Privacy policy

Last updated: 24 September 2026

We collect as little personal data as possible: no advertising, no tracking cookies, no third-party analytics, and all fonts and scripts are served from our own server.

1. Who is responsible

The controller of your personal data under the EU General Data Protection Regulation (GDPR) is Fengshui API, the operator of this website and API. You can reach us at any time through the contact form (topic "Privacy / personal data request").

2. What we process and why

Your account

  • Data: your name, e-mail address, an optional description of your project, a hash of your password (we cannot read your password), a hash and the first characters of your API key (we never store the key itself), and the dates the account was created, the key issued and the e-mail confirmed.
  • Purpose: giving you access to the API, letting you manage your account, and keeping it secure.
  • Legal basis: performance of the agreement with you (Art. 6(1)(b) GDPR).
  • Retention: until you delete your account — you can do so yourself at any time on your account page. Accounts whose e-mail address is never confirmed are deleted automatically after 30 days.

E-mails we send

Only messages you need: the confirmation link after sign-up and password reset links you request. They contain one-time links that expire after 7 days (confirmation) or one hour (password reset); we store only a hash of these tokens. We never send newsletters or marketing.

Contact form

  • Data: your name, e-mail address, topic and message.
  • Purpose and legal basis: answering you — our legitimate interest (Art. 6(1)(f) GDPR) or steps you asked for before or under an agreement (Art. 6(1)(b)).
  • Retention: the message is delivered to our mailbox and not stored on the website; we delete it once the matter is closed, at the latest after 12 months.

Protection against abuse

To limit sign-ups, sign-in attempts, contact messages and free calculator use, we keep short-lived counters keyed by your IP address (or by account for API requests). They expire after at most one hour. Legal basis: our legitimate interest in keeping the service secure and available (Art. 6(1)(f) GDPR).

Server logs

Like every web server, ours records technical access data — IP address, time, requested URL (which can include the values you enter into a calculator), status code and browser type — to operate the service and investigate errors and attacks. These logs are kept for no longer than 14 days. Legal basis: Art. 6(1)(f) GDPR.

Calculations

Dates and other values you enter into the calculators or send to the API are used only to compute the result and are not stored, apart from the server logs above.

Usage statistics

We count how many times each page and API endpoint is used per day. These counters contain no personal data — no IP address, no identifier, no cookie — and cannot be linked to you.

3. Cookies and browser storage

  • We set no cookies while you browse, use the calculators or read the documentation.
  • When you sign in, a strictly necessary session cookie (fengshui_session) keeps you signed in. It is deleted when you sign out or close the browser. Because it is essential for a service you request, it does not require consent.
  • The API playground stores the key you paste in your browser's sessionStorage for the current tab only. It is never sent to us except as the header of the API requests you make.

4. Who receives data

We do not sell or share personal data. It is processed on our behalf only by the providers we need to run the service — the hosting provider and the e-mail delivery provider — under data processing agreements. If a provider processes data outside the European Economic Area, this happens only with appropriate safeguards such as the EU Standard Contractual Clauses.

5. Your rights

You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Most of this you can do yourself on your account page; for anything else use the contact form. You also have the right to lodge a complaint with a data protection supervisory authority — in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), or the authority of the country where you live.

Providing your data is voluntary, but without an e-mail address and password we cannot create an account.

6. Security

Connections are encrypted, passwords are stored with a modern password-hashing algorithm, API keys and one-time links only as SHA-256 hashes, and access to the servers is restricted.

7. Changes

If we change how we process personal data, we update this page and the date above. Significant changes affecting account holders are announced by e-mail.