Legal document
Pipefork Privacy Policy
1. Overview
This Privacy Policy explains how Pipefork collects, uses, stores, shares, and protects personal data when you use Pipefork's website, dashboard, API builder, API runtime, documentation, support channels, and related services.
Pipefork is intended for professional, business, development, integration, and commercial use. It is not intended for personal, household, consumer, children's, medical, emergency, life-critical, or other high-risk use cases.
This Privacy Policy applies where Pipefork acts as a data controller. Where Pipefork processes personal data contained in Customer Content, API requests, API responses, logs, upstream data, or runtime configuration on behalf of a customer, Pipefork generally acts as a processor and the customer acts as controller.
If you use Pipefork on behalf of a company, customer, employer, or other organization, you are responsible for ensuring that your organization has provided any required notices to its own users, employees, customers, or other data subjects.
2. Personal Data We Collect
Pipefork may collect and process the following categories of personal data.
2.1 Account Data
- name;
- email address;
- authentication metadata;
- organization or workspace name;
- role and workspace membership;
- workspace invitations;
- account settings;
- professional/business-use confirmation;
- login and session metadata.
2.2 Usage and Technical Data
- IP address;
- browser and device information;
- timestamps;
- pages and features used;
- audit and security events;
- API usage counters;
- request metadata;
- rate-limit and quota events;
- error messages and diagnostic data;
- legal document acceptance records, including document type, version, locale, content hash, action, context, timestamp, and limited acceptance metadata.
2.3 API and Workspace Data
Depending on how you use the Service, Pipefork may process:
- API project names;
- endpoint paths and methods;
- request and response schemas;
- mapping and transformation configuration;
- environment names;
- API key metadata;
- upstream connection metadata;
- secret metadata, but not raw secret values in normal display or logs;
- logs and execution metadata;
- test payloads or sample data you provide.
2.4 Runtime and Log Data
When a published API is called, Pipefork may process runtime metadata such as:
- timestamp;
- workspace or tenant;
- API project;
- environment;
- endpoint;
- HTTP method;
- status code;
- duration;
- API key identifier;
- step-level success or failure;
- error messages;
- quota and rate-limit results;
- correlation IDs used for troubleshooting and support.
Depending on your configuration, logs, payloads, headers, query parameters, endpoint paths, or upstream responses may contain personal data. You are responsible for avoiding unnecessary personal data, secrets, credentials, payment card data, health data, national identification numbers, children's data, criminal offence data, special categories of personal data, or other highly sensitive data in logs and API payloads.
2.5 Billing Data
If you use paid features, Pipefork may process billing-related metadata such as:
- plan;
- subscription status;
- billing email;
- billing address and tax-related metadata where required;
- payment provider customer ID;
- invoices and payment status;
- refund, dispute, cancellation, and entitlement-repair metadata.
Full payment card details are normally processed by the payment provider and are not stored by Pipefork.
2.6 Support and Communication Data
- messages you send to Pipefork;
- support requests;
- feedback;
- email communications;
- attachments or diagnostic details you provide for support;
- information needed to respond to your request.
2.7 Customer-Selected Providers and BYOK Data
If a workspace admin configures customer-selected providers, such as BYOK LLM providers, external secret providers, upstream APIs, or private runners, Pipefork may process metadata needed to connect those providers. The actual data sent to those providers depends on the customer's configuration and API definitions.
3. Purposes and Legal Bases
Pipefork processes personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Creating and managing accounts | Contract |
| Providing the Service | Contract |
| Running API builder and runtime functionality | Contract |
| Professional/business-use confirmation and legal acceptance records | Contract / legal obligation / legitimate interests |
| Authentication, access control, and security | Contract / legitimate interests |
| Logging, debugging, abuse prevention, fraud prevention, and service reliability | Legitimate interests |
| Usage metering, quotas, rate limits, and entitlement enforcement | Contract / legitimate interests |
| Billing, subscription management, invoices, refunds, disputes, and tax records | Contract / legal obligation |
| Customer support | Contract / legitimate interests |
| Product analytics and improvement | Legitimate interests / consent where required |
| Legal compliance and legal claims | Legal obligation / legitimate interests |
| Marketing communications | Consent or legitimate interests, depending on context |
Where Pipefork relies on legitimate interests, those interests include securing the Service, preventing abuse, enforcing plan limits, maintaining reliable operations, improving product functionality, supporting customers, protecting legal rights, and preventing fraud or misuse.
Where processing is based on consent, you may withdraw consent at any time without affecting processing that took place before withdrawal.
Some personal data is required to create an account, provide the Service, secure the Service, comply with legal obligations, or manage billing. If required information is not provided, Pipefork may be unable to provide some or all of the Service.
4. Customer Content and Processor Role
If you use Pipefork to process personal data belonging to your own users, customers, employees, partners, or third parties, you are responsible for ensuring that you have a lawful basis and the right to process that data through Pipefork.
For such Customer Content, Pipefork generally acts as your processor. You instruct Pipefork to process Customer Content only to provide, secure, maintain, troubleshoot, and improve the Service, and as otherwise required by law.
Pipefork provides a Data Processing Addendum for Customer Content processed on behalf of customers. The DPA forms part of the customer relationship where Pipefork processes Customer Content as processor, unless the parties agree otherwise in writing.
You must not use Pipefork to process special categories of personal data, criminal offence data, health data, payment card data, national identification numbers, children's data, or other highly sensitive data unless Pipefork has expressly approved that use in writing and you have a lawful basis and appropriate safeguards.
5. Cookies and Similar Technologies
Pipefork may use cookies and similar technologies for:
- authentication;
- session management;
- security;
- remembering preferences;
- analytics;
- product improvement.
Essential cookies are required for the Service to work. Optional analytics or marketing cookies will be used only where legally permitted and, where required, with consent.
If optional analytics or marketing cookies are enabled, Pipefork should provide a cookie notice or consent mechanism that explains the purpose of those cookies and allows choices where required by law.
6. Subprocessors and Recipients
Pipefork may share personal data with service providers that help operate the Service, such as:
- cloud hosting providers;
- database providers;
- runtime infrastructure providers;
- cache and queue providers;
- email delivery providers;
- analytics providers;
- error monitoring providers;
- payment processors;
- customer support tools;
- security and abuse prevention providers;
- professional advisers where necessary for accounting, legal, tax, or compliance purposes.
Examples may include Vercel, Supabase or Neon, Upstash, Stripe, Google Cloud, GitHub, and similar infrastructure or SaaS providers, depending on the final production setup.
Pipefork maintains a subprocessor registry that identifies production providers, purposes, data categories, and transfer basis. The published subprocessor registry controls over the example provider list in this Privacy Policy if there is a difference.
Workspace-configured BYOK LLM providers, external secret providers, upstream APIs, and private-runner environments are customer-selected providers. Runtime LLM processing is disabled by default. If a workspace admin enables Runtime LLM processing and configures an LLM provider, LLM steps may send prompts, request-derived data, upstream response data, and generated outputs to that provider according to the customer configuration. Customers are responsible for their lawful basis, user notices, provider terms, and any transfer safeguards for those customer-selected providers.
Pipefork does not sell personal data.
7. International Transfers
Some service providers may process personal data outside Finland, the EU, or the EEA.
Where personal data is transferred outside the EEA, Pipefork uses safeguards required by applicable data protection law, such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments where required, or other appropriate mechanisms.
Customer-selected providers may process personal data in locations chosen by the customer or by that provider. Customers are responsible for assessing and configuring customer-selected providers appropriately.
8. Retention
Pipefork retains personal data only as long as necessary for the purposes described in this Privacy Policy, the Terms of Service, the Data Processing Addendum, applicable plan documentation, and applicable law.
Indicative retention periods:
| Data type | Retention |
|---|---|
| Account data | Until account deletion, plus limited backup/legal retention |
| Legal acceptance records | Document type, version, locale, content hash, action, context, and timestamps are retained while the account exists and longer only where needed for legal defense. IP address and User-Agent acceptance metadata are cleared after 180 days unless a legal/security hold applies |
| Workspace and API configuration | While workspace is active, unless deleted earlier. API drafts remain mutable; deployed API versions are immutable snapshots and are deleted through project/workspace deletion or purge flows rather than edited in place |
| Workspace secrets | Active until rotated, disabled, or deleted by workspace admins. Pipefork-owned encrypted secret values are overwritten on disable/delete; customer-owned external providers follow the customer's provider retention, version destruction, audit log, backup, and recovery-window configuration |
| Runtime request logs in the Pipefork database | Free: 7 days; Starter: 30 days; Pro: 90 days; Internal/admin workspaces: 365 days, unless a shorter workspace override applies |
| Runtime step response cache | Disabled by default in production unless explicitly enabled; when enabled, workspace/runtime TTL caps default to 5 minutes and never exceed 24 hours |
| Cloud provider console logs for Cloud Run and Vercel | 30 days or shorter for platform-owned production deployments, unless a legal hold or security incident exception applies |
| Security logs | As needed for security, abuse prevention, and legal protection; provider console security logs follow the 30-day cloud log cap unless an exception applies |
| Billing records | As required by accounting and tax law |
| Support messages and internal support notes | Support messages are retained as needed for support history and legal protection. Internal workspace support notes expire after 730 days unless a legal or security hold applies |
| Support notes and admin audit logs | Free-text fields are minimized before storage where practical. Admin audit logs are retained for up to 7 years unless a longer legal or security hold applies |
| Backups | Deleted or overwritten according to backup rotation |
Runtime cloud logs are minimized by default and should not contain request bodies, response bodies, headers, API keys, raw secrets, raw request paths, query strings, or user-controlled upstream error text. Request-log payload/body debug logging, if enabled for troubleshooting, should be explicit, short-lived, and disabled for production by default.
Runtime step response caching can store full upstream step outputs. It is disabled by default for production runtimes unless explicitly configured, uses short TTL caps, and is invalidated when related secrets or project deployments are withdrawn or deleted.
Workspace secret values are write-only in Pipefork. Creating or updating an existing secret rotates the stored value and records a non-sensitive lifecycle audit event. Disabling a Pipefork-owned encrypted secret overwrites the encrypted value. When a workspace uses a customer-owned external secret provider, Pipefork requests provider-native deletion where supported; remaining provider versions, audit logs, backups, or recovery windows are governed by the customer's provider configuration.
Deletion from backups, immutable logs, accounting records, legal records, and security records may take additional time or may be limited where retention is required for legal, tax, accounting, security, abuse prevention, dispute handling, or legal-defense reasons.
9. Security
Pipefork uses reasonable technical and organizational measures designed to protect personal data, including access controls, encryption where appropriate, logging, backups, minimization, segregation of duties, and operational security practices.
No service can guarantee absolute security. You are responsible for using strong authentication, protecting API keys, limiting workspace access, validating upstream data, and avoiding unnecessary personal or sensitive data in API payloads and logs.
Pipefork will assess personal data incidents and notify affected customers, users, data subjects, or authorities where required by applicable law.
10. Your Rights
Depending on your location, role, and applicable law, you may have rights to:
- obtain information about the processing of your personal data;
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing;
- receive data in portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with a data protection authority;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where that right applies.
Not all rights apply in all situations. For example, rights may depend on the legal basis for processing, whether Pipefork acts as controller or processor, legal retention obligations, security needs, and the rights and freedoms of others.
Requests can be sent to:
support@pipefork.com
Pipefork may need to verify your identity and account relationship before responding. Pipefork aims to respond within the time required by applicable law. Where Pipefork acts as processor for Customer Content, Pipefork may direct the request to the relevant customer/controller or assist that customer according to the Data Processing Addendum.
You may also lodge a complaint with the Finnish Data Protection Ombudsman or another competent supervisory authority. The Finnish Data Protection Ombudsman's website is: https://tietosuoja.fi/en
11. Deletion Requests
You may request deletion of your account or personal data. Depending on your account and plan configuration, deletion processing may start automatically after safety checks, or after a manual review by Pipefork. Automatic processing is used only when no blocking condition (for example an active paid subscription, unresolved billing records, or a shared workspace requiring ownership transfer) exists; otherwise the request is reviewed manually. Both paths run the same deletion process. Some data may be retained if required for legal, tax, accounting, security, abuse prevention, dispute resolution, legal-defense, or legitimate business purposes; retained records are minimized and direct identifiers are removed where possible.
Customer Content processed on behalf of a workspace may need to be deleted or exported by the workspace owner or administrator. If you are an end user of a Pipefork customer, you should normally contact that customer first because the customer may be the controller of your data.
12. Children
Pipefork is not intended for children or users under 18 years of age. Pipefork does not knowingly collect personal data from children.
Customers must not use Pipefork to process children's data unless Pipefork has expressly approved that use in writing and the customer has a lawful basis, appropriate notices, parental consent where required, and appropriate safeguards.
13. Automated Decision-Making
Pipefork does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on users.
AI-assisted builder features, generated suggestions, runtime transformations, and LLM steps may produce outputs based on user or customer configuration, but customers remain responsible for reviewing, testing, approving, and deploying their own API configurations and outputs.
14. Changes to This Privacy Policy
Pipefork may update this Privacy Policy from time to time for legal, security, operational, technical, product, provider, or data-processing changes.
Material changes may be notified by email, dashboard notice, login notice, or other reasonable means. Where required, Pipefork may ask users to accept or acknowledge updated legal documents before continuing to use the Service.
15. Contact
For privacy questions or requests:
support@pipefork.com