Who we are
The data controller for redditapis.com is the entity that operates the service. For data-protection questions, contact emma@redditapis.com.
What we collect, what we never store, where we host, and how to exercise your rights.
The short version
Who we are and what this policy covers.
The data controller for redditapis.com is the entity that operates the service. For data-protection questions, contact emma@redditapis.com.
Five categories of data, the minimum to run the service.
We do not store your Reddit account password.
Handled by Stripe. We never see your full card number, expiry, or CVC. Stripe shares the last 4 digits, brand, country of issuance, and a customer ID. For crypto payments we store the on-chain transaction hash for receipt purposes only. We do not store private keys, seed phrases, or wallet credentials.
When you authenticate through /api/reddit/login:
For every request we record:
We do not record:
Emails and Telegram messages are retained for three years after your last interaction, then deleted.
| Subprocessor | Purpose |
|---|---|
| Stripe | Payment processing |
| Cloudflare | DDoS and edge protection |
| Hetzner Cloud | Compute and hosting |
| Supabase | Database, auth, encrypted session storage |
When you use our API to interact with Reddit, your own Reddit account credentials and request data are sent to Reddit. We are not affiliated with, endorsed by, or sponsored by Reddit, Inc.
We disclose data only when served with a binding legal request from a jurisdiction with authority over us, after reviewing it for facial validity and overbreadth. We notify you unless prohibited by law.
Where data lives and how long we keep it.
Primary hosting and the database both sit in the EU (Frankfurt). Payment processing happens in the US. Our edge network is global. The named subprocessors that run each function are listed in §4.1.
For transfers out of the EEA/UK we rely on the European Commission's Standard Contractual Clauses (2021/914) and supplementary measures including encryption-in-transit and at-rest.
| Category | Retention |
|---|---|
| Account data | Until you close your account, plus 30 days |
| Billing records | 7 years (tax compliance) |
| Reddit session tokens | Until revoked or expired |
| API usage logs | 90 days hot, 12 months cold |
| Support correspondence | 3 years from last interaction |
What you can ask us to do with your data.
You can ask us to:
Email emma@redditapis.com. We respond within 30 days (less if your jurisdiction requires). We may ask you to verify your identity.
GDPR / UK GDPR: plus the right to lodge a complaint with your local supervisory authority.
CCPA / CPRA (California): we do not "sell" or "share" personal information, so there is nothing to opt out of. We honor Global Privacy Control (GPC) signals.
India DPDP Act 2023: plus nomination rights (DPDP §14) and grievance redressal.
Exercising rights is free. We may charge or refuse only where requests are manifestly unfounded or excessive, and we will explain.
Our service is not directed at children. We do not knowingly collect personal data from anyone under 16 years of age. If a child has provided data, email emma@redditapis.com and we will delete it. You must also be old enough to have a Reddit account under Reddit's own age requirements.
What we set, and how we protect what we hold.
We use strictly-necessary cookies for session and CSRF protection, plus a cookie that remembers your consent choices. Server-side analytics with no third-party ad pixels. No Facebook Pixel, Google Ads, LinkedIn Insight, or TikTok Pixel.
Stripe and Cloudflare may set their own cookies on checkout and when challenging suspicious traffic. Those are governed by their own policies.
Change consent at any time via the Cookie preferences link in the site footer.
We do not store your Reddit account password. We use TLS in transit. Data at rest is encrypted by our hosting and database providers per their published practices (see §4.1 for the named subprocessors). Production access is restricted to named operators with ed25519 SSH keys and passphrases (no password authentication, no shared credentials).
We do not currently carry Tech-E&O insurance. We disclose this and price the service accordingly.
If you find a vulnerability, email emma@redditapis.com with reproduction steps. Please do not test against accounts you do not own, do not attempt to access other customers' data, and do not run automated scanners against production endpoints.
We notify affected customers and the relevant regulator within 72 hours of becoming aware of a breach, where required by law.
Acceptable use: the rules that govern your use of the API live in our Terms of Service §6.
How we update this policy and how to reach us.
For material changes, we email all active customers at least 30 days before the change takes effect and keep the prior version at /legal/archive/privacy-<YYYY-MM-DD>.html.
Continued use after the effective date constitutes acceptance. If you do not accept, you may close your account before the effective date.
All topics route through one mailbox:
Questions about how we handle your data?
Reach us on TelegramContinue exploring related pages.
Reddit API use cases
14 use cases from AI training to brand monitoring and DMs.
RedditAPI pricing
Endpoint-level costs and quick monthly totals — reads from $0.002 / call.
Reddit API cost calculator
Estimate monthly spend using your request volume.
Reddit API guides and tutorials
Tutorials, walkthroughs, and API deep-dives for developers.
Reddit API alternatives
Evaluate alternatives by cost model, limits, and integration fit.
Affiliate program
Earn 20% lifetime commissions — capped at $5,000/yr.
Last updated: May 2026