Legal
Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains what personal data Renderfy collects, how we use it, and the choices you have. We aim to collect as little as possible to run the Service.
1. Who we are
Renderfy is a stateless rendering API and dashboard operated by PINTECH LABS, available at renderfy.io. For the purposes of data protection law, PINTECH LABS acts as the controller of the personal data described below.
2. Information we collect
Account information
When you sign in we collect your email address. Authentication is handled via a magic sign-in link or GitHub OAuth; we do not receive or store your password.
Usage and diagnostics
For each render we store metadata — the input type, output format, number of credits charged, duration, status, and timestamp — to power billing, your usage history, and troubleshooting. We also record credit transactions (grants, charges, refunds).
API keys
API keys are stored only as a salted hash; the full key is shown once at creation and never stored in a recoverable form. We keep a short prefix for display purposes.
Network data
To rate-limit the unauthenticated guest playground and prevent abuse, we store a one-way SHA-256 hash of the requester’s IP address. We do not store raw IP addresses for this purpose.
3. Content you render
The Service is stateless by default. The content you submit for rendering is processed in memory to produce your output and is not stored on our systems after the response is returned. We cannot access the substance of what you render after the fact — only the request metadata described above.
Two opt-in exceptions, both under your control:
- Idempotency keys. If you send an
Idempotency-Keyheader, we temporarily retain the rendered output so that an identical retry returns the same result without charging you twice. This copy is encrypted at rest, is used only for replay, and is automatically deleted after a short retention window (24 hours by default). Omit the header and nothing is retained. - Saved templates. If you create a template, the template layout you choose to save is stored on your account until you delete it. The variable data you pass in at render time to fill a template is not stored — it is substituted in memory and discarded with the rest of the render.
4. How we use your data
- to provide, maintain, and secure the Service;
- to authenticate you and manage your account;
- to meter credits, process payments, and show your usage history;
- to detect, prevent, and investigate abuse, fraud, and security incidents;
- to comply with legal obligations.
5. Cookies
We use strictly necessary cookies to keep you signed in. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for details.
6. Service providers
We share data with a small number of processors who act on our instructions, including our infrastructure and database provider (Supabase), our hosting and content-delivery providers, and, where you make a purchase, our payment provider. These providers may process data only as needed to deliver their service to us.
7. Data retention
We retain account and usage metadata for as long as your account is active and as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Rendered content is not retained, except for the short-lived, encrypted idempotency copy described in Section 3 (auto-deleted, 24 hours by default) and any templates you have explicitly saved (kept until you delete them). Guest rate-limit records are short-lived.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. You may also delete your account, after which we remove or anonymize associated personal data except where we must retain it by law.
9. Security
We use industry-standard measures to protect your data, including encryption in transit, hashed API keys, and row-level access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. International transfers
Your data may be processed in countries other than your own. Where it is transferred internationally, we rely on appropriate safeguards as required by applicable law.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, communicated to you.
13. Contact
For privacy questions or to exercise your rights, contact us at [email protected].