Privacy & GDPR Notice
Last updated: 9 June 2026. This notice explains how MagnetAPI.org handles personal data for the public website, client dashboard, admin dashboard, API gateway, wallet ledger, setup instructions, support, and transactional email.
Controller and contact
MagnetAPI.org is operated by LoveMedia Foundation NPC, a registered non-profit company in South Africa. Business Registration Number: 2024/122569/08. Registered address: Unit 1, Raddical Park, 3 Gourly Rd, Ballito 4399, South Africa. Contact number: +27873508601. Privacy, account, access, correction, deletion, and portability requests can be sent to support@magnetapi.org. We may ask for information needed to verify the requester before making account changes or releasing account data.
Personal data processed
- Account identifiers: username, email address, optional phone number, first name, surname, address, city, region, country, dashboard password fields, API token metadata, session records, account status, and admin-created marketplace delivery details.
- Service and billing records: Token Wallet balance, wallet adjustments, usage transactions, model name, request timestamps, token counts, charge amounts, and recent account activity.
- Technical and security data: IP address, user agent, request route, error details, authentication events, and operational logs needed to protect and operate the service.
- Registration abuse-prevention data: one-way hashes derived from the registration IP address and browser/device fingerprint. These hashes enforce the one-trial-account rule without storing the raw device fingerprint in the registration guard ledger.
- Support and communication data: email messages, SMTP delivery metadata, and any information a user or administrator sends to support.
Purposes and legal basis
- Contract and service delivery: create accounts, authenticate users, provide dashboard access, generate setup scripts, proxy API requests, maintain wallets, and show usage records.
- Legitimate interests: secure the platform, prevent abuse, debug errors, maintain service reliability, respond to support requests, and preserve audit records for administrators.
- Legal obligations: keep records where required for accounting, disputes, fraud prevention, tax, regulatory, or law enforcement requests.
- Consent and legitimate interests: measure signup performance, improve advertising attribution, and operate analytics or conversion tags where enabled.
Recipients and processors
Personal data is available to authorised MagnetAPI administrators and technical operators where needed. Data may be processed by hosting providers, database services, SMTP/email providers, upstream coding model/API providers, and security or infrastructure vendors needed to run the service. API prompts, completions, tool results, and metadata may be sent to upstream model/API providers to fulfil API requests.
International transfers
Infrastructure and providers may operate in countries outside the European Economic Area or the United Kingdom. Where GDPR transfer rules apply, MagnetAPI.org relies on appropriate contractual, technical, and organisational safeguards available through the relevant provider relationship.
Retention
Account, wallet, usage, and security records are kept while the account is active and for a reasonable period afterwards for support, billing, dispute, abuse-prevention, and legal record purposes. Data that is no longer needed is deleted or anonymised where practical, unless retention is required for legal, security, or accounting reasons.
Cookies and browser storage
The public website may load analytics and conversion measurement scripts, including Google Analytics, Meta Pixel, and Reddit Pixel where configured. After signup or authenticated use, conversion matching may include contact details such as email, optional phone number, account identifier, name, city, region, country, IP address, user agent, and browser identifiers supplied by analytics providers. MagnetAPI does not fabricate or transmit mobile advertising identifiers that the website does not collect. The registration page uses essential browser storage and a browser/device fingerprint to enforce one trial account per device and network address. The dashboard also uses essential browser storage to keep users signed in, remember setup preferences, and show account state. These items can be cleared in the browser, although clearing them signs the user out.
Your rights
Depending on location and applicable law, users may have rights to access, correct, erase, restrict, object to processing, withdraw consent, and receive a portable copy of personal data. Users may also have the right to lodge a complaint with their local data protection authority. Requests should be sent to support@magnetapi.org.
Security
MagnetAPI.org uses HTTPS, authenticated dashboards, API bearer tokens, server-side access controls, operational logging, privacy-focused response headers, and administrator-only account issuance. Users should keep dashboard credentials and API tokens private and request token rotation if a token is exposed.
Children
MagnetAPI.org is intended for business and developer use and is not directed to children. Administrators should not knowingly create accounts for children.
Changes to this notice
This notice may be updated when services, providers, legal requirements, or operational practices change. The latest version is published on this page.