Privacy Policy
Last updated: 4 October 2026
Information We Collect
When you use API Drama we collect:
- Account and billing information: API Key, label, plan, validity period, and remaining daily quota.
- Technical information: IP address, User-Agent, and the country a request originated from.
- Device information: device ID, brand, model, and OS version, when your application sends them.
- Usage history: endpoint, parameters, platform, request count, and response status codes.
- Abuse prevention data: the list of blocked IP addresses and devices, with the reason for each block.
We do not collect payment data such as card numbers, PINs, or e-wallet accounts, because payment is settled outside our systems.
How We Use It
Collected information is used to:
- Count your daily quota and enforce the limits of the plan you purchased.
- Apply per-endpoint rate limits and delays between requests.
- Detect and block abuse, scraping, and automated traffic that looks unusual.
- Remember your language and platform preferences so responses stay consistent.
- Answer your questions and complaints over Telegram.
Data Storage and Retention
- Account data and usage records are stored in MySQL, while cache entries, quota counters, blocklists, and sessions live in Redis.
- Daily quota counters are temporary and reset automatically at 00:00 UTC.
- Account data is permanently deleted if payment is more than 3 days overdue after expiry, or if the API Key is terminated for breaching these terms.
- Drama content is cached to speed up repeated requests and is refreshed periodically.
Sharing
We do not sell or share your personal data with third parties, except:
- Source platforms and CDNs, because some requests have to be forwarded to them. They receive an IP address and User-Agent, never your account identity or API Key.
- Payment service providers, when you choose to complete a purchase outside our systems.
- Where required by law or a valid legal process.
Security
We take reasonable measures to protect your data:
- All requests must travel over HTTPS.
- Authentication uses HMAC-SHA256 with a 5-minute validity window, so a recorded request cannot be replayed.
- IP blocklists are used to filter harmful traffic.
- Access to sensitive data is limited to what operations require.
No system is perfectly secure. We still apply reasonable measures to reduce the risk of a data breach.
Cookies
This site uses a functional session cookie so you stay signed in to the documentation area. The cookies we set are strictly necessary for the service to operate normally.
We do not use tracking cookies, advertising cookies, or third-party cookies to profile visitors.
Your Rights
You have the right to:
- Request information about the personal data we hold about you.
- Request deletion of your personal data, subject to any mandatory retention periods.
- Refuse certain data collection by not using the Service.
- Stop using the Service, which also stops new data collection. Historical data remains until its retention period ends.
Changes to This Policy
This policy may change at any time. Updates are published on this page with a new revision date, and take effect from that date.
Contact
For questions, correction requests, or deletion requests, contact us on Telegram at @hplssmnct. Include your API Key label so we can act faster.
Your Data Is Not a Commodity
We run an aggregator, not a data marketplace. No third party buys user profiles from us, and nobody reconstructs who you are from your API Key.