Privacy Policy
Last updated: June 26, 2026
Core Route ("Core Route", "we", "us", or "our") operates the website coreroute.dev, the API at api.coreroute.dev, and related products, dashboards, and communications (collectively, the "Platform"). Core Route is an API discovery and developer community platform. We help developers find, compare, monitor, and evaluate APIs and related services, and we provide tools for submitting listings, writing reviews, building collections, requesting new APIs, and claiming provider profiles.
This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and protect personal information when you visit the Platform without an account, register for an account, sign in with a third-party identity provider, submit content, interact with community features, receive emails from us, or otherwise communicate with Core Route.
We process personal information in accordance with applicable data protection laws. Depending on where you live, you may have specific rights regarding your information. Section 14 of this Policy explains those rights and how to exercise them.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use the Platform.
1. Definitions
In this Policy, "personal information" (also called "personal data" in some jurisdictions) means information that identifies, relates to, describes, or could reasonably be linked with an individual. This includes, for example, your name, email address, account identifiers, and certain usage or device data when it can be linked to you.
"Processing" means any operation performed on personal information, including collection, storage, use, disclosure, deletion, or archiving.
"You" and "your" refer to any individual who visits the Platform or uses our services, including registered account holders, contributors, and provider representatives.
2. Who is responsible for your information
For the purposes of applicable data protection law, Core Route is the controller of personal information processed through the Platform, except where we process information solely on behalf of a third party and act as a processor under a separate agreement.
If you have questions about this Policy or our privacy practices, you can contact us using the details in Section 20 at the end of this document.
3. Scope of this Policy
This Policy applies to personal information we process when you use the public website, authenticated dashboard, administrative interfaces (where applicable to your role), email communications sent by Core Route, and API endpoints that require authentication or collect usage data tied to an identifiable user or session.
What this Policy covers
- Account registration, login, password reset, and profile management.
- Community contributions such as API submissions, listing change proposals, reviews, ratings, collections, app idea submissions, community API requests, votes, bookmarks, and provider claim applications.
- Operational communications including submission status updates, moderation decisions, security alerts, and service announcements.
- Security, fraud prevention, rate limiting, captcha verification, and audit logging related to platform use.
- Product analytics and performance monitoring where enabled.
What this Policy does not cover
This Policy does not apply to third-party websites, API documentation portals, payment processors, identity providers, or services operated by API providers listed on Core Route. When you leave our Platform or integrate with a third-party API, that organization's privacy policy governs how they handle your information.
If you are an employee or contractor of a provider whose API is listed on Core Route, your relationship with that provider is separate from your use of the Platform as an individual user.
4. Information we collect
The information we collect depends on how you interact with the Platform. We collect information in three broad categories: information you provide directly, information collected automatically when you use the Platform, and information we receive from third parties.
4.1 Information you provide directly
When you create an account, we collect information such as your name, email address, and password. Passwords are stored using industry-standard hashing; we do not store plaintext passwords.
When you update your account or dashboard profile, we collect the information you choose to provide, which may include display preferences and saved items.
- Registration and authentication details, including email address, name, and credentials.
- Profile information you choose to add or update after registration.
- API submission data, including API name, description, documentation URLs, pricing notes, category selections, country coverage, and any supporting metadata you provide.
- Listing change proposals that suggest edits to existing directory entries.
- Reviews and ratings, including written feedback, star ratings, and associated API identifiers.
- Collections you create, including titles, descriptions, and the APIs you include.
- App idea submissions and community API requests, including descriptions, use cases, and voting activity where applicable.
- Provider claim materials, which may include your name, work email, company affiliation, verification documents, and statements of authorization.
- Communications you send to us, including support requests, abuse reports, privacy requests, and responses to moderation inquiries.
4.2 Information collected automatically
When you visit or use the Platform, we automatically collect certain technical and usage information. Some of this information is necessary to deliver the service securely; other information helps us understand how the Platform is used and where improvements are needed.
- Network and device data, such as IP address, browser type and version, operating system, device type, language settings, and approximate location derived from IP address.
- Referral and navigation data, including the page that linked you to Core Route, pages viewed, time spent on pages, click paths, search queries, filters applied, and comparison actions.
- Session and authentication data, including login timestamps, session identifiers, and authentication method used.
- Security and anti-abuse data, including failed login attempts, rate-limit events, captcha challenge identifiers, bot detection signals, and suspicious activity flags.
- Error and performance data, such as crash reports, server response times, and diagnostic logs needed to maintain reliability.
- Cookie and local storage identifiers used to maintain sessions, remember preferences, and protect against cross-site request forgery.
4.3 Information from third parties
- Identity provider data if you sign in with Google or another supported OAuth provider. This typically includes your name, email address, and profile identifier supplied by the provider, subject to your settings with that provider.
- Publicly available provider documentation, logos, OpenAPI specifications, and metadata used to populate or verify directory listings.
- Infrastructure, email delivery, analytics, search, monitoring, and security vendors that process data on our behalf to operate the Platform.
- Moderation or abuse reports submitted by other users that reference your account or published content.
4.4 Information we do not intentionally collect
We do not require you to provide sensitive categories of personal information such as government ID numbers, financial account details, health information, or precise geolocation for ordinary use of the Platform. Please do not include such information in reviews, submissions, or support messages unless we explicitly request it for a specific verification process (for example, a provider claim review).
5. How we use personal information
We use personal information only where we have a valid reason under applicable law. The primary purposes for which we use personal information are described below.
5.1 Providing and operating the Platform
- Create, authenticate, and manage user accounts.
- Enable browsing, search, filtering, comparison, and detail pages for APIs, categories, countries, providers, and collections.
- Process and display submissions, reviews, collections, app ideas, community requests, and provider claims.
- Deliver dashboard features such as saved items, submission tracking, monitoring views, and account settings.
- Send transactional emails, including account verification, password reset links, submission status updates, moderation outcomes, and security notifications.
5.2 Maintaining quality, safety, and trust
- Moderate user-generated content for accuracy, spam, malware links, impersonation, and policy violations.
- Review provider claim applications and verify authorized representatives where practicable.
- Investigate abuse reports, enforce rate limits, and protect the Platform from automated scraping or credential attacks.
- Maintain audit logs of administrative and moderation actions for accountability.
- Improve listing quality through editorial review, automated checks, and community feedback.
5.3 Improving and developing the Platform
- Analyze aggregated usage patterns to understand feature adoption and performance bottlenecks.
- Test new features, fix bugs, and optimize search and monitoring experiences.
- Conduct internal research on developer needs and directory completeness.
5.4 Legal and compliance purposes
- Comply with applicable laws, regulations, lawful requests, and court orders.
- Establish, exercise, or defend legal claims.
- Enforce our Terms of Service and other platform policies.
- Detect, prevent, and address fraud, security incidents, and unlawful activity.
5.5 Marketing and communications
We may send product announcements, newsletters, or community updates if you opt in or where permitted by law. You can unsubscribe from non-essential marketing emails at any time using the link in the message or by contacting us. Transactional and security-related messages are not marketing and may be sent even if you opt out of promotional communications.
6. Legal bases for processing
If you are located in the European Economic Area, United Kingdom, or another jurisdiction that requires a legal basis for processing personal information, we rely on one or more of the following bases depending on the activity:
Performance of a contract
We process account, authentication, and feature-related data as necessary to provide the Platform and the services you request when you register or use authenticated features.
Legitimate interests
We process certain information because it is necessary for our legitimate interests in operating, securing, and improving the Platform, maintaining listing quality, preventing abuse, and communicating with users about service-related matters. Where we rely on legitimate interests, we balance those interests against your rights and expectations.
- Platform security, fraud prevention, and anti-abuse measures.
- Moderation of submissions, reviews, and claims.
- Internal analytics and product improvement using aggregated or pseudonymized data where possible.
- Responding to inquiries and maintaining business records.
Consent
Where required by law, we rely on your consent for optional activities such as non-essential analytics cookies or marketing emails. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Legal obligation
We process information when necessary to comply with legal obligations, such as responding to valid legal process or retaining records required by applicable law.
7. Public and community-visible information
Certain information you submit on the Platform may be visible to other users or the general public. You should assume that anything you publish in a public-facing area of the Platform can be viewed, copied, and referenced by others even after you delete your account, because third parties may have saved or indexed it.
- Approved API listings and associated metadata may be publicly searchable.
- Reviews, ratings, and collections you publish are typically visible to other users.
- Community requests, app ideas, and votes may be displayed publicly depending on feature settings.
- Your display name or username may appear alongside content you contribute.
- Provider claim approvals may result in your affiliation with a provider being shown on a listing.
Choosing what to share
Do not include confidential business information, personal data belonging to others, or secrets such as API keys or credentials in public submissions, reviews, or comments. Core Route is a discovery platform, not a secrets manager.
10. How long we retain information
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Retention periods vary depending on the type of information and the reason we hold it.
10.1 Account information
We retain account information while your account is active. If you request account deletion, we will delete or anonymize personal information associated with your account within a reasonable period, except where retention is necessary for legal compliance, dispute resolution, fraud prevention, or enforcement of our agreements.
10.2 Community content
Public content you published may remain on the Platform after account deletion if it has been approved for listing, referenced by other users, or is required for the integrity of the directory. Where feasible, we will disassociate deleted accounts from remaining public content by removing or anonymizing identifying attribution.
10.3 Security and operational logs
Security logs, authentication records, and operational diagnostics are typically retained for a limited period sufficient to investigate incidents, enforce rate limits, and maintain system reliability, after which they are deleted or aggregated.
10.4 Legal and backup retention
Information may persist in encrypted backups for a limited time after deletion from active systems. Backups are restored only when necessary for disaster recovery and are subject to the same security controls as production data.
11. Security measures
We implement administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These measures include, where appropriate:
- Encryption of data in transit using HTTPS/TLS.
- Hashed storage of passwords using industry-standard algorithms.
- Role-based access controls for staff, moderators, and administrators.
- Rate limiting and abuse detection on authentication and submission endpoints.
- Cross-site request forgery protections for state-changing requests.
- Security headers and content security policies on web responses.
- Audit logging for sensitive administrative actions.
- Vendor due diligence and contractual security requirements for subprocessors.
Your role in security
No online service can guarantee absolute security. You are responsible for choosing a strong password, keeping your credentials confidential, signing out on shared devices, and notifying us promptly at hello@coreroute.dev if you suspect unauthorized access to your account.
Security incidents
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
12. International data transfers
Core Route may process and store personal information in countries other than the country where you reside, including countries that may have different data protection laws than your jurisdiction. This occurs when we use cloud infrastructure, email providers, or other subprocessors with global operations.
Where required by applicable law, we implement appropriate safeguards for cross-border transfers, such as standard contractual clauses approved by relevant authorities or equivalent mechanisms. You may contact us for more information about transfer safeguards applicable to your region.
13. Your privacy rights
Depending on your location, you may have rights regarding your personal information. These rights may include some or all of the following, subject to exceptions under applicable law:
- Right of access: request confirmation of whether we process your personal information and obtain a copy of that information.
- Right to rectification: request correction of inaccurate or incomplete personal information.
- Right to erasure: request deletion of your personal information in certain circumstances.
- Right to restriction: request that we limit processing in certain situations.
- Right to object: object to processing based on legitimate interests or for direct marketing.
- Right to data portability: receive personal information you provided in a structured, commonly used, machine-readable format where technically feasible.
- Right to withdraw consent: where processing is based on consent, withdraw consent at any time.
- Right to lodge a complaint: file a complaint with a supervisory authority in your jurisdiction.
13.1 How to submit a request
To exercise your privacy rights, email privacy@coreroute.dev from the address associated with your account and describe your request in sufficient detail. We may need to verify your identity before processing the request to protect your account from unauthorized access.
We will respond within the timeframe required by applicable law. If we deny a request, we will explain the reason unless prohibited by law.
13.2 Account deletion
You may request account deletion through your dashboard account settings or by contacting privacy@coreroute.dev. Deletion may not immediately remove all public content as described in Section 10.2.
13.3 Regional notices
Users in the European Economic Area and United Kingdom may contact their local data protection authority if they believe we have not addressed a concern adequately. Users in Nigeria may have rights under the Nigeria Data Protection Act and related regulations. Users in other jurisdictions may have additional rights under local consumer or privacy laws.
14. Automated processing
We may use automated tools to detect spam, flag suspicious login activity, score listing quality, or prioritize moderation queues. These processes support human review and platform safety; they do not produce legal or similarly significant effects about you without human involvement where such protection is required by law.
If you believe an automated decision has affected your account or content in error, contact hello@coreroute.dev and we will review the matter.
15. Children's privacy
The Platform is not directed to children under 16 years of age, and we do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, contact privacy@coreroute.dev and we will take steps to delete that information where required.
If we learn that we have collected personal information from a child under 16 without appropriate authorization, we will delete it promptly.
16. Third-party links and listed APIs
The Platform contains links to third-party websites, API documentation, status pages, GitHub repositories, and external developer resources. Clicking those links may take you outside Core Route.
We are not responsible for the privacy practices, security, or content of third-party services. API providers listed on Core Route may collect and process your data under their own terms when you sign up for or call their APIs. We encourage you to read the privacy policies of any third-party service before providing personal information.
17. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, legal requirements, or organizational structure. When we update this Policy, we will revise the "Last updated" date at the top of this page.
If we make material changes that significantly affect your rights, we will provide additional notice where appropriate, such as by email to registered users or a prominent notice on the Platform before the changes take effect.
Your continued use of the Platform after the effective date of an updated Policy constitutes acknowledgment of the changes. If you do not agree with an updated Policy, you should stop using the Platform and may request account deletion.
19. Contact us
For privacy questions, data subject requests, or concerns about this Policy, contact privacy@coreroute.dev.
For general support unrelated to privacy rights, contact hello@coreroute.dev.
For legal or copyright matters, contact legal@coreroute.dev.
We aim to respond to privacy requests within 30 days, or sooner where required by applicable law.



