NOTTHEREALAPI · POLICY
Privacy Policy
Last updated: 29 September 2026
This Privacy Policy explains what information NotTheRealAPI collects, why we use it, how long we keep it, and the choices you have.
Who we are
NotTheRealAPI is responsible for the personal information described here. You can reach us at support@nottherealapi.com.
Information we collect
When you use NotTheRealAPI, we collect details such as your name, email address, account information, workspace and team membership, subscription status, and settings or configuration you enter into the service. If you contact us for support, we also handle your messages and the information you choose to share.
If you create a password account, your password is securely hashed and is never stored in plaintext.
Test request data
Test requests can include an HTTP method, path, headers, query values, request body, response data, timestamps and related request details. We use this information to show you what your endpoint received and how it responded.
NotTheRealAPI is designed for test data. We redact common sensitive headers and configured sensitive fields before supported request data is stored. Unsupported or malformed content may be omitted instead of field-redacted, and no automated redaction system can identify every secret or piece of personal data. Do not send real production credentials, secrets or personal information unless genuinely required for your test.
Treat receiver URLs like secrets. Anyone with a valid receiver URL may be able to send requests to that endpoint. Keep URLs private, and rotate or delete an endpoint if its URL is exposed.
How we use your information
We use information to:
- create and secure accounts;
- provide workspaces and collaboration;
- receive and display test requests and return configured mock and scenario responses;
- manage subscriptions and billing;
- send account and service messages;
- prevent abuse, investigate faults and meet legal obligations.
Where UK data protection law applies, we generally use information because we need it to provide the service you asked for, because we have a legitimate interest in keeping the service secure and reliable, or because we have a legal obligation. Where we rely on consent, you can withdraw it at any time.
Sign-in and payments
If you choose to sign in with GitHub, Google or Microsoft, that provider processes the information needed to authenticate you. These options are available only when enabled. You may also be able to sign in with an email address and password.
Stripe processes payments. We keep the billing identifiers and subscription status needed to manage your access, but we do not store your full payment card details.
Who we share information with
We use trusted service providers to host and operate NotTheRealAPI and to deliver account-related email. Stripe handles payments, and a sign-in provider handles authentication if you choose to use it.
How long we keep information
Test request history is kept for up to 30 days and is limited to the latest 10,000 requests per workspace.
We may keep some account, billing or security records for longer where needed for legal, accounting, fraud-prevention or dispute purposes. Deleted information may remain in backups for a limited period until those backups expire.
Deleting your account
You can delete your account from Account Settings. This removes your account, sessions, connected sign-in methods, personal workspace and related data. It also ends any subscription for that personal workspace. Other members lose access to that workspace, but their own accounts remain. Some records may be kept for the reasons above or temporarily in backups.
International transfers
Some of our service providers may process information outside the UK. Where required, we use appropriate safeguards for international transfers.
Your rights
Depending on the circumstances, you may have rights to access, correct or delete your information, restrict or object to how we use it, and receive a portable copy of some information. If we rely on your consent, you can withdraw it at any time. You can complain to the UK Information Commissioner’s Office.
Automated decisions
We use automated technical controls such as rate limits and security checks. We do not currently use automated decision-making that produces legal or similarly significant effects about you.
Contact us
Questions about this policy or your information? Email us at support@nottherealapi.com.

