Privacy Policy

Last updated: September 2026

1. Who we are

Form4API (“we”, “us”) operates the API and website at form4api.com. We provide programmatic access to publicly available SEC Form 4 insider trading filings.

Form4API is operated independently from Sweden and is the data controller for the personal data described in this policy. A formal business entity has not yet been registered; this section will be updated with the registered name and Swedish organisationsnummer once it is. Governing law is Sweden. You can reach us about privacy at support@form4api.com.

2. Data we collect

Account data

When you sign up, Clerk (our authentication provider) collects your email address and manages your session. We store your Clerk user ID linked to your API key and plan.

Email & communications data

We store your email address (synced from Clerk) in our own systems so we can send you the account and lifecycle emails described in Section 3. Every such email includes a one-click unsubscribe link, and you can manage these preferences from your dashboard at any time.

Early-access / waitlist

If you ask to be notified about a paid plan while self-serve checkout isn't yet available, we record which plan you expressed interest in so we can email you when it opens. This is deleted when you unsubscribe or delete your account.

API usage data

We log every API request: timestamp, endpoint, HTTP status code, and your API key identifier. We use this to enforce rate limits, display your usage stats, and debug issues. These logs do not contain your IP address, and individual request logs are retained for 90 days.

Payment data

Payments are processed by Stripe. We do not store card numbers or bank details. We receive confirmation of your subscription plan and billing status from Stripe.

Technical data

Standard server logs may include IP addresses and user-agent strings. Vercel Analytics collects anonymised, cookieless page-view data. We also use Google Analytics 4 (see Section 4 and the Cookies section below), which sets cookies and collects data such as your approximate IP address, browser type, device, and pages visited. Google Analytics data is only collected after you give explicit consent via our cookie banner.

Dashboard session recordings

On pages under /dashboard only — never on the public website — we use PostHog to record a visual replay of clicks, scrolls, and page views, so we can see where signed-up users get stuck or abandon setup. Sensitive fields (your API key, webhook signing secrets) and all form inputs are masked before a recording ever leaves your browser. This is collected only after you accept our cookie banner, applies only to the dashboard, and is used solely to watch session replays — we do not use PostHog for analytics, experiments, or any other purpose.

API usage data

When you call the API with your key we record the endpoint, the query parameters you used, the response status, how long it took, and which of our clients you called through (for example our MCP server or one of our SDKs). We use this to operate the service, enforce rate limits, and understand which features are actually used. Detailed request logs are deleted after 90 days; aggregated daily totals are kept so we can measure long-term trends. We do not record request or response bodies, and these logs do not contain your API key.

How you found us

Where you consent to cookies, we record once how you first arrived — any campaign tags in the link, the domain name (not the full address) of the referring site, and the page you landed on. See the f4_attr cookie in Section 6.

Testimonial submissions

If you choose to submit a testimonial, we collect the name, title, company, and email address you provide, your star rating, your written quote, and any optional video or link. Where you give your consent, your testimonial together with your name, title, and company may be displayed publicly on our website and in marketing materials. Submitting a testimonial is entirely optional and is not required to use the Service.

3. How we use your data

  • To authenticate you and serve your API key
  • To enforce rate limits and plan quotas
  • To process payments and manage your subscription
  • To display usage statistics in your dashboard
  • To send transactional emails (e.g. account and billing confirmations) via Clerk and Stripe
  • To send service and lifecycle emails about your account (e.g. getting started, a heads-up as you approach your usage limit, and occasional product updates) — every one of these carries a one-click unsubscribe link, and you can turn them off from your dashboard at any time. Optional product-update/marketing emails are sent only if you opt in.
  • To publicly display testimonials you submit, where you have given consent, on our website and in marketing materials
  • To investigate abuse or security incidents

Legal basis (GDPR). We process account and usage data to provide the Service you signed up for (performance of a contract); service/lifecycle emails and security/abuse handling on our legitimate interest in operating and protecting the Service (with a one-click opt-out); analytics cookies and any marketing email only with your consent.

We do not sell your data, use it for advertising, or share it with third parties except as described in Section 4.

4. Third-party processors

ProcessorPurposeData shared
ClerkAuthenticationEmail, session tokens
StripePayment processingEmail, billing info
ResendTransactional & lifecycle email deliveryEmail address
VercelHosting & analyticsAnonymised page views
Google LLCAnalytics (GA4)IP address, device, browsing behaviour — consent required
PostHogDashboard session replay onlyMasked click/scroll/page-view recordings from /dashboard — consent required
HetznerAPI server hostingAPI request logs
SentryError monitoringStack traces (no PII)

5. Data retention

  • Account data is retained while your account is active and for 30 days after deletion.
  • Your stored email address, waitlist interest, and testimonial submissions are retained until you unsubscribe (email) or delete your account, whichever applies.
  • API request logs are retained for 90 days.
  • Payment records are retained as required by law (typically 7 years).

6. Cookies

We use strictly-necessary authentication cookies (no consent required) and, only with your consent, analytics cookies:

CookieProviderPurposeExpiry
__session, __clientClerkAuthentication / keeps you signed in (strictly necessary)Session
_gaGoogle AnalyticsDistinguishes users (consent required)2 years
_ga_*Google AnalyticsSession state (consent required)2 years
cookie_consentForm4APIStores your consent choice (localStorage)Until cleared
f4_attrForm4APIRecords which channel first brought you here, so we know where our users come from (consent required)30 days
ph_*PostHogSession identifier for dashboard-only screen recordings (consent required)1 year

Google Analytics cookies are only set after you accept via our cookie banner. You can withdraw consent at any time by clearing your browser's local storage or cookies, which will cause the banner to reappear on your next visit.

f4_attr is a first-party cookie we set, only with your consent, to record how you first found us. It holds any campaign tags in the link you arrived through (utm_source, utm_medium, utm_campaign), the domain name of the site that linked to us, and the page you landed on. It stores the domain only — never the full referring address — and no IP address. It is written once and never updated, so returning later through a different link does not change it, and it is not set at all if you arrive directly or with no referring site. If you create an account, this is saved once against your account so we can see which channels bring people to Form4API. It is never shared with third parties and is not used to track you across other websites.

Google LLC processes analytics data in the United States under Standard Contractual Clauses. Google's Privacy Policy.

PostHog session replay only runs on pages under /dashboard, only after you accept the cookie banner there, and never on the public marketing or data pages. It masks your API key, webhook secrets, and all form inputs before anything is recorded. PostHog's Privacy Policy.

7. Your rights

You can request access to, correction of, or deletion of your personal data at any time by emailing support@form4api.com. We will respond within 30 days. You can delete your account at any time from your account settings — doing so removes your API keys, stored email address, testimonials, and any waitlist interest from our systems. You can stop lifecycle emails without deleting your account using the unsubscribe link in any email or the preferences on your dashboard.

If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY, Integritetsskyddsmyndigheten).

8. Security

All data is transmitted over HTTPS. API keys are stored hashed. We do not store plaintext credentials. If you believe your API key has been compromised, contact us immediately and we will rotate it.

9. Changes

We may update this policy. Material changes will be communicated by email to registered users. Continued use of the service after changes constitutes acceptance.