TRUST

COMPLIANCE & DATA HANDLING

LAST UPDATED: AUGUST 29, 2026

This page explains, in plain language, what data Brizzox touches and what it never keeps. It complements the privacy policy and terms of service, which remain the binding documents.

WHAT COUNTS AS PUBLIC DATA

Brizzox APIs return only information that a platform shows to a visitor who is not logged in: public profiles and posts, ads published in advertising-transparency libraries, and property listings that portals display to everyone. If a page requires an account, a password, a follow approval or a paywall to view, it is out of scope by design.

We do not bypass access controls, do not use borrowed or purchased accounts, and do not return content from private profiles, closed groups or unlisted listings.

ZERO DATA RETENTION (ZDR)

Every API call is executed live against the source when you make it, and the response is streamed back to you. Brizzox does not store, cache or index the personal data contained in those responses. There is no Brizzox database of profiles, posts, ads or listings, which also means there is nothing stale to serve: what you receive is the public state at the time of the request.

What we do keep is the operational metadata needed to run the service: which API key made a request, when, to which endpoint, the response status and latency, and the credits consumed. Raw request logs are kept for a limited period for billing, abuse prevention and support, then dropped; aggregated usage counts are kept for your dashboard.

ACCOUNT AND PAYMENT DATA

Your account holds the details you gave us at sign-up (name, email, authentication provider) and your subscription and credit balances. Card details never touch Brizzox servers: payments are processed by Stripe, and Brizzox stores only Stripe's references. See the privacy policy for the full list of what is collected and why.

API KEY SECURITY

API keys are generated per API, stored as a SHA-256 hash for lookup and encrypted at rest for display, and the plaintext is never written to logs. Keys can be revoked instantly from the dashboard, which also cuts MCP access because the MCP server authenticates with the same keys.

Rate limits and credit ceilings are enforced at AWS API Gateway before a request reaches any upstream source, so a leaked key cannot run up unlimited usage.

ACCEPTABLE USE

You are responsible for using the data you retrieve in line with the source platform's public terms and the laws that apply to you, including data-protection law where personal data is involved. Brizzox may suspend keys used for harassment, doxxing, spam, credential attacks or any use that targets individuals rather than public information at scale. The terms of service set out the details.

REMOVAL AND INQUIRIES

Because Brizzox does not retain response data, there is normally nothing for us to delete about a third party: removing content at the source removes it from every subsequent API response. If you believe a Brizzox customer is misusing public data, or you have a legal or data-protection question, contact us and we will respond by email.

CONTACT

Data-handling questions, removal requests and security reports: admin@brizzox.com. Security researchers can also find this address in /.well-known/security.txt.