Legal
Privacy Policy
Effective September 11, 2026. This policy explains the personal data handled when you visit or use Exende.
1. Controller and contact
The controller for Exende is Daniel Zaharia, Largo Valgioie 22, Italy. For privacy requests, contact support@exende.dev.
2. Data we process
- Account data: name, email address, verification status, organization membership, and account settings.
- Authentication data: password hashes, session identifiers, device or browser information, and security-related IP information.
- Developer data: API-key fingerprints, scopes, creation and revocation records, usage totals, and request metadata. Full API-key secrets are shown once and are not retained by Exende.
- Billing data: plan, subscription status, credit grants, and Stripe customer, subscription, invoice, and payment references. Exende does not store complete payment-card numbers.
- Support data: messages and information you choose to provide when contacting support.
- Website analytics: page visits, referral sources, browser and device information, broad location information, and usage measurements provided by Vercel Web Analytics and Google Analytics.
3. Why we process data
We process personal data to:
- create accounts, authenticate users, and deliver requested services;
- issue and enforce scoped API credentials, entitlements, and credits;
- process subscriptions, maintain invoices, and meet accounting obligations;
- protect Exende, its users, and its infrastructure from abuse and security threats;
- answer support requests and communicate material service information;
- understand aggregate website usage and improve product reliability.
The legal bases are performance of a contract, steps requested before entering a contract, compliance with legal obligations, and legitimate interests in security, support, and service improvement. Where consent is legally required, we rely on consent and allow it to be withdrawn.
4. Service providers
We use carefully scoped providers to operate Exende:
- Cloudflare: DNS, network delivery, Workers, databases, security, and inbound email routing.
- Vercel: website hosting and privacy-focused aggregate Web Analytics.
- Google: Google Analytics for website traffic, page navigation, and usage measurement.
- Stripe: checkout, subscriptions, invoices, tax-related checkout fields, payment methods, and the customer billing portal.
- Resend: transactional account email such as verification and password-reset messages.
- DataAPI infrastructure: product-safe hiring-data access, scoped credential enforcement, and usage accounting.
Providers process data under their own contractual and security obligations. Data may be processed outside your country when legally permitted and protected by an applicable transfer mechanism.
5. Cookies and analytics
Exende uses essential storage required for secure sign-in and session operation. These mechanisms are not used for advertising. Vercel Web Analytics reports aggregate traffic without third-party cookies or persistent cross-site identifiers. Google Analytics is also installed and may use first-party cookies to distinguish browsers and measure visits and navigation. Google receives page and referrer URLs and browser and device information through its tag. You can control cookies and tracking through your browser settings.
Product events sent to Vercel help us understand catalogue use, account creation, API-key setup, and checkout. These custom events exclude search text, API keys, emails, and record contents; Vercel analytics URLs omit query strings and fragments.
6. Retention
Account and organization records are kept while the account is active and for a limited period afterward when needed for security, dispute resolution, or legal obligations. Billing and accounting records are kept for the period required by applicable law. Security logs, sessions, and usage metadata are retained only as long as reasonably necessary for their stated purposes. Deletion requests do not require us to erase records that must legally be retained.
7. Security
We use access controls, scoped credentials, one-way credential storage, transport encryption, secret separation, and audit records. No system can guarantee absolute security, so you should keep credentials private and report suspected compromise immediately.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. You may also withdraw consent where processing depends on consent and lodge a complaint with your data-protection authority. Send requests to support@exende.dev. We may need to verify your identity before acting on a request.
9. Public hiring data
Exende observes reviewed public career sources. The public-data product is separate from customer account data. If you believe a public record contains personal information that should be corrected or removed, contact support with the relevant source and record details.
10. Children
Exende is a business and developer service and is not directed to children. Do not create an account if you are not legally able to enter the applicable agreement.
11. Changes to this policy
We may update this policy to reflect product, provider, or legal changes. The effective date at the top identifies the current version, and material changes will be communicated when required.