← PolyApiIDE

Privacy Policy

Effective date: 2026-08-31 · Version 2026-08-31 · Operator: polyapiclient.ru · Contact: support@polyapiide.ru

Chrome Web Store / Edge Add-ons — Limited Use certification. PolyApiIDE collects and processes user data only as needed for the product’s single purpose: providing a local-in-browser API client (IDE) and related licensing, payment, and optional cloud backup services. We do not sell personal data, do not use it for advertising, and do not transfer it to data brokers.

Contents

  1. Who we are & scope
  2. Single purpose
  3. Data we process
  4. Chrome extension permissions
  5. How we use data
  6. Third parties
  7. Storage, security, retention
  8. Your rights & deletion
  9. Children
  10. International transfers
  11. Policy changes
  12. Contact
  13. Related documents

1. Who we are & scope

This Privacy Policy (“Policy”) explains how the operator of https://polyapiclient.ru and the PolyApiIDE browser extension (“Service”, “Product”) handles information when you use:

Personal data operator (under applicable Russian Federation law, including Federal Law No. 152‑FZ): self-employed individual in the Russian Federation Efin Yuriy Anatolyevich (Ефин Юрий Анатольевич), TIN (INN) 500173519797, phone +7 (916) 208‑38‑14, Telegram @Efin_Yuri, email support@polyapiide.ru. See also the Contacts page.

  • the PolyApiIDE extension (Chrome / Chromium / Microsoft Edge);
  • the polyapiclient.ru website (landing, checkout, demo video, support);
  • APIs on polyapiclient.ru used for licensing, the technical API client (client_id), payments, and cloud backup.

By installing the extension, using the website, or purchasing Lifetime, you acknowledge this Policy. License terms are set out in the License Agreement.

After you install the extension, the browser (Google Chrome, Mozilla Firefox, Microsoft Edge or another vendor) may independently collect and process additional data about you and your device under that vendor’s privacy policy and terms. The PolyApiIDE operator does not control that processing, is not its operator and is not responsible for it. Those relations are not governed by this Policy, the License Agreement or the public offer.

2. Single purpose

PolyApiIDE’s single purpose is to provide developers and QA engineers with a tool to compose, send, and inspect HTTP/API requests, manage collections/environments, run QA/load scenarios, and use related IDE helpers initiated by the user.

The Service is not designed for covert browsing-history collection, ad profiling, or data selling.

3. Data we process

3.1. Data that typically stays on the user’s device

  • request collections, environments, variables, IDE settings, and local history in extension storage;
  • license key and activation metadata in chrome.storage;
  • technical API client credentials (client_id / client_secret) if the user opts into a server feature;
  • request/response content entered and viewed by the user in the IDE;
  • request/collection cookies, including values the user explicitly synced from the site via “Sync cookies from site”.

These are not sent to our servers unless the user explicitly triggers a feature that requires it (website checkout, the “Activate Demo” form, creating a technical API client, cloud backup, support request, AI chat history sync, counted QA/load runs). Free does not require an account and does not create a client_id until the user opts into a server feature.

The demo key (14 days of the full product) is issued once per email via the website form with required consents. On Free the server counts collection, folder and load runs per calendar month (separate counters). Paid plans and an active demo are not limited by these quotas.

3.2. Data that may be sent to polyapiclient.ru

CategoryExamplesPurpose
Identifiers email; client_id; license-to-email binding; session device_id (local device/profile UUID) Technical API client (not a store account), license issuance/validation, anti-sharing; active session limits (Free: 2; demo: 1; Month/Year: 5; Lifetime: 5 per key)
Authentication OTP (temporary); hashed client_secret on server Email ownership proof, API protection
Payment data payer email, amount, payment status, YooMoney label/operation id; not full card numbers Lifetime checkout and contract performance
Technical / session extension version; IP and IP hash (logs/anti-abuse); coarse country_code from IP when available; active session heartbeat (client_id, device_id, user-agent/device label) in Redis with short TTL; server metrics Compatibility, security, reliability; concurrent session limits
API client credentials on server client_secret hash; optional secret_encrypted (AES/Crypt) for welcome/re-issue only API client auth and transactional email
Preferences marketing email consent; analytics_opt_out (extension usage analytics refusal) Honour user choices; record extension analytics opt-out
Website cookies essential: language, cookie choice (polyapi_cookie_consent); analytics (Yandex Metrica with webvisor/clickmap) only after “Accept all” Site operation and (with consent) web analytics
User-initiated content IDE cloud backup (Lifetime); support message text; AI chat history (truncated text after secrets and personal data are stripped; attachment metadata without file bytes); cookies stored in the IDE — only if they are included in a backup snapshot Restore settings; customer support; sync AI dialogues across sessions
Consent records privacy policy version, personal data consent time; log (personal_data_consents: email, privacy version, source payment/support/landing/ide, IP); license terms version and acceptance time; acceptance log (terms_acceptances: email, version, source demo/payment/ide/landing, IP); marketing email flag (customers.marketing_email_consent); accepted terms versions list in DB (legal_document_versions). Paid users may accept consents in the IDE (Settings → License); document text stays on the website, versions come from the server. Free does not collect these consents in the extension. Legal record of consent; demo/checkout for any listed version; soft policy updates in the IDE

3.3. Data we do not intentionally collect

  • general browsing history outside user-initiated API calls;
  • user website passwords (except if a session cookie itself holds a secret and the user explicitly synced cookies from that site);
  • site cookies in the background — not without a click on “Sync cookies from site”;
  • live logins, passwords, tokens and personal data from AI chats — history is heuristically scrubbed before it is stored (not a 100% guarantee);
  • data for targeted advertising;
  • precise GPS coordinates; a coarse country_code may be derived from IP for session anti-abuse and is not used for advertising.

3.4. Cookie sync from the site

In the IDE the user may click “Sync cookies from site”. Only after that explicit click does the extension request the optional cookies permission and read the browser cookie jar via chrome.cookiesscoped to the request URL hostname. Cookies are not auto-synced.

Synced cookies are stored locally in the IDE (request/collection cookies) and are not uploaded to our servers unless the user later runs a cloud backup that includes request cookies stored in the IDE.

Risk: session cookies (including for sites where you are logged in) can leak into IDE storage, subsequent HTTP requests, curl preview, cloud backups, and AI prompts if you explicitly send the request contents. Do not sync cookies from production if you do not want them living in the client.

4. Chrome extension permissions

PermissionWhy it is needed
storage, unlimitedStorage Local storage of collections, environments, settings, license, and API client credentials.
tabs, windows Open the IDE window/tab and payment window upon user action.
proxy, webRequest, webRequestAuthProvider Optional HTTP(S) proxy for user API requests (including basic auth) only when configured by the user.
host_permissions: <all_urls> Required for an API client: the user supplies arbitrary API URLs and initiates requests. The extension does not crawl the web in the background.
cookies (optional) Requested on click of “Sync cookies from site”. Reads chrome.cookies only for the request URL hostname. Without that click the permission is not requested and site cookies are not read.

Broad host access is used only to perform requests the user explicitly starts in the IDE (and related IDE features), consistent with the product’s single purpose.

Separately from extension permissions, the browser itself may record installs, updates, crashes and other telemetry under the vendor’s policy. That is not processing by the PolyApiIDE operator and is not covered by this document.

5. How we use data

  • provide IDE functionality and license status checks;
  • create and authenticate a technical API client (OTP + rate limiting) — only if the user opts into a server feature;
  • process Month / Year / Lifetime payments via YooMoney/YooKassa: Month and Year — activation key by email; Lifetime — key and Lifetime archive (and/or a one-time download link); the offline zip is not part of subscription plans;
  • optional manual cloud backup of the IDE (user-triggered only; can be disabled); optional email backup on request;
  • cookie sync from the site — only on an explicit IDE click, locally; not sent to the server unless the user includes those cookies in a cloud backup;
  • AI chat history — truncated message text after heuristic scrubbing of secrets (logins, passwords, tokens, API keys, Bearer/JWT and similar) and personal data (email, phone numbers, card numbers and similar identifiers); attachment metadata (filename, size, has_attachment flag); PDF/file bytes are never stored on the server; can be deleted in IDE settings. Scrubbing does not guarantee 100% detection — do not paste live credentials into chat;
  • marketing emails — only with separate consent (“I agree to receive emails…”);
  • extension usage analytics: IDE action events go to Yandex Metrica (and optionally GA if an ID is configured in the build), not stored as an event journal in our database; the server only keeps the analytics_opt_out flag. Disable in IDE settings;
  • website analytics (Yandex Metrica with webvisor) — only after consent to analytics cookies in the banner;
  • user support;
  • security: fraud/spam/license-abuse prevention;
  • extension version compatibility.

We do not use data for third-party advertising and do not sell personal data.

6. Third parties

  • YooMoney / YooKassa — payment processing;
  • email provider (e.g. Yandex Mail SMTP) — OTP, license keys, support email;
  • hosting / VPS — website and API hosting;
  • Yandex Metrica — website analytics (with cookie consent) and extension usage events (unless opted out in the IDE).

Request content may be sent to third-party APIs chosen by the user — that is the user’s action. Optional AI providers/integrations configured by the user receive only data the user explicitly sends through those features.

7. Storage, security, retention

  • transit to polyapiclient.ru uses HTTPS;
  • API client secrets: hashed for verification; optional encrypted copy (secret_encrypted) for welcome/re-issue;
  • essential site cookies until expiry/clearing; third-party analytics cookies per their policies and only after consent;
  • license keys are not published in public directories;
  • cloud backup: a history of snapshots is kept — the last 3 on Free and the last 10 on paid plans (Month / Year / Lifetime); older ones beyond the limit are deleted when a new snapshot is saved; abandoned records may also be removed under the age-based server retention policy (typically ~90 days);
  • AI chat history is kept until the user deletes a chat or clears all history; deleting an API client nulls the relation;
  • server logs/metrics are kept only as needed for security and operations;
  • local browser data is removed when the user uninstalls the extension.

8. Your rights (152‑FZ) & deletion

Under applicable Russian Federation law (including Federal Law No. 152‑FZ), you may:

  • obtain information about processing of your personal data and access to it;
  • request clarification, blocking or destruction of data that is unlawfully processed or inaccurate;
  • withdraw consent where processing is based on consent (marketing emails; site analytics cookies);
  • opt out of extension usage analytics in IDE settings;
  • uninstall the extension — local IDE data is removed by the browser (chrome.storage);
  • request deletion/correction of server-side data tied to your email (API client, license, backups, AI history) via support@polyapiide.ru;
  • complain to Roskomnadzor or a court as provided by law.

We aim to respond within a reasonable time (typically up to 30 days), subject to mandatory retention for accounting, contract performance and anti-fraud. Withdrawal of consent does not affect lawfulness of processing before withdrawal.

9. Children

The Product is intended for adult developers/professionals. We do not knowingly collect data from children under 13 (or under 16 where required). Contact us to request deletion if you believe such data was provided.

10. International transfers

Servers and processors may be located in different jurisdictions. By using the Service you understand processing may occur outside your country of residence; we apply reasonable safeguards.

11. Policy changes

We may update this Policy. The current version is always at https://polyapiclient.ru/en/privacy. For material changes to data practices we will provide prominent notice (website and/or in-product / email where appropriate). The effective date is shown at the top.

The license agreement is updated on the server independently of Chrome Web Store releases. Demo and checkout accept any version from the accepted list in the database (not only the latest). If an earlier accepted version is on file, the IDE may show “Service policies have changed” with links to the fresh documents and an option to accept the latest version; acceptance is stored on the server.

12. Contact

Personal data operator / privacy requests:
Email: support@polyapiide.ru
Phone: +7 (916) 208‑38‑14
Telegram: @Efin_Yuri
Self-employed: Ефин Юрий Анатольевич
TIN (INN): 500173519797
Support: https://polyapiclient.ru/en/support
Website: https://polyapiclient.ru

13. Related documents

  • PolyApiIDE License Agreement
  • This Policy is the public disclosure of data practices for Chrome Web Store and Microsoft Edge Add-ons listing.