Privacy policy
Last updated: 26 August 2026
This document is available in English only. A translation may follow, but the English text is the one that applies.
Who we are
saveapi.org provides an HTTP API that turns a public social-media link into direct media URLs and metadata. This policy explains what we record when you use the site and the API, why, and for how long.
What we collect
When you sign in:
- Through Telegram — your Telegram user ID, first and last name, username and profile photo URL, as sent to us by Telegram. We never receive your phone number or your messages.
- Through Google — your Google account ID, email address, display name and profile picture URL. We request only the openid, email and profile scopes; we cannot read your mail, files or contacts.
When you call the API:
- The link you asked us to resolve, the endpoint used, the response status, how long the request took, your IP address and your User-Agent header.
- Counters of how many requests each of your keys has made, per day and per calendar month.
We do not collect payment card details. We do not use analytics or advertising trackers, and the site sets no third-party cookies.
What we do not do
- We never download, copy or store the media itself. The API returns links that point at the source platform's own servers; the files do not pass through us.
- We do not sell your data, and we do not share it with advertisers or data brokers.
- We do not store your API keys in a readable form. Only a SHA-256 hash is kept, which is why a key can be shown to you exactly once.
How long we keep it
- Per-request records — including the resolved link and your IP address — are deleted automatically after 90 days.
- Daily totals per key (counts only, no links and no IP addresses) are kept while your account exists, because they are your billing history.
- Account details stay until you ask us to delete the account.
- Sign-in sessions expire 30 days after your last visit, or immediately when you sign out.
Cookies
One cookie, set only after you sign in. It holds a random session identifier and nothing else — no personal data is stored inside it. It is marked HttpOnly, so scripts on the page cannot read it, and SameSite=Lax, so other sites cannot use it on your behalf. There are no advertising or analytics cookies.
Who else sees the data
- Telegram and Google — only during sign-in, and only because you chose that method.
- Our hosting provider (Hetzner Online GmbH, Germany), which operates the servers the data sits on.
- Law enforcement, if we are legally required to respond to a valid request.
To resolve a link, our servers contact the platform that hosts it. Those requests carry our infrastructure's address, not yours.
Your choices
- Ask for a copy of the data tied to your account, or ask us to delete the account and everything attached to it.
- Revoke any API key at any time from the dashboard; it stops working immediately.
- Sign out of every device from your account settings.
Write to privacy@saveapi.org and we will answer within 30 days.
Changes
If this policy changes in a way that affects what we collect or how long we keep it, we will update the date at the top and tell account holders by email or in the dashboard before the change takes effect.