions, audit logs, backups, or recovery windows are governed by the customer's provider configuration.
Deletion from backups, immutable logs, accounting records, legal records, and security records may take additional time or may be limited where retention is required for legal, tax, accounting, security, abuse prevention, dispute handling, or legal-defense reasons.
9. Security
Pipefork uses reasonable technical and organizational measures designed to protect personal data, including access controls, encryption where appropriate, logging, backups, minimization, segregation of duties, and operational security practices.
No service can guarantee absolute security. You are responsible for using strong authentication, protecting API keys, limiting workspace access, validating upstream data, and avoiding unnecessary personal or sensitive data in API payloads and logs.
Pipefork will assess personal data incidents and notify affected customers, users, data subjects, or authorities where required by applicable law.
10. Your Rights
Depending on your location, role, and applicable law, you may have rights to:
- obtain information about the processing of your personal data;
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing;
- receive data in portable format;
- withdraw consent where processing is based on consent;
- object to direct marketing and opt out of marketing emails using the unsubscribe link or by contacting Pipefork;
- lodge a complaint with a data protection authority;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where that right applies.
Not all rights apply in all situations. For example, rights may depend on the legal basis for processing, whether Pipefork acts as controller or processor, legal retention obligations, security needs, and the rights and freedoms of others.
Requests can be sent to:
support@pipefork.com
Pipefork may need to verify your identity and account relationship before responding. Pipefork aims to respond within the time required by applicable law. Where Pipefork acts as processor for Customer Content, Pipefork may direct the request to the relevant customer/controller or assist that customer according to the Data Processing Addendum.
You may also lodge a complaint with the Finnish Data Protection Ombudsman or another competent supervisory authority. The Finnish Data Protection Ombudsman's website is: https://tietosuoja.fi/en
You can download a JSON export of account-related data held by Pipefork from Account settings without asking Pipefork to prepare it. The export includes your account profile, legal acceptances and confirmation metadata, workspace memberships, accessible API project definitions, your AI usage records and available redacted request snapshots, connected-client grants, data-subject request history, and billing identifiers and summaries for workspaces where you have billing access.
The export contains Pipefork's stored billing information, not additional payment information held only by Stripe. It does not include every runtime payload, support exchange, provider record, or item of workspace data that may relate to you or other people. Contact Pipefork using the privacy address above if you need access to personal data outside the self-service export or cannot use Account settings.
11. Account and Data Deletion
You can initiate deletion of your own Pipefork account in Account settings. You must confirm the action and may need to sign in again if your authentication is no longer recent enough. Pipefork then checks the account and any workspaces you own. When the applicable deletion policy allows automatic processing and the safety checks find no blockers, your deletion is queued without manual approval and you are signed out. The account deletion workflow runs in the background, so being signed out does not mean that all data has already been deleted.
If manual review is configured or a blocker is found, Pipefork reviews the deletion before the same workflow can run. Blockers may include an active paid subscription, unresolved billing, external resources that need cleanup, or a workspace you own that has other members and needs ownership resolution. The workflow deletes workspaces you own when it can safely do so, removes your memberships in other workspaces, and deletes your sign-in account. Content in a workspace you do not own may remain under that workspace's control. Download your account-data JSON and separately export any other workspace content you need before initiating deletion, because access may end immediately on the automatic path.
Some records may be retained in minimized form where required or permitted for legal, tax, accounting, security, abuse prevention, or legal claims. Backup and provider retention may take additional time as described in Section 8. You can also contact Pipefork about deletion of other personal data or if you cannot use the account settings. If you are an end user of a Pipefork customer, you should normally contact that customer first because the customer may be the controller of your data.
12. Children
Pipefork accounts and workspaces are for users who are at least 18 years old, as stated in the Terms of Service. Pipefork does not knowingly collect account data from users under 18. If you believe someone under 18 has a Pipefork account, please contact us using the privacy address in Section 15.
Customers must not use Pipefork to process children's data unless Pipefork has expressly approved that use in writing and the customer has a lawful basis, appropriate notices, parental consent where required, and appropriate safeguards.
13. Automated Decision-Making
Pipefork does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on users.
AI-assisted builder features, generated suggestions, runtime transformations, and LLM steps may produce outputs based on user or customer configuration, but customers remain responsible for reviewing, testing, approving, and deploying their own API configurations and outputs.
14. Changes to This Privacy Policy
Pipefork may update this Privacy Policy from time to time for legal, security, operational, technical, product, provider, or data-processing changes.
Material changes may be notified by email, dashboard notice, login notice, or other reasonable means. Where required, Pipefork may ask users to accept or acknowledge updated legal documents before continuing to use the Service.
15. Contact
For privacy questions or requests:
support@pipefork.com