Privacy
Privacy, plainly.
What cors.dev processes to run the website, proxy and optional accounts.
This website
No account is needed to browse this site. We count first-party product events, such as a successful first request or the start of signup or checkout, in Cloudflare Analytics Engine. Application analytics store only an event name and a fixed source label, not URLs, email addresses, keys or IP addresses. We do not use tracking cookies or track you across sites.
We measure website visits with Simple Analytics, a cookieless analytics service that collects no personal data and does not track visitors across sites.
Cloudflare hosts this website and proxy. Its infrastructure processes network information, including IP addresses, to deliver requests and apply security controls.
Optional accounts
Firebase Authentication handles account sign-in with Google. We use your email address and Firebase user ID to identify your account and connect it to your saved Connections and keyed usage.
Firebase stores authentication state locally in your browser so you stay signed in between visits. Signing out clears that local sign-in state. Your account credentials and Firebase tokens are not forwarded to upstream APIs.
Payments
When you purchase a plan, Bitgate's payment platform and Stripe process the billing information needed for checkout, payment and subscription management. We retain payment references, subscription status and billing periods to provide your request allowance.
Payment details are separate from product analytics. Full card details are handled by the payment processor, not stored in cors.dev's application database.
API requests
When you use the proxy, we process the destination URL, including its query string, to request the data you chose. That API provider receives the destination and supported forwarded headers under its own policies.
We do not forward browser cookies or your cors.dev Connection key. Managed requests can explicitly forward Authorization and custom API headers, along with the request body, to the destination you choose. Auto Fetch can stream verified responses; other proxy responses are buffered within the service limits. If you opt in to GET caching, eligible public responses can be held in Cloudflare cache for the requested lifetime of 1 to 300 seconds. Credential-bearing requests and private responses are excluded.
Service operations
We retain usage counts and redacted request diagnostics to operate the service and enforce rate and concurrency limits. Account activity covers new keyed requests, not past anonymous traffic. Raw destination URLs, query strings, keys, authentication tokens and response bodies are not recorded in application logs.
Network security data processed by Cloudflare is separate from these application records.
Domain opt-outs
When you register a domain opt-out, we store the domain, abuse contact email and DNS verification records to confirm ownership and maintain the block. The TXT record you publish is public; your contact email is not displayed publicly or shared with affected customers.
We may notify customers whose Connections are affected. Notices identify the blocked hosts, not the site owner's contact details.
When you email us
We receive your email address and the information you send, and keep the correspondence to respond and support your integration. Avoid sending API secrets or sensitive response data.
For privacy questions or a request about your information, email kevin@bitgate.com.