Privacy Policy
Last updated: October 3, 2026
Introduction
This Privacy Policy describes how ReqPad ("we", "us", or "our") collects, uses, and shares information when you use our mobile application ("App").
By using ReqPad, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Information You Provide
- API Requests: The URLs, headers, and request bodies you create are stored locally on your device. We do not have access to this data, except for the redacted excerpts you choose to send to ReqPad AI (see AI Features).
- Collections: Your saved API collections and environments are stored locally on your device.
Information Collected Automatically
When you use our App, we automatically collect certain information:
- Analytics Data: We use Firebase Analytics to collect anonymous usage statistics such as app opens, feature usage, and screen views. This helps us improve the App.
- Crash Reports: We use Sentry to collect crash reports and error logs. This includes device type, operating system version, and stack traces. This data is used solely to identify and fix bugs.
- Device Information: Basic device information such as device model, operating system version, and app version.
Purchase Information
If you make in-app purchases, payment processing is handled by Apple (App Store) or Google (Play Store). We use RevenueCat to manage subscriptions and receive:
- Purchase status (active/expired)
- Subscription type
- Anonymous purchase identifiers
We do not have access to your payment details (credit card numbers, billing address, etc.).
How We Use Information
We use the collected information to:
- Provide and maintain the App
- Improve and optimize the App experience
- Identify and fix bugs and crashes
- Process and manage subscriptions
- Send push notifications (with your permission) about updates and promotions
Data Storage
- Local Data: Your API requests, collections, and environments are stored locally on your device. We do not upload this data to our servers. When you use an AI feature, a redacted excerpt is processed as described in AI Features and is not stored.
- Analytics & Crash Data: Stored securely on Firebase and Sentry servers.
- Subscription Data: Stored securely on RevenueCat servers.
AI Features (ReqPad AI)
ReqPad AI is optional. It can explain a response or error, write a request from your description, write tests for a response, and turn a question about a JSON response into a JSONPath query. Nothing is sent until you agree to the notice shown before your first AI action, and only when you start an AI action.
- What is sent: only what the action needs — the request and response (or error) you ask about, with bodies shortened (about 8 KB of request body and 12 KB of response body); your description and the names (never values) of the environment variables it mentions; when writing a WebSocket, Socket.IO, MQTT, gRPC or MCP message or a GraphQL query, the last few messages on the connection (redacted), the schema it must follow and the editor's current text; or your question with a structural sample of the JSON (keys, types and the first items of lists). The app shows you exactly what will be sent before you agree.
- Secrets are removed on your device first: Authorization,
Proxy-Authorization, Cookie, Set-Cookie and X-Api-Key headers, any header, query
parameter or JSON field whose name looks like a token, key, secret or password, values
that look like credentials (Bearer/Basic tokens, JWTs, common API key formats), and the
values of your secret environment variables are replaced with
[redacted]or the variable's name. - Who processes it: our AI service runs on Cloudflare Workers and uses open-weight models hosted on Cloudflare Workers AI. Cloudflare processes the data on our behalf to produce the answer; it is not used to train AI models.
- Retention: ReqPad does not store or log the content of AI requests or answers. To apply free and Pro limits we keep only a count of AI actions per anonymous RevenueCat app user ID, and a short-lived cache of whether that ID has ReqPad Pro.
- Your choice: you can turn AI features off at any time in Settings → AI, which hides them everywhere, and ask to be shown the consent notice again. To delete your AI usage counter, contact us with your Support ID.
Third-Party Services
We use the following third-party services:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Firebase Analytics | Usage analytics | Google Privacy Policy |
| Firebase Cloud Messaging | Push notifications | Google Privacy Policy |
| Sentry | Crash reporting | Sentry Privacy Policy |
| Cloudflare Workers AI | Runs ReqPad AI (only when you use an AI feature) | Cloudflare Privacy Policy |
| RevenueCat | Subscription management | RevenueCat Privacy Policy |
Data Retention
- Analytics Data: Retained for 14 months, then automatically deleted.
- Crash Reports: Retained for 90 days, then automatically deleted.
- AI Features: Request and answer content is not retained. AI action counters are kept while you use the app (free actions count for the lifetime of the install's anonymous ID; Pro actions per calendar month).
- Subscription Data: Retained as long as you have an active subscription, plus as required by law.
Your Rights
Depending on your location, you may have the following rights:
For All Users
- Access: Request a copy of your data
- Deletion: Request deletion of your data
- Opt-out: Limit ad/analytics tracking through your device's privacy settings, or contact us to request opt-out and deletion
For EU/EEA Users (GDPR)
- Right to access, rectify, or erase your personal data
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent
For California Users (CCPA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (Note: We do not sell your data)
- Right to non-discrimination
Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (HTTPS/TLS)
- Secure cloud infrastructure
- Regular security reviews
This Website
reqpad.app is a static site. We use Cloudflare Web Analytics — a privacy-friendly, cookieless service that reports aggregate traffic (page views, referrers, country) without tracking individuals across sites.
Children's Privacy
ReqPad is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: support@reqpad.app
This privacy policy is effective as of October 3, 2026.