Legal
Privacy Policy
This Privacy Policy explains how FatBaby API ("FatBaby", "we", "us") collects, uses, and protects information when you use https://thefatbaby.com and related API services.
Last updated: September 7, 2026
1. Who we are
FatBaby operates a developer API platform that provides utility endpoints (such as image and JSON tools), account dashboards, API keys, and credit-based billing. For privacy questions, contact us at privacy@thefatbaby.com.
2. Information we collect
- Account data: email address, name (optional), password hash, account status, and role.
- Authentication data: session cookies and related security metadata (IP address, user agent).
- API usage data: endpoint called, status code, credits used, latency, request/response summaries stored in execution logs, and API key identifiers.
- Uploaded content: files you send to API endpoints (for example images) are processed to fulfill your request. We do not use customer uploads to train public AI models.
- Billing data: plan, wallet balance, ledger entries, and checkout/payment metadata provided by our payment processor (Creem). We do not store full card numbers on our servers.
- Technical logs: request IDs, IP addresses, and error codes needed to operate and secure the service.
3. How we use information
- Create and manage your account, API keys, and sessions
- Process API requests and deduct credits
- Show dashboards, usage logs, and billing status
- Prevent abuse, fraud, and unauthorized access
- Provide support and communicate service notices
- Comply with legal obligations
4. Cookies and sessions
We use an httpOnly session cookie (fb_sid) to keep you signed in to the dashboard. This cookie is required for authenticated dashboard use and is not used for third-party advertising.
5. Execution logs and retention
API execution logs (including status, credits consumed, and response summaries) are retained for 4 days and then deleted automatically. Binary image outputs are not stored in logs; only metadata (such as content type and size) is kept. Uploaded files are processed in memory for the request and are not retained as a long-term content archive unless required for security investigation.
6. Sharing of information
We may share information with:
- Infrastructure providers that host our servers, databases, and networking
- Payment processors that handle subscriptions and checkouts
- Legal authorities when required by law or to protect rights and safety
We do not sell your personal information.
7. Security
We use industry-standard safeguards including password hashing (scrypt), hashed API keys, httpOnly session cookies, HTTPS, rate limiting, and access controls. No method of transmission or storage is 100% secure; please protect your API keys and rotate them if exposed.
8. Your choices
- Access or update account details from your dashboard where available
- Revoke API keys at any time
- Request account deletion or a copy of your account data by emailing privacy@thefatbaby.com
9. International transfers
Your information may be processed in countries where we or our providers operate. We take reasonable steps to ensure appropriate protection for such transfers.
10. Children
FatBaby API is intended for adults and business users. We do not knowingly collect personal information from children under 16.
11. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of the service after changes means you accept the updated policy.
12. Contact
Questions about this policy: privacy@thefatbaby.com
Website: https://thefatbaby.com
