Privacy policy
Last updated: 26 August 2026
validkit is a validation API. People send us other people's phone numbers, email addresses and IP addresses, so the most important thing this page can tell you is what we do not keep. This policy describes the service as it is actually built, not as we would like it to sound.
What we do not store
We do not store the values you submit for validation. A phone number, email address or IP address you send to the API is held in memory for the length of the request, used to produce the response, and then discarded. It is never written to our database.
What we record against a validation request is the type of validation (phone, email or IP), the number of credits it used, whether it succeeded, how long it took, and when it happened — so we can meter your account and show you your own usage. None of those fields contains the value you submitted.
What we do store
- Your account: the email address you sign up with, a hash of your password (never the password itself), your plan, and the date you created the account.
- Your API keys: a SHA-256 hash of each key plus its first few characters for display. We cannot recover a key you have lost — only issue a new one.
- Your credit balance and its reset date.
- Usage records as described above: type, credits, status, response time, timestamp.
- Billing identifiers from Stripe. Card details are handled entirely by Stripe and never reach our servers.
Bulk uploads
A CSV you upload in the dashboard is parsed in your own browser and sent to the same validation API in batches. The file is not stored on our servers, and the values inside it are treated exactly like any other validation input — processed in memory, then discarded.
Analytics and session recording
We currently run no analytics, no advertising trackers and no session recording on this site. There are no third-party scripts on any page. If that changes, this section will state exactly what is captured, how it is masked, how long it is kept, and how to opt out — before the change ships, not after.
Cookies
One cookie, for your login session. It exists so that you stay signed in. There are no advertising or cross-site tracking cookies.
We send transactional email only — account confirmation and notices about your own credit balance. We do not sell, rent or share your email address, and we do not send marketing to addresses submitted for validation. An address you validate through the API is not a contact of ours and never enters any list.
Sub-processors
- Cloudflare — hosting, edge delivery, and the database.
- Stripe — payments and billing. Card data never touches our infrastructure.
Validation itself requires some lookups against outside systems: email validation resolves live DNS MX records for the domain you submit, and IP validation is answered against reputation and geolocation data. We do not sell or share submitted values, and none of these lookups results in a submitted value being stored by us. If you need a current, itemised list of every party involved in answering a particular validation type, ask us and we will tell you.
Retention and deletion
Account data is kept for as long as your account exists. Ask us to delete your account and we will remove your account record, API keys, wallet and usage history. Because validated values were never stored, there is nothing of your customers' data for us to delete.
Your responsibilities
The data you send us is usually about other people. You are the controller of it and we process it on your instructions. You are responsible for having a lawful basis to validate it. See the terms of service.
Contact
Questions about this policy, or a deletion request: reply to any email you have received from us.