ApiChatcher Privacy Policy

Overview

ApiChatcher (hereinafter referred to as "we" or "the App") is a multi-platform HTTP/HTTPS packet capture and debugging tool for iOS, Android, macOS, and Windows, designed to help developers and testers capture, analyze, and debug network traffic. We respect and protect the privacy of every user. This Privacy Policy explains how we collect, use, store, and protect your personal information. Please read it carefully before using the App.

App Description

ApiChatcher is a multi-platform HTTP/HTTPS packet capture and debugging tool for iOS, Android, macOS, and Windows. It helps users capture HTTP/HTTPS requests and responses, generate API documentation, export to Postman or Apifox, replay requests, rewrite responses, and use scripts for advanced debugging workflows.

Data Storage and Processing

Data Storage Location

  • Local Storage: ApiChatcher stores all captured network traffic locally on your device. Your data stays on your device—not on our servers—so your captured traffic remains private.

Account System

  • Optional Login: ApiChatcher offers optional account sign-in. You can register and sign in with your email address and a verification code. Sign-in is optional; you can use the core capture and debugging features without an account.
  • Purpose of Login: Sign-in is used to: (1) sync your subscription status so your benefits apply across platforms (iOS, Android, macOS, Windows) and devices; and (2) when you choose to enable Cloud Sync, back up end-to-end encrypted rule-based configuration to our servers for cross-device sync. We do not use your login information for any other purpose.
  • Account Usage Limit: One account may be used on up to 3 platforms at the same time. Accounts are for personal use only—please do not share or lend your account.
  • Data Separation: Your account information is separate from captured network traffic. Whether you sign in does not affect your local control over captured data. Cloud Sync uploads encrypted rule configuration only, not packet capture data (see "Cloud Sync" below).

Subscriptions and Payments

When you purchase Pro or Ultimate membership, payment is processed by:

  • Apple App Store: in-app purchases on iOS
  • Google Play: in-app purchases on Android
  • Official website: WeChat Pay (for Chinese users) or Creem (other regions), as shown on the purchase page

We do not directly collect or store sensitive payment details such as card numbers or payment passwords. These platforms provide information needed to verify subscriptions (order IDs, subscription IDs, product identifiers, expiration dates, etc.) so we can link membership to your account. Each platform's handling of payment data is governed by its own privacy policy.

Network Traffic Data

Captured Data

  • Local Processing: All captured HTTP/HTTPS requests and responses are processed and stored locally on your device.
  • No Capture Data Upload: We do not transmit captured network traffic to our servers or third parties.

Data Processing Principles

  • Local Processing: All capture data is processed on your device.
  • User Control: You have full control over captured data, including viewing, exporting, and deleting it.

Cloud Sync (Optional)

You may voluntarily enable Cloud Sync to sync selected rule-based configuration (such as Host filters, DNS mapping, rewrite rules, scripts, combo replay, and Protobuf descriptor files) across signed-in devices. The feature is off by default; you must set an encryption passphrase on your device and turn it on manually.

How This Differs from Capture Data

  • Captured traffic data (capture history, sessions, request/response bodies, etc.) stays on your device only and is never uploaded through Cloud Sync.
  • Cloud Sync covers rule and configuration files only, and applies end-to-end encryption on your device before upload.

What We Store on Our Servers

When you use Cloud Sync, our servers may store:

  • Encrypted configuration backups (ciphertext): Not readable as plaintext without your encryption passphrase.
  • Key fingerprint: A checksum derived on your device from the encryption key, used to verify all devices use the same key; not your passphrase and cannot be reversed to recover the passphrase or key.
  • Salt: A public parameter used in passphrase-based key derivation; alone, it cannot decrypt data.
  • Sync metadata: Such as configuration type, item IDs, version numbers, and update timestamps for incremental sync—not configuration plaintext.

What We Do Not Store

  • Your encryption passphrase
  • The encryption key used to decrypt configuration (derived locally from your passphrase)
  • Any unencrypted rule or script plaintext
  • Capture traffic, sessions, request/response bodies, etc.

Your Control

  • You can turn off Cloud Sync at any time; turning it off does not automatically delete existing cloud backups.
  • You can delete cloud configuration data in the app, which removes encrypted backups from our servers only and does not affect local configuration on your device (unless you clear app data yourself).
  • Your encryption passphrase is stored only in secure local storage on your device and is never uploaded. If you forget it, we cannot recover it; you may need to delete cloud data and set a new passphrase. See the Cloud Sync User Guide.

User Data Collection

User Data We Collect

  • Account Information: If you sign in, we collect the email address used for registration, for account identification and subscription sync only.
  • Subscription Information: When you purchase through the Apple App Store, Google Play, or our website, we receive information needed to verify and sync subscription status—not for other purposes.
  • Data We Do Not Collect: ApiChatcher does not collect, store, or analyze captured packet data, traffic content, device information, location data, etc. All capture data stays on your device. We do not collect your Cloud Sync encryption passphrase; the cloud stores ciphertext and metadata such as fingerprints and salts only (see "Cloud Sync").

Security Measures

  • Local Storage: All capture-related data is stored locally on your device for maximum privacy.
  • Encrypted Upload (Optional): If you enable Cloud Sync, only end-to-end encrypted rule configuration is uploaded; capture traffic is never uploaded.
  • Regular Reviews: We review and update security measures as privacy requirements and technology evolve.

Legal Basis for Data Processing

When you create an account, we process your email address based on:

  • Contractual Necessity: Processing your email is necessary to provide account services and sync subscription status across platforms and devices.
  • Consent: By registering voluntarily, you consent to processing your email for account identification and subscription sync. You may withdraw consent by requesting account deletion.

Your Data Protection Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate or incomplete data
  • Erase data when no longer necessary or when you withdraw consent
  • Restrict processing in certain cases
  • Data portability in a structured, machine-readable format
  • Object to processing in certain situations

Contact [email protected] to exercise these rights. We will respond in accordance with applicable data protection laws.

Data Retention

  • Account Information (Email): Retained while your account is active; deleted within a reasonable period after account deletion.
  • Subscription Information: Retained until subscription expires or account is deleted.
  • Captured Network Data: Reminder—all capture data stays on your device only and is never stored on or transmitted to our servers. You control retention and deletion on your device.
  • Cloud Sync Data: If you use Cloud Sync, encrypted backups remain on our servers until you delete cloud data or delete your account (per product flow). We cannot access configuration plaintext.

Contact Us

Questions or suggestions about this Privacy Policy:

Policy Updates

We may update this Privacy Policy from time to time. Changes take effect when posted on this page. Please check back periodically.

Last updated: August 11, 2026