GovCon API Get a free key

Privacy Policy

What GovCon API collects, why, who processes it for us, how long it is kept, and how to have yours deleted.

Effective date: May 15, 2026. Last updated: September 28, 2026.

Scope

This policy covers govconapi.com: the website, the REST API and the MCP server.

GovCon Contacts, the web application at contacts.govconapi.com, has its own privacy policy for the information that application collects. You sign in to it with your GovCon API account, so the account record described below is also used for that sign-in.

Summary

  • We collect the email address on your account, a log of your API requests, whether your subscription is active, and what you send us by chat, email or on-page feedback.
  • We use it to deliver keys, run billing, prevent abuse, answer support requests and understand how the API is used.
  • We do not sell personal information.
  • Our API request log does not record the body of any request or response.
  • If your application calls our API for your users, we see the requests your servers send, including their search parameters, but not who your users are.
  • To see, correct, export or delete your information, email [email protected].

What we collect

Your account. The email address you give when you request a key or subscribe. When you request a key or subscribe on our site, we store it in lowercase and without any "+tag", because one inbox is one account. With it we keep your API key, your plan, whether the plan includes Pro, whether the key is active, when it was created and when it expires, and whether you have used the free trial. When you request a new key, the earlier key is deactivated and its record is kept.

We use your email to send your key; account and billing messages (plan changes, cancellation, renewal receipts, failed payments, a reminder before a trial ends); and replies to support requests.

Your API requests. For every request to /api/v1/ we record the time, the endpoint, the HTTP method, the query parameters (each value cut to 256 characters), the response status, the response time, the email and plan of the account, an internal ID for the key (not the key itself), the IP address the request came from, and the user agent. Requesting a key or starting a checkout on our site is also an API request, so the email address you enter is recorded with it. We do not record request or response bodies. Requests for web pages are not in this log.

We use this log to investigate abuse and key sharing, to troubleshoot and answer support requests, to test changes against the kinds of requests customers send, and to learn which endpoints and parameters are used, so we can improve them and tell the customers a change would affect.

Billing. Stripe processes paid plans and collects and stores your payment details. We never receive your full card number or security code. Our own records hold your email, your plan and whether your subscription is active; when we need your Stripe customer record, we look it up by email. We also still hold the full billing notifications Stripe sent us up to November 2025, which carry subscription and invoice details.

Chat. The chat widget on many of our pages is provided by tawk.to. When it loads, tawk.to receives your IP address and browser details, and it stores any conversation you start so we can reply and follow up.

Email to support. We keep the email you send to [email protected] so we can answer you and keep a history of your account.

On-page feedback. Several pages let you send us a note about the page by pressing Ctrl+Enter (Cmd+Enter on a Mac). We record the page, the referring page, your note, any text you had selected, your IP address and your browser's user agent, and we email the note to our team. The note also appears in our application logs.

The free CAGE code lookup. It uses hCaptcha to keep automated traffic out. hCaptcha receives your IP address and information about your browser.

Website analytics and advertising. Some pages on our website use Google Analytics, and the home page also loads a Google Ads tag for advertising measurement. Google records the pages you view, the referring site, your device and browser, and an approximate location derived from your IP address, using cookies. Some pages also load web fonts from Google Fonts, which receives your IP address when the page loads. The API explorer at /docs loads its script from jsDelivr, which receives your IP address.

Edge and hosting logs. Cloudflare sits in front of govconapi.com and processes request information, such as IP address, user agent and country, for security, DDoS protection and routing. For requests that do not identify themselves as a web browser, which includes most API and MCP calls, we also record the path, method, IP address, user agent, country, network operator and referring page in a Cloudflare analytics store, to tell crawlers, bots and scanners apart from customers. Our hosting provider keeps application logs, which include the paths and query strings of requests and can include email and IP addresses.

What we do not collect

  • Request and response bodies in the API request log. The log records that a request happened and how it ended.
  • Who your users are. If you build on the API, we receive your servers' requests, including their parameters, not your customer list.
  • Your conversations with an AI assistant. The MCP server runs alongside your AI client and sends only the parameters of each tool call, as ordinary API requests. The conversation around them does not reach us.
  • Card details. Stripe handles them.
  • Sensitive personal information. We do not ask for it. Please leave it out of support requests unless it is needed.

Service providers

These providers process information for us, under their own terms:

  • Stripe: payments and subscriptions. Privacy policy
  • Resend: delivery of account emails and of notifications to our team. Privacy policy
  • Cloudflare: DNS, TLS, content delivery, security, bot analytics and encrypted backup storage. Privacy policy
  • Railway: application hosting and application logs. Privacy policy
  • Hetzner: infrastructure hosting, in Germany. Privacy policy
  • tawk.to: chat. Privacy policy
  • hCaptcha: the bot check on the free CAGE code lookup. Privacy policy
  • jsDelivr: delivery of the script for the API explorer at /docs. Privacy policy
  • Google: website analytics, advertising measurement, web fonts, and the mailbox that receives our copies of billing emails. Privacy policy

We do not sell personal information to these providers or to anyone else.

How long we keep it

  • Account records: while your account exists. Deactivated keys and ended subscriptions stay in our account records until you ask us to delete them.
  • API request logs: not deleted on a schedule. Entries stay after an account ends; ask us and we delete or anonymize the entries tied to your account.
  • On-page feedback: until you ask us to delete it.
  • Billing records: Stripe keeps payment and invoice records under its own obligations.
  • Chat transcripts: kept in tawk.to until we delete them. We delete yours on request.
  • Website analytics: for the retention period set in our Google Analytics account.
  • Bot analytics and edge logs: for Cloudflare's standard retention.
  • Application logs: for Railway's standard log retention.
  • Backups: encrypted, and kept on a rolling schedule of a few months. Information deleted from the database stays in older backups until they expire.

Your choices and rights

Wherever you are, you can ask us to:

  • show you the information we hold about you
  • correct anything that is wrong, including moving your key, plan and subscription to a new email address
  • export your account record and the request-log entries tied to it
  • delete your account: we deactivate your keys, delete your account record, and delete or anonymize your request-log entries. Records we must keep for billing, tax, security or fraud prevention stay, and we tell you what remains and why. Copies in backups expire on the schedule above.

Email [email protected]. We answer within 30 days.

Cookies and similar technologies

  • Google Analytics cookies on the pages that use it, and Google Ads cookies on the home page.
  • tawk.to cookies and browser storage on pages with the chat widget, so a returning visitor sees their conversation.
  • hCaptcha on the free CAGE code lookup, for its bot check.
  • Cloudflare can set a security cookie to tell people from automated traffic.

Our site has no signed-in area and sets no cookies of its own. The API does not use cookies: it reads your key from the Authorization header. Blocking analytics or advertising cookies does not affect the API or the site.

Security

  • govconapi.com is served over HTTPS, and traffic between our application and our database is encrypted in transit.
  • The database is not reachable from the public internet, and administrative access to it is restricted.
  • Backups are encrypted.
  • Access to production systems is restricted to authorized personnel.
  • API keys are stored in our database as issued, not hashed, and are sent to you by email. Treat your key like a password. If it is exposed, request a new one with the same email address and the old key stops working at once. Your responsibilities for your key are in the Terms of Service.
  • We do not hold SOC 2 or ISO 27001 certification. If your compliance program requires a specific framework, email us before relying on an assumption.

Report a security issue to [email protected].

International processing

Our application and database are hosted in the EU. Stripe, Resend, Google, tawk.to, hCaptcha and Cloudflare may process information in the United States and in other countries where they operate.

Children

GovCon API is a business and developer service and is not directed to children. We do not knowingly collect personal information from children.

Changes to this policy

When we make a material change, such as collecting a new kind of information or adding a provider that receives personal information, we email account holders before it takes effect. The date at the top shows the current version.

Contact

Questions or requests about this policy: [email protected]