Legal

Privacy Policy

Last updated: 30 June 2026 · Version 1.0

This Privacy Policy explains how personal data is collected, used, shared, and protected when you visit oden-api.com or use the ODEN web search API (the “Service”). We take a deliberately minimal approach: we process only what we need to run the Service, bill it, and keep it secure.

1 Who we are

The data controller responsible for your personal data is:

  • Samie Stenberg (sole trader / enskild firma), trading as ODEN
  • Address: Briggvägen 35, 826 60 Söderhamn, Sweden
  • Email: [email protected]

We have not appointed a Data Protection Officer, as we are not legally required to. For any privacy question, use the contact email above.

2 Scope

This policy covers personal data we process as a controller — that is, the data of our account holders and website visitors. It does not cover how you, as our customer, use the Service to process other people's data; where the text of your search queries contains personal data, you act as controller for that data and we process it on your behalf. Business customers who need a Data Processing Agreement (DPA) for that purpose can request one at the contact email above.

3 Data we process

Depending on how you use the Service, we process the following categories of personal data:

Account & identity

Your email address, an account identifier, and any optional display name, collected when you create an account. Authentication is handled through our auth provider (Supabase).

API credentials

The API key(s) issued to your account, together with associated metadata: your plan, top-up balance, and creation date. These are stored in Cloudflare KV.

Usage records

The number of searches made per billing period, linked to your API key and account identifier, with timestamps. These are stored in a Cloudflare D1 database and are used to enforce quotas and to bill you accurately.

Billing data

Payments are processed by Stripe. Stripe holds your payment method, billing email, and (for businesses) VAT identification number. We receive and keep a Stripe customer reference, your subscription status, and records of completed payments and top-ups. We never see or store full card numbers.

Technical & security data

Your IP address, used transiently to apply rate limits and protect the Service against abuse; request trace identifiers; and short-lived diagnostic logs.

Search queries & results

The text you send to the Service is processed in real time to fetch and synthesise results. Query text may appear in short-lived operational logs (retained up to 7 days) and in a shared results cache (retained up to 1 hour, keyed by an anonymised hash rather than by your identity). We do not store your queries against your account, and we do not use them to build a profile of you.

4 Purposes & legal bases

We process personal data for the following purposes, each with a legal basis under the GDPR (Article 6):

PurposeLegal basis
Provide the Service, issue API keys, return resultsPerformance of a contract (Art. 6(1)(b))
Meter usage and enforce quotasPerformance of a contract (Art. 6(1)(b))
Process payments and manage subscriptionsPerformance of a contract (Art. 6(1)(b))
Keep accounting and tax recordsLegal obligation (Art. 6(1)(c))
Secure the Service, prevent abuse, apply rate limitsLegitimate interests (Art. 6(1)(f))
Send essential service communicationsPerformance of a contract / legitimate interests
Optional marketing emails (if any)Consent (Art. 6(1)(a)), withdrawable any time

Where we rely on legitimate interests, that interest is operating a secure, reliable, and abuse-resistant service. We have balanced this against your rights and consider the processing proportionate and expected.

5 Cookies & local storage

The Service uses only strictly necessary cookies and local storage — primarily to keep you signed in to your dashboard (set by our auth provider). These are essential to deliver a service you have requested and do not require consent under the Swedish Electronic Communications Act / ePrivacy rules.

The website loads web fonts from Google Fonts, which transmits your IP address to Google in order to serve the font files. We do not use advertising or third-party analytics cookies. If we introduce analytics in future, we will update this policy and ask for your consent where required.

6 Recipients & sub-processors

We do not sell your personal data and do not share it for advertising. We share data only with the service providers we rely on to run ODEN, each acting as our processor under contract:

ProviderRole
Cloudflare, Inc.Hosting, edge compute, AI inference, KV/D1 storage, rate limiting
SupabaseAuthentication and account database
StripePayment processing
Google (Fonts)Serving web fonts (receives IP address)

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and property of ODEN, our users, or others.

7 International transfers

ODEN is operated from the EU and we keep data within the European Economic Area (EEA) wherever practical. Some of our providers (such as Cloudflare, Stripe, and Google) operate globally and may process personal data outside the EEA, including in the United States.

Where data is transferred outside the EEA, we rely on appropriate safeguards: an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified) and/or the European Commission's Standard Contractual Clauses. You can request more detail about a specific transfer at our contact email.

8 Retention

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it:

DataRetention
Account & API key dataFor the life of your account; deleted or anonymised within 90 days of account closure, unless we must keep it longer for legal reasons
Usage & billing recordsUp to 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen)
Operational logsUp to 7 days
Results cacheUp to 1 hour

9 Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have your data deleted, subject to our legal retention duties.
  • Restriction — limit how we process your data in certain cases.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these, email us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with the Swedish supervisory authority:

Supervisory authority

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
[email protected] · +46 8 657 61 00 · imy.se

10 Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, secret management, scoped API keys, rate limiting, and storage on infrastructure operated by reputable providers. No method of transmission or storage is perfectly secure, but we work to protect your data and to respond promptly to any incident.

11 Children

The Service is a developer tool intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

12 Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify account holders by email. Your continued use of the Service after a change means you accept the updated policy.

13 Contact

Questions about this policy or about how we handle your data? Email [email protected].