Skip to content

Privacy Policy

Nick edited this page Nov 27, 2025 · 1 revision

Privacy Policy

Last Updated: 2025-11-27


πŸ” Our Privacy Commitment

Masker API is designed with privacy as a core principle. We believe your data should never be stored, logged, or retained.


What We Process

  • Text strings and JSON payloads sent via HTTP POST requests
  • Only string values in JSON are scanned for PII
  • Processing happens in-memory only

What We Do NOT Store

  • ❌ No database - All processing is in-memory, stateless
  • ❌ No file storage - Nothing is written to disk
  • ❌ No content logging - Request/response bodies are never logged
  • ❌ No data retention - Your data is processed and immediately discarded

What We Log (Service Metadata Only)

We log only service metadata for operational purposes:

2025-11-27 10:30:45 - masker - INFO - request: method=POST path=/v1/redact status=200 content_length=128 duration_ms=45.20 request_id=abc123

Logged:

  • HTTP method (GET, POST, etc.)
  • Request path
  • HTTP status code
  • Payload size (bytes)
  • Processing time (milliseconds)
  • Request ID (for tracking)

Never Logged:

  • Request body content
  • Response body content
  • PII content
  • User data
  • Email addresses
  • Phone numbers
  • Names
  • Any personal information

Data Processing

  1. Request received - Data is read into memory
  2. PII detection - Text/JSON is scanned for PII
  3. Redaction applied - PII is replaced with masks/placeholders
  4. Response sent - Redacted data is returned
  5. Memory cleared - All data is immediately discarded

No data persists after the request is complete.


Security Measures

  • βœ… HTTPS only - All communication is encrypted
  • βœ… Stateless architecture - No session data stored
  • βœ… Non-root execution - Docker container runs as non-root user
  • βœ… No external storage - No database or file system access
  • βœ… Request ID tracking - For debugging without exposing content

GDPR Compliance

Masker API is GDPR compliant because:

  • No personal data is stored
  • No personal data is logged
  • No data retention
  • No third-party data sharing
  • Complete data deletion after processing

Your Rights

Since we don't store any data, there's nothing to request, delete, or export. Your data is processed and immediately discarded.


Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page.


Contact

For privacy-related questions, please contact us through GitHub Issues.


Privacy First. No Data Storage. No Logging. Ever.

Clone this wiki locally