Repuso API - Privacy Policy
Last updated 2026-08-08. Covers the Repuso API and its developer console (api.repuso.com, repuso.com/developers). Supplements the main Repuso Privacy Policy; where they differ for API usage, this policy controls.
Who we are
The Repuso API is operated by OnClick Solutions Ltd ("Repuso", "we"). Contact: hello@repuso.com. See our support page.
What we collect
- Account data - the email address you sign in with (OTP login), your API keys, plan and billing state. We do not store API passwords; sign-in is a one-time email code.
- Configuration you create - the review profiles you choose to monitor, groups, tags, webhook endpoints and their settings.
- Public review data - reviews, ratings and profile metadata publicly available on the source platforms for the profiles you monitor, collected on a schedule and returned to you as normalized JSON.
- Usage metadata - per-request records (timestamp, endpoint, method, status, count) used for rate limiting, quotas and billing. We do not store your request payloads or response bodies beyond a short-lived recent-requests buffer shown in your own console.
How we use it
- To provide the service: run the crawlers, serve the API, deliver webhooks and show your console.
- To meter usage and bill your account.
- To secure the service - detect abuse, rotate compromised keys, enforce rate limits.
- To send transactional email (login codes, quota notices, billing). We do not sell your data or use it for advertising.
AI tool connections (MCP / OAuth)
When you connect an AI tool (Claude, ChatGPT, Cursor and others) via our MCP server, that tool authenticates either with your API key or through our OAuth sign-in. An OAuth authorization grants the connected tool access to your account through short-lived tokens which you can revoke by rotating your API key or contacting support. Tool calls are ordinary API calls on your account and are logged as usage like any other request. We do not share your data with the AI provider beyond the responses your own tool requests.
Sub-processors
We use third parties strictly to operate the service: cloud hosting and crawling infrastructure, Stripe (payments), and an email provider (transactional email). Review data is retrieved from the public source platforms you select.
Retention
- Collected reviews and configuration persist while the profile is monitored; removing a profile deletes its collected reviews (unless you ask to keep them).
- Usage aggregates are retained for billing and abuse-prevention. The recent-requests buffer expires within days.
- Closing your account removes your configuration and collected data on our standard schedule, subject to legal retention obligations.
Your rights
You can access, export, correct or delete your account data. Email hello@repuso.com and we will respond within a reasonable period. If you are in a jurisdiction with statutory data rights (e.g. GDPR/UK GDPR), see also our GDPR notice.
Security
API traffic is TLS-encrypted. API keys are confidential - do not embed them in client-side code or public repositories, and rotate immediately if exposed. We may suspend or rotate keys showing signs of compromise.
Changes
We will update this page and the "last updated" date when this policy changes materially.
← Repuso for developers · API Terms · Support