Zero Customer API Keys Required

Privacy Policy

Last updated: August 6, 2026

1. Zero Customer API Keys Guarantee

Deprecast monitors only public vendor signals — OpenAPI/Swagger schemas, RSS feeds, and public changelogs. We do never ask for, store, or process your external API keys, OAuth client secrets, database credentials, or application code.

2. Data We Collect

  • Account Email Address: Collected when you log in via magic link to deliver authentication links, weekly digests, and urgent breaking change alerts.
  • Watchlist Preferences: The 30-vendor toggles, mute states, and optional notification destinations (such as Slack incoming webhooks) you configure in your dashboard.
  • Operational Logs: Minimal server access logs (IP address, user agent, timestamps) retained briefly for security, abuse prevention, and rate limiting.

3. How We Use Your Information

We use collected information strictly to operate and improve Deprecast:

  • Sending passwordless authentication magic links.
  • Delivering weekly API breaking-change email digests and urgent sunset alerts.
  • Broadcasting alerts to your configured Slack incoming webhook URL if provided.

We never sell, rent, or trade your personal data or email address to third parties.

4. Security & Storage

Session tokens are hashed and stored in secure, HTTP-only cookies. Magic links expire within 15 minutes. Data is stored securely in encrypted production infrastructure.

5. Contact Us

For privacy inquiries or account deletion requests, email support atsupport@deprecast.com