This Privacy Policy explains how personal data is collected, used, shared, and protected when you visit oden-api.com or use the ODEN web search API (the “Service”). We take a deliberately minimal approach: we process only what we need to run the Service, bill it, and keep it secure.
1 Who we are
The data controller responsible for your personal data is:
- Samie Stenberg (sole trader / enskild firma), trading as ODEN
- Address: Briggvägen 35, 826 60 Söderhamn, Sweden
- Email: [email protected]
We have not appointed a Data Protection Officer, as we are not legally required to. For any privacy question, use the contact email above.
2 Scope
This policy covers personal data we process as a controller — that is, the data of our account holders and website visitors. It does not cover how you, as our customer, use the Service to process other people's data; where the text of your search queries contains personal data, you act as controller for that data and we process it on your behalf. Business customers who need a Data Processing Agreement (DPA) for that purpose can request one at the contact email above.
3 Data we process
Depending on how you use the Service, we process the following categories of personal data:
Account & identity
Your email address, an account identifier, and any optional display name, collected when you create an account. Authentication is handled through our auth provider (Supabase).
API credentials
The API key(s) issued to your account, together with associated metadata: your plan, top-up balance, and creation date. These are stored in Cloudflare KV.
Usage records
The number of searches made per billing period, linked to your API key and account identifier, with timestamps. These are stored in a Cloudflare D1 database and are used to enforce quotas and to bill you accurately.
Billing data
Payments are processed by Stripe. Stripe holds your payment method, billing email, and (for businesses) VAT identification number. We receive and keep a Stripe customer reference, your subscription status, and records of completed payments and top-ups. We never see or store full card numbers.
Technical & security data
Your IP address, used transiently to apply rate limits and protect the Service against abuse; request trace identifiers; and short-lived diagnostic logs.
Search queries & results
The text you send to the Service is processed in real time to fetch and synthesise results. Query text may appear in short-lived operational logs (retained up to 7 days) and in a shared results cache (retained up to 1 hour, keyed by an anonymised hash rather than by your identity). We do not store your queries against your account, and we do not use them to build a profile of you.
4 Purposes & legal bases
We process personal data for the following purposes, each with a legal basis under the GDPR (Article 6):
| Purpose | Legal basis |
|---|---|
| Provide the Service, issue API keys, return results | Performance of a contract (Art. 6(1)(b)) |
| Meter usage and enforce quotas | Performance of a contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Keep accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Secure the Service, prevent abuse, apply rate limits | Legitimate interests (Art. 6(1)(f)) |
| Send essential service communications | Performance of a contract / legitimate interests |
| Optional marketing emails (if any) | Consent (Art. 6(1)(a)), withdrawable any time |
Where we rely on legitimate interests, that interest is operating a secure, reliable, and abuse-resistant service. We have balanced this against your rights and consider the processing proportionate and expected.
6 Recipients & sub-processors
We do not sell your personal data and do not share it for advertising. We share data only with the service providers we rely on to run ODEN, each acting as our processor under contract:
| Provider | Role |
|---|---|
| Cloudflare, Inc. | Hosting, edge compute, AI inference, KV/D1 storage, rate limiting |
| Supabase | Authentication and account database |
| Stripe | Payment processing |
| Google (Fonts) | Serving web fonts (receives IP address) |
We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and property of ODEN, our users, or others.
7 International transfers
ODEN is operated from the EU and we keep data within the European Economic Area (EEA) wherever practical. Some of our providers (such as Cloudflare, Stripe, and Google) operate globally and may process personal data outside the EEA, including in the United States.
Where data is transferred outside the EEA, we rely on appropriate safeguards: an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified) and/or the European Commission's Standard Contractual Clauses. You can request more detail about a specific transfer at our contact email.
8 Retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it:
| Data | Retention |
|---|---|
| Account & API key data | For the life of your account; deleted or anonymised within 90 days of account closure, unless we must keep it longer for legal reasons |
| Usage & billing records | Up to 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen) |
| Operational logs | Up to 7 days |
| Results cache | Up to 1 hour |
9 Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — have your data deleted, subject to our legal retention duties.
- Restriction — limit how we process your data in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these, email us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
[email protected] · +46 8 657 61 00 · imy.se
10 Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, secret management, scoped API keys, rate limiting, and storage on infrastructure operated by reputable providers. No method of transmission or storage is perfectly secure, but we work to protect your data and to respond promptly to any incident.
11 Children
The Service is a developer tool intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12 Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify account holders by email. Your continued use of the Service after a change means you accept the updated policy.
13 Contact
Questions about this policy or about how we handle your data? Email [email protected].