← Back to home

Privacy Policy

Last updated: June 9, 2026

1. Who We Are

FAMAPI ("we", "us", "our") is an independent developer tool operated by TEAM-AKIRU, providing a UPI payment verification API service accessible at provider.akiru.online. We are not affiliated with, endorsed by, or connected to FamApp (formerly FamPay), Trio, or IDFC FIRST Bank in any way.

For privacy-related inquiries, contact us at a69881018@gmail.com.

2. What Data We Collect

We collect only the minimum data necessary to operate the service:

2.1 Account Information

  • Your email address, display name, and profile picture from your Google account (provided at sign-in via OAuth).
  • We do not collect your Google account password.

2.2 Gmail Access (Optional)

  • If you choose to connect your Gmail account, we request read-only access to your inbox.
  • We use this access solely to search for UPI transaction confirmation emails from your payment provider to verify payment status.
  • We do not read, store, index, or process any other emails in your inbox.
  • We store only your Gmail OAuth refresh token (encrypted) to perform verification on your request. We never store email content.
  • You can revoke Gmail access at any time from your Google Account settings at myaccount.google.com/permissions or from within your dashboard.

2.3 Payment Records

  • UPI purpose codes, payment amounts, timestamps, and verification status are stored to provide your payment history and enforce API quotas.
  • We do not store full UPI transaction IDs, bank account numbers, or any sensitive financial credentials.

2.4 Usage & Technical Data

  • API request logs including IP addresses, endpoints called, and timestamps, retained for security, abuse prevention, and analytics.
  • API keys generated for your account.

3. How We Use Your Data

  • To authenticate you and maintain your account.
  • To verify UPI payments on your explicit request via the API.
  • To enforce rate limits and daily request quotas per your subscription plan.
  • To display your payment history and usage analytics in the dashboard.
  • To send transactional emails such as subscription confirmations (no marketing emails without consent).
  • To investigate abuse, fraud, or violations of our Terms of Service.

We do not sell, rent, or trade your personal data to any third party. We do not use your data for advertising.

4. Google API Data Usage Disclosure

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only access Gmail data when you explicitly trigger a payment verification request.
  • Gmail data is used only to detect payment confirmation emails — for no other purpose.
  • We do not transfer Gmail data to third parties except as necessary to perform the verification (e.g., our own servers).
  • We do not use Gmail data for serving advertisements or for any purpose unrelated to the service.
  • We do not allow humans to read your Gmail data unless required by law or you give explicit permission for debugging.

5. Data Storage & Security

  • Data is stored in Supabase (PostgreSQL), hosted on Google Cloud infrastructure.
  • Gmail refresh tokens are stored encrypted at rest.
  • All data transmission between your browser and our servers uses HTTPS/TLS encryption.
  • API keys are hashed and stored securely. Never share your API key.
  • Payment records are retained for 90 days after creation, then automatically deleted.
  • Request logs (IP addresses) are retained for 30 days for security purposes.

6. Third-Party Services

We use the following third-party services which have their own privacy policies:

  • Supabase — authentication and database hosting (supabase.com/privacy).
  • Google OAuth & Gmail API — sign-in and payment email verification (policies.google.com/privacy).
  • ImgBB — temporary QR code image hosting (images are deleted after payment verification or expiry).
  • Vercel — web hosting and serverless functions.

7. Your Rights

  • Access: You can view all your payment records and account data in the dashboard at any time.
  • Correction: Contact us to correct inaccurate personal data.
  • Deletion: You can request full account deletion by emailing us. All profile data, Gmail credentials, payment records, and API keys will be permanently deleted within 7 days.
  • Gmail Revocation: Disconnect Gmail at any time from your dashboard or directly via Google Account settings.
  • Portability: Export your payment history as CSV from the Payments page.

8. Children's Privacy

This service is intended for developers aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us immediately for deletion.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and notify you via email if the changes are material. Continued use of the service after changes constitutes your acceptance of the updated policy.

10. Contact Us

For any privacy-related questions, data deletion requests, or concerns: