Privacy Policy
Last updated: July 31, 2026
This policy explains what personal data IMEIAPI.org("we") collects, why we collect it, and the choices you have. We keep data collection to the minimum needed to run the Service.
1. Data we collect
Contact data. If you write to us through the contact form or by e-mail, we receive your name, e-mail address and the content of your message, and keep the correspondence to handle your request.
Account and payment data. When accounts open, we will collect your e-mail address and, for purchases, billing details processed by our payment provider. We do not store full card numbers.
API usage data. Once the API is live we log requests (queried IMEI, timestamp, response status, API key used) to run the Service, draw down your prepaid balance and prevent abuse. IMEI numbers identify devices, not people; we do not link them to device owners.
2. Cookies
This website currently sets no cookies at all. Your theme choice (light or dark) is kept in your browser's local storage on your device and is never sent to us. If we add analytics later, it will be behind a consent banner that defaults to off, and this policy will be updated before that happens.
3. Analytics
We do not currently run any analytics, advertising or tracking scripts on this website.
4. Legal bases (GDPR)
We process data to perform our contract with you (account, API, payments), to pursue our legitimate interests (service security, abuse prevention, aggregate statistics), to comply with legal obligations (accounting), and — for anything requiring consent — based on the consent you give.
5. Sharing
We share data only with processors necessary to run the Service: hosting infrastructure, e-mail delivery and payment processing. We do not sell personal data.
6. Retention
Correspondence is kept for as long as needed to handle your request and our records of it. Account data is kept for as long as your account exists, including the 12-month life of any prepaid balance. API logs are kept for up to 24 months as payment evidence and for abuse prevention, then deleted or anonymized. Accounting records are kept as required by law.
7. Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, restriction of or objection to its processing, and a portable copy. You can also lodge a complaint with your data protection authority. To exercise your rights, contact [email protected].
8. Security
All traffic to the website and API is encrypted with TLS. API access requires per-account keys, and internal access to production data is limited to what is necessary to operate the Service.
9. Changes to this policy
We may update this policy as the Service evolves — for example when accounts, payments or analytics launch. The current version is always available at imeiapi.org/privacy with the date of the last update shown above.
10. Contact
Privacy questions and requests: [email protected].