Privacy Policy

Effective: September 12, 2025

Who we are: SecFilingApi ("we," "us," "our") — a service being built at secfilingapi.com to turn SEC filings into clean, queryable JSON.

This Privacy Policy explains what we collect right now (primarily waitlist emails), how we use it, and the choices you have. We'll update this policy as the product evolves.

1 What we collect

Email address you submit to join the waitlist.

Optional data you choose to share (e.g., name, role, company, use case).

Basic logs from our website host/CDN (e.g., IP address, user agent, pages viewed) for security and reliability.

Referral info (e.g., ?s=source or UTM params) if present in the URL.

No sensitive personal data (e.g., health, biometric, precise location) is requested or required.

2 How we use your information

Waitlist & updates. To email you about development progress, early access, schema drafts, and launch news.

Product planning. To understand demand, prioritize features, and improve the service.

Security & reliability. To ensure the site works and to detect abuse or errors.

Legal compliance. To comply with applicable laws and enforce our Terms.

We do not sell your personal information. We also don't use your data for interest-based advertising.

3 Lawful bases (EEA/UK)

If you're in the EEA/UK, we process your personal data on the basis of:

Consent (you opted into the waitlist)

Legitimate interests (site security, service reliability, product planning)

You can withdraw consent any time via unsubscribe or by contacting us.

4 Sharing with service providers ("processors")

We use trusted third parties to help us operate the site and send emails. These may include:

Hosting/CDN (e.g., Cloudflare, Hetzner or similar)

Email delivery (e.g., Postmark, AWS SES, Mailgun or similar)

Error monitoring/analytics (added only if/when enabled)

Processors only receive what's needed to provide their services and must protect your data. We'll update this list as our vendors change.

5 Data retention

Waitlist data: kept until you unsubscribe or we clean inactive records.

Server logs: retained for a limited period for security and troubleshooting, then deleted or anonymized.

6 Your choices & rights

Unsubscribe at any time via the link in our emails or by writing to [email protected]

Access, correct, delete. You can request a copy or deletion of your data.

EEA/UK/California rights. Where applicable, you may have additional rights (portability, restriction, objection). We do not "sell" or "share" personal information as defined by the CPRA.

International transfers

We may process data in countries other than yours. Where required, we use appropriate safeguards (e.g., SCCs) with our processors.

Security

We use reasonable technical and organizational measures (e.g., TLS in transit, restricted access) to protect your data. No system is 100% secure.

Children's privacy

This site is not directed to children under 16, and we don't knowingly collect their data.

Changes to this policy

We'll post updates here and change the "Effective date." Material changes may be announced via email to waitlist subscribers.

Contact

SecFilingApi

[email protected]