Privacy Policy
Last updated September 16, 2026
socialmediaapi.lol is a read only data API. This policy explains what we store about the people who use the service, what we do not store, and the choices you have.
What we collect
We collect the minimum needed to run an API business: the email address and display name returned by Google when you sign in, an internal account identifier, and the request metadata for the calls you make.
Payment details are handled entirely by our payment processor. We never see or store card numbers.
- Account details: email address, display name, profile picture URL
- Billing records: plan, billing period and invoice history
- Usage records: endpoint path, timestamp, credit cost and response status
- Technical data: IP address and user agent, retained for abuse prevention
What we do not collect
We never ask for a Facebook or Instagram password, and we never ask you to connect a personal social account. There is no logged in session or cookie jar belonging to you on our servers.
Because requests are made against public surfaces only, no private messages, private groups or restricted content is ever retrieved, processed or stored by this service.
How we use your data
Account and usage data are used to authenticate you, provision your API keys, meter credit consumption, prevent abuse and provide support. We do not sell personal data.
Aggregated, non identifying operational metrics such as request volume per endpoint are used to plan capacity and reliability work.
Data we return to you
Responses contain publicly available information about social media accounts and advertisements, which is not personal data in our possession. You are responsible for ensuring your use of that data complies with applicable law, including data protection rules in your jurisdiction.
We do not retain response payloads after the response has been delivered. If you need to keep the data, store it in your own systems.
Sub processors
We use a small number of vendors to operate the service: a cloud hosting provider for compute and storage, our payment processor for billing, and an email provider for transactional mail. Each is bound by a data processing agreement.
Retention and deletion
Account records are kept while your account is active. When you delete your account, account details and API keys are removed within 30 days. Billing records are retained for as long as tax law requires.
You can request export or deletion of your account data at any time by emailing support.
Your rights
Depending on where you live you may have the right to access, correct, export or delete the personal data we hold, and to object to certain processing. Email us and we will respond within 30 days.
Children
The service is intended for developers and organisations and is not directed at children under 16. We do not knowingly collect data from children.
Changes
If this policy changes materially we will update the date at the top of the page and email account holders. Continued use after a change means you accept the updated policy.