Operated by Datavidence LLC ("Datavidence," "we," "us")
Applies to the Datavidence Financials API and the datavidence.ai websites (the "Service")
Effective date: September 14, 2026 · Last updated: September 23, 2026
1. Who we are
Datavidence LLC operates the Datavidence Financials API, a service that delivers normalized US-GAAP financial statements derived from public SEC EDGAR filings. For any privacy question, contact admin@datavidence.ai.
2. Scope
This policy covers personal data we process when you use the API or visit our websites. It does not cover third-party marketplaces (such as RapidAPI or AWS Data Exchange) through which you may subscribe — those platforms handle your account registration, identity, and payment under their own privacy policies.
3. Data we process
A note on what we do not collect. The financial Data the Service returns is public information about public companies, not personal data about you. For customers who subscribe through a marketplace, we do not store your name, email, or payment-card details — the marketplace handles registration and billing. A marketplace may forward identifiers with each request (for example, your marketplace username or plan); we do not record them.
We process the following:
API credentials. We store a cryptographic hash of your API Key (not the key itself), together with your plan tier and quota counters. We cannot recover your raw key from the hash.
Usage logs. For each API request we record the endpoint called, HTTP status, response time, timestamp, and the IP address of the request, associated with the (hashed) key that made it. For requests that come through a marketplace, the IP address we see is usually the marketplace's gateway rather than yours. IP address may constitute personal data in some jurisdictions. Website page views are not written to usage logs.
Server logs. Our web server and application also write a short technical log line for every request, including website page views, which contains the IP address and the page or endpoint requested. These logs are used only to debug problems and are size-capped (see Retention).
Operational metrics. Aggregate, non-identifying counters (latency distributions, cache hit-rate, error counts) used to monitor service health.
Communications. If you email us (e.g., admin@datavidence.ai), we process the contents and your address to respond.
Website. Our websites set no cookies and use no analytics or tracking tools. One exception to “no third parties”: the datavidence.ai homepage loads its fonts from Google Fonts, so when you open it your browser sends your IP address and browser details to Google, under Google's privacy policy. If we add analytics later, we will update this policy to disclose the provider and purpose.
4. Why we process it (purposes)
To provide the Service — authenticate requests and enforce plan quotas and rate limits.
Security and abuse prevention — detect and mitigate misuse, credential compromise, and attempts to exceed limits (IP logging supports this).
Reliability and debugging — diagnose errors and monitor performance.
Billing support — reconcile usage where a channel requires it.
Where a legal basis is required (e.g., under the GDPR), we rely on performance of a contract (providing the Service you request) and our legitimate interests in operating, securing, and improving the Service.
5. How we share data
We do not sell your personal data. We share it only with:
Marketplace gateways (e.g., RapidAPI, AWS Data Exchange) that mediate your subscription and metering, as applicable.
Infrastructure providers that host the Service and its backups (currently Oracle Cloud Infrastructure) and process data on our behalf to run it.
Email providers. Mail sent to admin@datavidence.ai is routed by Cloudflare and delivered to a Google (Gmail) mailbox, so those providers process it.
Google Fonts, as described under “Website” above.
Legal / safety — where required by law, or to protect our rights, users, or the public.
6. Retention
Hashed API Key and quota state — for as long as the key is active.
Usage logs — 12 months, for security, billing reconciliation, and debugging. A daily job deletes entries older than that.
Backups — our database backups are kept for 30 days, so data we delete also disappears from backups within 30 days.
Server logs — kept in size-capped files that are overwritten as new traffic arrives, typically within days to weeks, and never beyond the next redeploy of the service.
Emails — for as long as needed to handle your request and any follow-up.
7. Security
We protect data with measures appropriate to its sensitivity, including storing API keys only as hashes, encrypting data in transit (TLS), and restricting administrative access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Wherever you live, you can ask us, at admin@datavidence.ai, what data we hold that is tied to your API key, or ask us to delete it. We will do either.
Because we don't hold your name or email (unless you have emailed us), we can only find your records through your API key. We may ask you to prove you control that key, for example by making a request with it, before sharing or deleting anything.
Privacy laws such as the EU/UK GDPR or California's CCPA may give you further rights where they apply to us; where they do, we will respond as they require. We do not sell personal data or share it for advertising.
9. International transfers
We operate from the United States and our infrastructure is US-hosted. If you access the Service from outside the US, you understand your data will be processed in the US. We do not currently have a formal transfer mechanism (such as the EU Standard Contractual Clauses) in place; if we onboard EU/UK customers directly, we will put one in place and update this policy.
10. Children
The Service is a business/developer tool, is not directed to children, and we do not knowingly collect personal data from anyone under 16.
11. Changes
We may update this policy; we will revise the effective date and, for material changes, provide reasonable notice. Continued use after changes take effect constitutes acceptance.