← home

Privacy Policy

Last updated: 20 September 2026. gankdat ("we", "us") is the trading name of Giovanni Funaro, a sole trader in the United Kingdom, who is the data controller for the personal data described here. Contact: info@gankdat.com.

The short version: the only personal data we hold about you is your email address and the operational records needed to run your account. No analytics, no trackers, no ad tech, no selling data. Each dataset we serve states its own personal-data posture in our terms — public-record datasets run Blind Mode (personal data stripped before we store it); the UK sanctions list is served as published, minimized, for compliance use (section 3).

1. What we collect, and why

Data When Why
Email address You sign in or join the waitlist It is your account identity: sign-in links, API-key ownership, plan and quota all attach to it. Waitlist emails are used only to tell you about launch.
API keys (hashed) You create a key We store only a SHA-256 hash — we cannot recover or display your key after creation.
OAuth tokens (hashed) You connect gankdat from an AI client such as Claude The sign-in request, authorization code, access token (1 hour) and refresh token (30 days) are stored only as SHA-256 hashes, together with the client's identifier (a URL) and the key on your account they act through. Revoking that key at /account ends the connection; expired tokens are deleted within a day.
Usage counters You call the API Monthly request counts per account, for quotas and the usage display on your dashboard.
Billing records You buy a plan Your Stripe customer reference, plan, and a credit ledger. Card details go directly to Stripe — we never see or store them.
Request metadata Every API request Timestamp, endpoint, key identifier, response status, and IP address, in short-lived operational logs — for rate limiting, abuse prevention, and debugging. We do not log request bodies.
Correspondence You email us To answer you.
Feedback You submit the feedback form Your message (and email address, only if you choose to give one) is stored so we can act on it and reply. Deleted on request.

2. Cookies

We set exactly one cookie: fapi_session, an opaque session identifier created when you sign in (HttpOnly, Secure, expires after 30 days or on sign-out). It is strictly necessary to keep you signed in, which is why there is no cookie banner — we have nothing else to ask consent for. No analytics or third-party cookies, ever.

3. Source data — per-dataset posture & "Blind Mode"

The datasets we serve come from official government feeds, and each dataset's personal-data posture is stated in the licence table in our terms. Public-record datasets (Find a Tender procurement notices; planning.data.gov.uk planning applications; TED procurement notices; The Gazette corporate insolvency notices; Companies House new incorporations) run Blind Mode: personal data present in source records — for example planning-applicant names and contact details — is dropped at ingest and never stored or served. We do not build profiles of individuals, and our terms forbid using the service to re-identify anyone.

uk-sanctions is different by nature: the UK Sanctions List is a government publication that names designated persons and entities so that others can comply with sanctions law. We serve it for that purpose, minimized — we drop dates of birth, identity and passport numbers, contact details, and birth places at ingest, keeping designation facts (names, aliases, regime, dates, countries). Our lawful basis is legitimate interests: enabling sanctions compliance and due diligence using data the government publishes for exactly that use. Designated persons' rights requests should be directed to the FCDO, which controls the list; we reflect the official publication and refresh daily.

sam-exclusions follows the same compliance-list posture: the US SAM.gov exclusions list names parties barred from US federal awards so that others can screen against it. We serve it minimized — all addresses, SSN/TIN/NPI identifiers, and free-text comments are dropped at ingest, keeping exclusion facts (name, classification, exclusion type and program, agency, UEI/CAGE codes, dates). Lawful basis is the same legitimate interest; excluded parties' rights requests should be directed to SAM.gov (US GSA), which controls the list; we reflect the official publication and refresh daily.

4. Pay-per-request crypto payments (x402)

Agents may pay per request in USDC without creating an account. Those payments settle on a public blockchain (Base) via a payment facilitator; the paying wallet address is pseudonymous public-ledger data by the nature of blockchains. We do not link wallet addresses to email accounts, and no account is created for x402 usage.

5. Legal bases (UK GDPR)

6. Who processes data for us

Processor Purpose Privacy policy
Cloudflare Hosting, storage, DNS, email routing, bot protection cloudflare.com
Stripe Payment processing and billing portal stripe.com
Resend Sending transactional email (sign-in links), EU region resend.com
Coinbase Developer Platform Verifying and settling x402 crypto payments coinbase.com

We do not sell personal data, buy contact lists, or send cold email to individuals.

7. International transfers

Some processors are US companies operating global infrastructure. Where personal data leaves the UK, transfers rely on UK adequacy decisions (including the UK–US Data Bridge) or the processors' standard contractual safeguards.

8. Retention

9. Security

All traffic is TLS-encrypted. API keys are stored only as SHA-256 hashes. Sign-in is passwordless (no password database to breach). Secrets are held in our hosting platform's encrypted secret store, and admin operations use constant-time credential checks.

10. Your rights

Under UK GDPR you may request access, correction, erasure, restriction, objection, or portability of your personal data. Email info@gankdat.com and we will action it — deleting your account removes your email, keys, and sessions (billing records we must keep for tax law are retained until that clock runs out). You may also complain to the Information Commissioner's Office (ICO).

11. Children

The service is a business tool and is not directed at children under 16. We do not knowingly collect their data.

12. Changes

We may update this policy; material changes will be posted here with a new date, and — for signed-up users — flagged by email where the change matters to you.