This Privacy Policy (“Policy”) explains how the operator of https://polyapiclient.ru and the PolyApiIDE browser extension (“Service”, “Product”) handles information when you use:
Personal data operator (under applicable Russian Federation law, including Federal Law No. 152‑FZ): self-employed individual in the Russian Federation Efin Yuriy Anatolyevich (Ефин Юрий Анатольевич), TIN (INN) 500173519797, phone +7 (916) 208‑38‑14, Telegram @Efin_Yuri, email support@polyapiide.ru. See also the Contacts page.
By installing the extension, using the website, or purchasing Lifetime, you acknowledge this Policy. License terms are set out in the License Agreement.
After you install the extension, the browser (Google Chrome, Mozilla Firefox, Microsoft Edge or another vendor) may independently collect and process additional data about you and your device under that vendor’s privacy policy and terms. The PolyApiIDE operator does not control that processing, is not its operator and is not responsible for it. Those relations are not governed by this Policy, the License Agreement or the public offer.
PolyApiIDE’s single purpose is to provide developers and QA engineers with a tool to compose, send, and inspect HTTP/API requests, manage collections/environments, run QA/load scenarios, and use related IDE helpers initiated by the user.
The Service is not designed for covert browsing-history collection, ad profiling, or data selling.
chrome.storage;client_id / client_secret) if the user opts into a server feature;These are not sent to our servers unless the user explicitly triggers a feature that requires it (website checkout, the “Activate Demo” form, creating a technical API client, cloud backup, support request, AI chat history sync, counted QA/load runs). Free does not require an account and does not create a client_id until the user opts into a server feature.
The demo key (14 days of the full product) is issued once per email via the website form with required consents. On Free the server counts collection, folder and load runs per calendar month (separate counters). Paid plans and an active demo are not limited by these quotas.
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | email; client_id; license-to-email binding; session device_id (local device/profile UUID) | Technical API client (not a store account), license issuance/validation, anti-sharing; active session limits (Free: 2; demo: 1; Month/Year: 5; Lifetime: 5 per key) |
| Authentication | OTP (temporary); hashed client_secret on server | Email ownership proof, API protection |
| Payment data | payer email, amount, payment status, YooMoney label/operation id; not full card numbers | Lifetime checkout and contract performance |
| Technical / session | extension version; IP and IP hash (logs/anti-abuse); coarse country_code from IP when available; active session heartbeat (client_id, device_id, user-agent/device label) in Redis with short TTL; server metrics | Compatibility, security, reliability; concurrent session limits |
| API client credentials on server | client_secret hash; optional secret_encrypted (AES/Crypt) for welcome/re-issue only |
API client auth and transactional email |
| Preferences | marketing email consent; analytics_opt_out (extension usage analytics refusal) |
Honour user choices; record extension analytics opt-out |
| Website cookies | essential: language, cookie choice (polyapi_cookie_consent); analytics (Yandex Metrica with webvisor/clickmap) only after “Accept all” |
Site operation and (with consent) web analytics |
| User-initiated content | IDE cloud backup (Lifetime); support message text; AI chat history (truncated text after secrets and personal data are stripped; attachment metadata without file bytes); cookies stored in the IDE — only if they are included in a backup snapshot | Restore settings; customer support; sync AI dialogues across sessions |
| Consent records | privacy policy version, personal data consent time; log (personal_data_consents: email, privacy version, source payment/support/landing/ide, IP); license terms version and acceptance time; acceptance log (terms_acceptances: email, version, source demo/payment/ide/landing, IP); marketing email flag (customers.marketing_email_consent); accepted terms versions list in DB (legal_document_versions). Paid users may accept consents in the IDE (Settings → License); document text stays on the website, versions come from the server. Free does not collect these consents in the extension. |
Legal record of consent; demo/checkout for any listed version; soft policy updates in the IDE |
In the IDE the user may click “Sync cookies from site”.
Only after that explicit click does the extension request the optional cookies permission
and read the browser cookie jar via chrome.cookies — scoped to the request URL hostname.
Cookies are not auto-synced.
Synced cookies are stored locally in the IDE (request/collection cookies) and are not uploaded to our servers unless the user later runs a cloud backup that includes request cookies stored in the IDE.
Risk: session cookies (including for sites where you are logged in) can leak into IDE storage, subsequent HTTP requests, curl preview, cloud backups, and AI prompts if you explicitly send the request contents. Do not sync cookies from production if you do not want them living in the client.
| Permission | Why it is needed |
|---|---|
storage, unlimitedStorage |
Local storage of collections, environments, settings, license, and API client credentials. |
tabs, windows |
Open the IDE window/tab and payment window upon user action. |
proxy, webRequest, webRequestAuthProvider |
Optional HTTP(S) proxy for user API requests (including basic auth) only when configured by the user. |
host_permissions: <all_urls> |
Required for an API client: the user supplies arbitrary API URLs and initiates requests. The extension does not crawl the web in the background. |
cookies (optional) |
Requested on click of “Sync cookies from site”. Reads chrome.cookies only for the request URL hostname. Without that click the permission is not requested and site cookies are not read. |
Broad host access is used only to perform requests the user explicitly starts in the IDE (and related IDE features), consistent with the product’s single purpose.
Separately from extension permissions, the browser itself may record installs, updates, crashes and other telemetry under the vendor’s policy. That is not processing by the PolyApiIDE operator and is not covered by this document.
analytics_opt_out flag. Disable in IDE settings;We do not use data for third-party advertising and do not sell personal data.
Request content may be sent to third-party APIs chosen by the user — that is the user’s action. Optional AI providers/integrations configured by the user receive only data the user explicitly sends through those features.
secret_encrypted) for welcome/re-issue;Under applicable Russian Federation law (including Federal Law No. 152‑FZ), you may:
chrome.storage);We aim to respond within a reasonable time (typically up to 30 days), subject to mandatory retention for accounting, contract performance and anti-fraud. Withdrawal of consent does not affect lawfulness of processing before withdrawal.
The Product is intended for adult developers/professionals. We do not knowingly collect data from children under 13 (or under 16 where required). Contact us to request deletion if you believe such data was provided.
Servers and processors may be located in different jurisdictions. By using the Service you understand processing may occur outside your country of residence; we apply reasonable safeguards.
We may update this Policy. The current version is always at https://polyapiclient.ru/en/privacy. For material changes to data practices we will provide prominent notice (website and/or in-product / email where appropriate). The effective date is shown at the top.
The license agreement is updated on the server independently of Chrome Web Store releases. Demo and checkout accept any version from the accepted list in the database (not only the latest). If an earlier accepted version is on file, the IDE may show “Service policies have changed” with links to the fresh documents and an option to accept the latest version; acceptance is stored on the server.
Personal data operator / privacy requests:
Email: support@polyapiide.ru
Phone: +7 (916) 208‑38‑14
Telegram: @Efin_Yuri
Self-employed: Ефин Юрий Анатольевич
TIN (INN): 500173519797
Support: https://polyapiclient.ru/en/support
Website: https://polyapiclient.ru