Privacy
Last updated 11 October 2026.
Who we are
OneAPI is made by CloudCircus. Contact us at support@cloudcircus.com. OneAPI is hosted in the EU.
An organisation (company) decides who is a member, what its models do and which systems it connects. For the data that passes through OneAPI on its behalf, the organisation is the data controller and we process it on its behalf.
What we store
- Your account: email address, name (if you add it), and a hashed password or the social login you used. If your organisation requires signing in with Microsoft or Google, we also store when you last did.
- Organisations: their name and email domains, members and their roles, groups, invites, models, applications and what each may call, and a history of these changes (who changed what, and when).
- Tokens: only a hash of each token, its name, scopes, when it was last used and from which IP address.
- Credentials for connected systems (API keys, OAuth tokens), encrypted with a key per organisation. They're never shown again once entered.
- The call log: for every call, who made it (and for whom), from which IP address, which model, operation and record, the names of the fields it changed, the result, and the addresses of the calls OneAPI made to the connected system. Not the data in the requests or responses. Kept as long as the organisation chooses (90 days unless it changes that).
Data from connected systems
OneAPI passes data between your callers and your connected systems without storing it, with these exceptions, each encrypted with the organisation's key:
- Sample responses an integrator captures while building a mapping, kept for 30 days and shown only to integrators.
- The response to a write sent with an Idempotency-Key, kept for 24 hours so a retried request gets the same answer.
- Responses an organisation chooses to cache for a model, kept for the time it sets (usually seconds or minutes).
Who can see it
Only members of the organisation see its models, applications and history. The call log is shown to its owners, admins and integrators; members see the calls made by or for them. We don't sell data, show ads, or send your data to AI services.
Emails we send
Invites, account emails (confirming your address, resetting your password), and a note to the inviter when an invite is accepted. Data from connected systems is never put in an email.
Logs
Our server keeps technical logs (such as IP addresses and requested pages) for 30 days, to run and secure the service.
Deleting data
Owners can delete their organisation, which deletes everything in it at once, including its call log and credentials. To delete your account, email support@cloudcircus.com from your account's address.