Cookie Policy
Last updated: 25 August 2026
This Cookie Policy explains how API Hubs ("we", "us") uses cookies and similar browser technologies on the API Hubs website and dashboard. It should be read together with our Privacy Policy.
Google Analytics notice
API Hubs uses Google Analytics when you use the website. Browser activity is measured by the Google tag, while confirmed product events are sent from our server through the Google Analytics Measurement Protocol. By accessing or continuing to use the website, you consent to this analytics collection as described here and in the Privacy Policy.
Technology categories
Essential
Used for authentication, account security, OAuth sign-in and core website functions. These technologies are required for the Service to work and cannot be switched off through the website. They also cover the device check behind the free signup trial, which lets the trial be granted once per device; the rest of the Service works even when that check cannot run.
Preferences
Used to remember a choice you make, such as light, dark or system theme. Preference storage is not used to identify you or follow you across websites.
Analytics
Google Analytics measures page usage, traffic sources and selected funnel events. By accessing or continuing to use the website, you consent to this analytics collection. We keep Google Ads, advertising personalisation, heatmaps and session recording disabled.
Analytics provider
The following third-party service receives browser and usage data to provide analytics reports.
Google Analytics
When you use the website, Google Analytics receives page URLs, referrers, campaign parameters, device and browser information, a pseudonymous identifier, and selected product-funnel events. Signed-in activity may be associated with your internal user ID, but we do not send your email address. Google Ads and remarketing are not enabled.
Browser storage and identifiers
The names below describe the storage API Hubs currently uses. Exact authentication cookie names may include security prefixes and can differ between development and production deployments.
Better Auth session cookies
Strictly necessary cookies that keep you signed in, associate requests with your account and protect the authentication flow. Session cookies contain a random token rather than your password. Their expiry follows the session settings of the Service.
OAuth and security cookies
Short-lived, strictly necessary values may be created while you sign in with Google or GitHub. They help validate the callback and prevent request forgery, and expire after the authentication flow or a short fixed period.
theme
Local browser storage that remembers whether you selected the light, dark or system theme. It remains on the device until you change the choice or clear browser storage and is not sent with every HTTP request.
apistock_device_id
HTTP-only cookie that stores a signed device identifier issued by our identity service. It lets the free signup trial be granted once per device rather than once per email address. It holds no account data, cannot be read by scripts and expires after 24 hours.
apistock_device_anchor
Companion cookie that holds only the outcome of the last device check: that it succeeded, so it is not repeated on every page, or that it failed, so it is not retried for about ten minutes. It contains no identifier and does not decide whether you receive the trial.
_ga and _ga_<container-id>
Google Analytics cookies that distinguish pseudonymous browser sessions and apply Google's configured expiry rules.
apistock_ga_client_id and apistock_ga_session_id
HTTP-only first-party copies of the identifiers generated by Google Analytics. They let confirmed server events, such as a completed payment, be associated with the same analytics browser and session.
How your choices work
- You can change the visual theme at any time using the theme control in the site header or dashboard profile menu.
- By accessing or continuing to use the website, you consent to the Google Analytics collection described in this Policy. If you do not agree, do not continue using the website and use browser settings or a content blocker to block analytics.
- You can remove cookies and local storage through your browser settings. Removing the theme value resets the preference; removing session cookies signs you out; removing Google Analytics cookies resets its pseudonymous browser identifiers.
- You can block cookies in your browser, but blocking strictly necessary authentication storage may prevent sign-in and other account features from working.
- API requests authenticated with an API key do not require a browser session cookie.
Retention
Session and temporary authentication cookies expire according to their configured lifetime and may be deleted earlier when you sign out. The theme preference remains until you change it or clear browser storage. Google Analytics identity links are kept for up to 400 days after the browser was last seen, and successfully delivered server-event records are normally removed after 30 days. Google Analytics event data is configured for 14-month retention. We do not use browser identifiers for advertising profiles.
Third-party websites and international processing
Google may process analytics data in other countries under its own privacy and security terms. Links from API Hubs may also take you to documentation, model providers, sign-in providers or payment providers. Technologies used on those external services are controlled by their own cookie and privacy policies.
Updates to this Policy
We may update this Policy when our authentication, browser storage or third-party integrations change, or when legal requirements change. The latest revision date is shown above. Material changes will be disclosed through the website, dashboard or email as appropriate.
Contact us
If you have questions about this Cookie Policy or our use of browser technologies, contact us at support@apihubs.ru.
For more information about how we handle personal data, read our Privacy Policy.