This policy explains what personal data DuelAPI collects, why, and what you can do about it. Contact: duelapi@proton.me.
1. Data we collect about customers
- Payment and billing details. Stripe handles checkout and stores your card details; we never see full card numbers. We receive your email address, name, billing country and your Stripe customer and subscription IDs.
- API key and usage. For each key we store its plan, credit balance, when it was created and last used, and request counts.
- Technical data. Your IP address is used for rate limiting and abuse prevention (for example, one free key per IP per day) and may appear in server logs.
- Website analytics. We use Simple Analytics, which doesn't use cookies or collect personal data and respects Do Not Track.
- Your browser. The subscription page remembers your API key in your own browser (local storage) so you don't have to paste it again. It stays on your device.
We don't use advertising or tracking cookies.
2. How we use it
- To run the service: issue keys, count credits, apply rate limits and deliver data.
- To take payments and send your API key and billing emails.
- To prevent abuse and keep the service secure.
- To answer you when you contact us.
We process this data to perform our contract with you, to meet legal obligations (such as keeping payment records), and for our legitimate interest in keeping the service secure.
3. Who we share it with
- Stripe, for payments and the billing portal.
- Our email provider, to send your key and account emails.
- Our hosting provider, which runs the servers.
We don't sell your personal data or share it for advertising. We may disclose data if the law requires it.
4. Data about Duel.com users
The API republishes information that Duel.com users made public on Duel.com: usernames and player IDs, bets and results, public chat messages, rock-paper-scissors matches and the public leaderboard. We don't collect this from our customers, and we don't combine it with customer data.
If you're a Duel.com user and want your information removed from DuelAPI, email duelapi@proton.me with your username. We'll remove what we hold and stop republishing it where we reasonably can.
5. How long we keep it
- Key and usage records: while the key exists, then deleted within 90 days unless we need them for billing records.
- Payment records: as long as tax and accounting law requires.
- Server logs: kept for a limited period for security and troubleshooting.
- Duel.com data: bets are kept for about a day in memory and in daily files; round history and aggregates are kept longer.
6. Your rights
Depending on where you live (for example under the GDPR or the CCPA), you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and complain to your data protection authority. Email duelapi@proton.me and we'll respond within 30 days.
7. Security
Connections to the site and API use HTTPS. Access to customer data is restricted, and payment details stay with Stripe. No system is perfectly secure; keep your API key private, and reset it if it leaks.
8. Children
The service is for people aged 18 or over, and we don't knowingly collect data from anyone younger.
9. Changes
We'll update the date at the top when this policy changes, and tell paying customers by email about significant changes.