Privacy Policy
Last updated: August 3, 2026
This policy explains what personal data IMEIAPI.org("we") collects, why we collect it, and the choices you have. We keep data collection to the minimum needed to run the Service.
1. Data we collect
Contact data. If you write to us through the contact form or by e-mail, we receive your name, e-mail address and the content of your message, and keep the correspondence to handle your request.
Account data. Creating an account stores your e-mail address and a hash of your password — never the password itself. We also keep the state of your account: whether it is on trial, how many lookups remain, and when they expire.
Payment data. When purchasing becomes available, billing details will be handled by our payment provider. We do not store full card numbers.
API usage data. Once the API is live we log requests (queried IMEI, timestamp, response status, API key used) to run the Service, draw down your prepaid balance and prevent abuse. IMEI numbers identify devices, not people; we do not link them to device owners.
2. Cookies
Strictly necessary.Signing in sets two cookies. One holds your session token and is not readable by scripts; the other is a plain flag that lets the site show “Dashboard” instead of “Sign in” without asking the server. It grants no access on its own. Both are deleted when you sign out. These are required for the account to work, so they are not subject to consent.
Analytics — only if you agree. We use Google Tag Manager and Google Analytics to understand how the site is used. They set cookies, and they are switched off until you accept them in the banner. We implement Google Consent Mode v2: before any decision, all analytics and advertising signals are set to denied, and the tag container is not loaded at all. Declining is a real choice — the site behaves identically either way.
Your light/dark theme preference is kept in your browser's local storage, not in a cookie, and is never sent to us. To change a consent decision, clear this site's data in your browser and the banner will appear again.
3. Analytics
With your consent, Google Analytics collects aggregated usage data: pages visited, approximate region, device and browser type. We use it to see which parts of the documentation and journal are worth expanding. It is not used to identify you personally, and without your consent the tools do not load at all.
4. Legal bases (GDPR)
We process data to perform our contract with you (account, API, payments), to pursue our legitimate interests (service security, abuse prevention, aggregate statistics), to comply with legal obligations (accounting), and — for anything requiring consent — based on the consent you give.
5. Sharing
We share data only with processors necessary to run the Service: hosting infrastructure, our content delivery network, the database service, e-mail delivery, payment processing and — with your consent — Google Analytics. We do not sell personal data.
6. Retention
Correspondence is kept for as long as needed to handle your request and our records of it. Account data is kept for as long as your account exists, including the 12-month life of any prepaid balance. Session records expire after 30 days; password reset tokens after one hour. API logs are kept for up to 24 months as payment evidence and for abuse prevention, then deleted or anonymized. Accounting records are kept as required by law.
7. Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, restriction of or objection to its processing, and a portable copy. You can also lodge a complaint with your data protection authority. To exercise your rights, contact [email protected].
8. Security
All traffic to the website and API is encrypted with TLS. Passwords are stored as scrypt hashes with a per-password salt, and session tokens are stored only as hashes — a copy of the database would not let anyone sign in as you. API access requires per-account keys, and internal access to production data is limited to what is necessary to operate the Service.
9. Changes to this policy
We may update this policy as the Service evolves — for example when accounts, payments or analytics launch. The current version is always available at imeiapi.org/privacy with the date of the last update shown above.
10. Contact
Privacy questions and requests: [email protected].