YourFoodAPI ← Back to landing

Legal

Privacy Policy

How YourFoodAPI collects, uses, and protects personal data — written in plain English, structured to satisfy the EU GDPR.

Last updated: June 16, 2026

1. Who is the data controller

YourFoodAPI is operated by Wojciech Skrzek, trading as WebMoose, a Polish sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland under tax number NIP 646-292-67-00, with registered address at ul. Zapolskiej 22/12, 43-100 Tychy, Poland.

For any privacy questions, data subject requests, or breach notifications: api@yourfoodapi.com.

2. What personal data we process

YourFoodAPI is a data API. We do not run user accounts, do not handle payments directly, and do not collect any data you don't actively send us. In practice we process:

2.1 Server access logs

When you visit yourfoodapi.com or your application sends a request to api.yourfoodapi.com, our infrastructure automatically records:

  • Your IP address
  • Date and time of the request
  • Requested URL and HTTP method
  • HTTP status code returned
  • User agent (browser or library identifier)
  • Referrer (where applicable)

These records are kept for up to 30 days and are used solely for security, abuse prevention, and debugging.

2.2 Marketplace data via RapidAPI

Subscriptions, billing, and your API key are handled entirely by RapidAPI (Nordic APIs Inc., d/b/a RapidAPI). When you authenticate against our API through the RapidAPI gateway, we receive an opaque identifier that lets us enforce per-subscription quotas — we do not receive your name, email, or payment details. See the RapidAPI Privacy Policy for how they process your account information.

2.3 Analytics on the landing page

The marketing website yourfoodapi.com uses Google Analytics 4 only after you give explicit consent through our cookie banner. Until you accept, no analytics cookies are set and no data is sent to Google. If you accept, Google Analytics receives:

  • A pseudonymous identifier in the _ga cookie
  • Page views, session duration, and approximate geographic region
  • Device type and browser

IP addresses are anonymized before storage in line with Google Analytics 4 defaults. You can withdraw consent at any time using the "Cookie preferences" link in the footer or by clearing your browser cookies.

3. Legal basis

We rely on the following legal bases under Article 6 GDPR:

PurposeLegal basis
Operating the API and website (logs)Legitimate interest, Art. 6(1)(f)
Performing the API service for subscribersContract performance, Art. 6(1)(b)
Security and abuse preventionLegitimate interest, Art. 6(1)(f)
AnalyticsConsent, Art. 6(1)(a)
Responding to your emailsLegitimate interest, Art. 6(1)(f)

4. Who we share data with

We do not sell personal data. We rely on the following processors who help us deliver the service:

  • Cloudflare, Inc. — DNS, CDN, DDoS protection. Receives request metadata and IP. Data is processed under Cloudflare's DPA with EU SCCs.
  • Hosting provider in the EU — runs the API server. Processes logs as described above.
  • RapidAPI (Nordic APIs Inc.) — gateway and marketplace operator.
  • Google Ireland Ltd. — analytics, only after your consent.

Where data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and supplementary measures as appropriate.

5. How long we keep your data

  • Access logs: up to 30 days, then deleted automatically
  • Email correspondence: up to 24 months after the last message
  • Analytics events (if you opted in): 14 months in Google Analytics
  • Subscription metadata used for rate limiting: for the duration of your subscription, then 30 days for billing dispute resolution

6. Your rights

Under GDPR you can:

  • Request access to the personal data we hold about you
  • Request correction or deletion
  • Withdraw consent (for analytics) at any time
  • Object to processing based on legitimate interest
  • Request restriction of processing
  • Request data portability where applicable
  • Lodge a complaint with the Polish Personal Data Protection Office (Urząd Ochrony Danych Osobowych) or your local supervisory authority

To exercise any of these rights, email api@yourfoodapi.com. We will respond within 30 days.

7. Cookies

See the separate Cookie Policy for a per-cookie breakdown of what each cookie does, who sets it, and how long it lasts.

8. Children

YourFoodAPI is a B2B developer tool. It is not directed at children under 16 and we do not knowingly collect personal data from them.

9. Security

We use industry-standard encryption in transit (TLS 1.2+), restrict server access to authorized personnel, and protect data with the gateway's secret-header authentication. No system is perfectly secure — if you discover a vulnerability, please email api@yourfoodapi.com.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced on the landing page and via the email associated with your RapidAPI subscription. The "Last updated" date at the top of this page reflects the current version.

YourFoodAPI

Bilingual nutrition & recipe data API.
Built for fitness, meal planning and health apps.

Product

  • Features
  • Pricing
  • Blog
  • FAQ
  • Docs
  • OpenAPI spec

Company

  • Contact
  • RapidAPI listing

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 YourFoodAPI Made for developers
We use cookies for security and (with your permission) analytics. You can change your mind any time from the footer. See our Cookie Policy and Privacy Policy.