Legal

Privacy Policy

Last updated: 30 July 2026 · Version 1.1

This Privacy Policy explains how personal data is collected, used, shared, and protected when you visit oden-api.com or use the ODEN web search API (the “Service”). We take a deliberately minimal approach: we process only what we need to run the Service, bill it, and keep it secure.

1 Who we are

The data controller responsible for your personal data is:

  • Samie Stenberg (sole trader / enskild firma), trading as ODEN
  • Address: Briggvägen 35, 826 60 Söderhamn, Sweden
  • Email: support@oden-api.com

We have not appointed a Data Protection Officer, as we are not legally required to. For any privacy question, use the contact email above.

2 Scope

This policy covers personal data we process as a controller — that is, the data of our account holders and website visitors. It does not cover how you, as our customer, use the Service to process other people's data; where the text of your search queries contains personal data, you act as controller for that data and we process it on your behalf. Business customers who need a Data Processing Agreement (DPA) for that purpose can request one at the contact email above.

3 Data we process

Depending on how you use the Service, we process the following categories of personal data:

Account & identity

Your email address, an account identifier, and any optional display name, collected when you create an account. Authentication is handled through our auth provider (Supabase).

API credentials

The API key(s) issued to your account, together with associated metadata: your plan, top-up balance, and creation date. These are stored in Cloudflare KV.

Usage records

The number of searches made per billing period, linked to your API key and account identifier, with timestamps. These are stored in a Cloudflare D1 database and are used to enforce quotas and to bill you accurately.

Billing data

Payments are processed by Stripe. Stripe holds your payment method, billing email, and (for businesses) VAT identification number. We receive and keep a Stripe customer reference, your subscription status, and records of completed payments and top-ups. We never see or store full card numbers.

Technical & security data

Your IP address, used transiently to apply rate limits and protect the Service against abuse; request trace identifiers; and short-lived diagnostic logs.

Search queries & results

The text you send to the Service is processed in real time to fetch and synthesise results. Query text may appear in short-lived operational logs (retained up to 7 days) and in a shared results cache (retained up to 1 hour, keyed by an anonymised hash rather than by your identity). We do not store your queries against your account, and we do not use them to build a profile of you.

4 Purposes & legal bases

We process personal data for the following purposes, each with a legal basis under the GDPR (Article 6):

PurposeLegal basis
Provide the Service, issue API keys, return resultsPerformance of a contract (Art. 6(1)(b))
Meter usage and enforce quotasPerformance of a contract (Art. 6(1)(b))
Process payments and manage subscriptionsPerformance of a contract (Art. 6(1)(b))
Keep accounting and tax recordsLegal obligation (Art. 6(1)(c))
Secure the Service, prevent abuse, apply rate limitsLegitimate interests (Art. 6(1)(f))
Send essential service communicationsPerformance of a contract / legitimate interests
Optional marketing emails (if any)Consent (Art. 6(1)(a)), withdrawable any time

Where we rely on legitimate interests, that interest is operating a secure, reliable, and abuse-resistant service. We have balanced this against your rights and consider the processing proportionate and expected.

5 Cookies & local storage

The Service uses only strictly necessary cookies and local storage — primarily to keep you signed in to your dashboard (set by our auth provider). These are essential to deliver a service you have requested and do not require consent under the Swedish Electronic Communications Act / ePrivacy rules.

Web fonts are self-hosted on our own domain, so viewing the site sends your IP address to no font provider. We use no advertising cookies, no third-party analytics, and no cross-site trackers.

Cookieless site analytics

We measure how the website is used with a first-party, cookieless counter that we built and host ourselves. It sets no cookie, reads no cookie, and writes nothing to your device — so there is no identifier to consent to under ePrivacy Article 5(3), which is why you see no cookie banner. It also honours the browser Do Not Track and Global Privacy Control signals, and ignores automated traffic.

For each page view we record: the page path, the referring site's host (never the full URL), your country and (for larger countries) city as Cloudflare reports it, a coarse device / operating-system / browser category, viewport and screen size, timezone, and any UTM campaign tags in the link you followed. We do not store your IP address. Instead it is hashed with SHA-256 against a random salt that is regenerated every 24 hours and then discarded; once the day rolls over, the input that produced the hash no longer exists anywhere, so the rows become permanently unlinkable. A short-lived session identifier derived from that hash lets us count a visit without a cookie and cannot outlive the day's salt.

This data is anonymous, is used only in aggregate to understand traffic, is never sold or shared with third parties, and is deleted automatically after 180 days. You can read the exact fields and hashing design, and audit the beacon, at /a.js.

6 Recipients & sub-processors

We do not sell your personal data and do not share it for advertising. We share data only with the service providers we rely on to run ODEN, each acting as our processor under contract:

ProviderRole
Cloudflare, Inc.Hosting, edge compute, AI inference, KV/D1 storage, rate limiting
SupabaseAuthentication and account database
StripePayment processing

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and property of ODEN, our users, or others.

7 International transfers

ODEN is operated from the EU and we keep data within the European Economic Area (EEA) wherever practical. Some of our providers (such as Cloudflare and Stripe) operate globally and may process personal data outside the EEA, including in the United States.

Where data is transferred outside the EEA, we rely on appropriate safeguards: an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified) and/or the European Commission's Standard Contractual Clauses. You can request more detail about a specific transfer at our contact email.

8 Retention

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it:

DataRetention
Account & API key dataFor the life of your account; deleted or anonymised within 90 days of account closure, unless we must keep it longer for legal reasons
Usage & billing recordsUp to 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen)
Operational logsUp to 7 days
Results cacheUp to 1 hour
Cookieless site analyticsUp to 180 days (IP salt discarded every 24 hours)

9 Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have your data deleted, subject to our legal retention duties.
  • Restriction — limit how we process your data in certain cases.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these, email us at support@oden-api.com. We will respond within one month. You also have the right to lodge a complaint with the Swedish supervisory authority:

Supervisory authority

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
imy@imy.se · +46 8 657 61 00 · imy.se

10 Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, secret management, scoped API keys, rate limiting, and storage on infrastructure operated by reputable providers. No method of transmission or storage is perfectly secure, but we work to protect your data and to respond promptly to any incident.

11 Children

The Service is a developer tool intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

12 Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify account holders by email. Your continued use of the Service after a change means you accept the updated policy.

13 Contact

Questions about this policy or about how we handle your data? Email support@oden-api.com.