New: Fixed Bid Applications. See the packages

EffortlessAPI
Legal

Privacy Policy

This policy explains how An Abstract Level Inc., which operates EffortlessAPI ("we" or "us"), collects and uses personal data when you use effortlessapi.com, our platform, our tools and our command-line interface.

1. What this policy covers

This policy covers personal data we collect and decide about ourselves: when you visit our website, create an account, buy something, give us material for a project, or contact us.

Where we host or process data for a customer under a separate agreement, such as a hosting agreement, that agreement governs the data and this policy does not apply to it. Our Terms of Service do not include hosting; it is only ever offered under such an agreement.

2. Your project material and your customers' data

Our tools derive rulebooks, code and documentation from the structure of a business: its entities, rules and relationships. They do not need real records about real people to do that. Mock data serves the same purpose.

Please do not give us personal data about your customers, employees or anyone else unless it is needed. Remove it, or replace it with mock data, before you upload a file or connect a source.

If personal data is in what you give us anyway, for example records in a connected Airtable base or rows in a rulebook, it is stored with your project like the rest of your material and handled as described below. You remain responsible for having a lawful basis to share it with us.

We do not send your project material to AI model providers. If you use our command-line tools together with Claude Code or another AI tool, what you share with that tool is between you and its provider.

3. What we collect

  • Account. Your email address (verified with a sign-in code), the name and phone number you add to your profile, your organization's name and billing email, and your role in it.
  • Sign-in sessions. A record of each sign-in, with a hashed copy of the session token and the browser user agent, so we can keep your account secure and end sessions that look stolen.
  • Acceptance of our Terms. When you accept our Terms, we record which version you accepted, when, for which account, plan or purchase, the exact wording you agreed to, the Order you were shown, and the IP address and browser user agent it came from. This is our evidence of the agreement.
  • Projects. The material you give us for a project: rulebooks, configuration, your answers to project questions, the client name, contact email and company you enter, and the repository you want it delivered to. If you connect an Airtable base, we store what we import from it and a snapshot of its structure. We keep every version of a project file you upload or import until the project is deleted.
  • Fixed-price requests. When you ask for a quote or a fixed-price build, your name, email, phone number, company, project description and the documents you attach.
  • Use of the platform. We may record which tools and builds run on your projects, when, with what result, and on how many files of what size, to operate, secure, bill for and improve the platform.
  • Payments. Our payment provider, Stripe, collects your card details directly; we never see or store them. We keep the Stripe references for your customer record, subscriptions, purchases and invoices, and the amounts, names and emails on them.
  • Messages. What you send us through a contact form, by email or when booking a call.
  • Website analytics. Only if you allow optional cookies: pages visited, approximate location, device and browser, through Google Analytics. See section 8.
  • Server logs. Our hosting providers keep standard request logs, including IP addresses, for security and troubleshooting.

4. Credentials you give us

When you give us a credential to read another system, such as an Airtable personal access token, we use it to read that system for that one request, through our server and our own import service, and we do not save it with your project. Your sign-in tokens for our own platform are kept in your browser so you stay signed in, until you sign out.

5. How we use it

  • To provide what you have ordered and run your projects.
  • To sign you in and keep your account secure.
  • To take payments, manage subscriptions and keep financial records.
  • To keep evidence of the agreements you have accepted.
  • To answer you, and to tell you about changes to your plan or our terms.
  • To enforce fair use, prevent abuse and improve the platform.

6. Decisions about you

We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not treat anyone differently for exercising a privacy right.

7. Legal basis (EU, EEA and UK)

  • Contract: to provide your account, plan, purchases and projects.
  • Consent: for analytics cookies. You can withdraw it at any time (section 8).
  • Legitimate interests: to secure and improve the platform, enforce fair use, keep evidence of agreements and answer people who contact us.
  • Legal obligation: to keep financial and tax records.

8. Cookies and similar storage

We use functional cookies and browser storage that the site needs to work: your cookie choice, your sign-in, your cart and projects you started before signing in. These do not track you.

Analytics cookies are optional. Google Analytics does not load until you accept them in the cookie banner. If you later withdraw consent, we stop it and remove its cookies. You can change your choice at any time with the "Cookie settings" link at the bottom of every page.

Some pages embed services from other companies, which may set their own cookies when they load. YouTube videos use its privacy-enhanced mode. The Calendly booking calendar loads only when you click to open it, or automatically if you have accepted optional cookies. Their own privacy policies apply.

9. Who we share it with

We do not sell or share personal data. We share it only with providers who help us run the service, for that purpose:

  • Stripe: payments, subscriptions and invoices.
  • Control Plane: hosting of our application, database and project builds.
  • Amazon Web Services: hosting of our website.
  • Google: email, including sign-in codes, and website analytics if you consent.
  • GitHub: delivering repositories to you.
  • Airtable: only when you connect a base, to read it.
  • Formspree and Calendly: our contact forms and call booking.
  • YouTube: videos on our website, in privacy-enhanced mode.

We may also disclose data where the law requires it, to protect our rights or others' safety, or to a buyer if our business is sold or reorganized.

10. International transfers

We are based in the United States, and our providers may process data in the United States and other countries. If you are in the EU, EEA, UK or Switzerland, by using the service you ask us to transfer your data to the United States, which is needed to provide what you ordered. We are not certified under the EU-US Data Privacy Framework. Onward transfers by our providers are covered by their standard contractual clauses.

11. How long we keep it

  • Account and project material: while your account is open. When you ask us by email to delete a project or close your account, we delete it by hand within 30 days, except what we must keep as described below. Before that, you can ask us for a copy.
  • Project build environments (the editor, derived API and database for a run): removed automatically within 30 minutes of the run ending.
  • Acceptance records: for as long as your account exists and at least three years afterwards, as our Terms state.
  • Orders, invoices and payment records: for the period the law requires or allows for claims, tax and accounting.
  • Fixed-price requests and messages: as long as needed to answer and follow up, and deleted on request.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict how we use it, and to withdraw consent. To use any of these rights, or to close your account, email hello@effortlessapi.com from the address on your account. We will respond within 30 days and will not charge for it. If you are in the EU, EEA or UK, you can also complain to your data protection authority.

13. Security

We protect data with reasonable technical and organizational measures, including encrypted connections, session tokens hashed on our server and access limited to the people who need it. No system is perfectly secure; if a breach affects your personal data, we will tell you where the law requires it.

14. Children

Our services are for businesses and adults. You must be at least 18, or the age of majority where you live, to create an account, and we do not knowingly collect personal data from anyone younger.

15. Changes to this policy

We may update this policy. Each version has its own version number and date, shown below; the current version is always at effortlessapi.com/privacy. If a change materially affects how we use your data, we will tell you by email or in your account before it applies.

16. Contact

Questions about this policy or your data:

An Abstract Level Inc. (EffortlessAPI)

3710 Ross St, Madison, WI 53705, USA

hello@effortlessapi.com

Version 2026-10-02. Last updated October 2, 2026.