Privacy policy
Effective 2026-10-06.
recallsapi.com is operated by PrimeZen LLC, Texas ("we"). This policy explains what we store when you use the API, the MCP server, catalog monitoring and this website, and what we do with it. Contact: hello@recallsapi.com.
What we store
- Account: your email address, a normalized form of it (lowercase, without a +tag) used to keep one free account per inbox, plan, account status and creation dates.
- API keys: only a SHA-256 hash of each key, plus its first 12 characters so a key can be identified. We cannot read your full key back.
- Catalogs: catalog names, alert email addresses, webhook URLs and webhook signing secrets, and the items you upload (SKU, name, brand, UPC, model, NDC, lot, VIN, marketplace), with their recall matches and whether each was alerted or dismissed.
- Alert log: for each alert, the channel (email or webhook), the number of matches, whether it was sent and any error.
- Usage: a count of API calls per account per day, used for quotas and shown to you through
/v1/account. - Signup throttling: to limit how many keys one network or email domain can create per day, salted SHA-256 hashes of the requesting IP address and its network ranges, and of the email domain for addresses outside the large shared email providers, each with the date and a count. We do not store the IP address itself for this.
- Billing: for paid plans, the Stripe customer and subscription identifiers, and the identifier of a checkout that is still open. Stripe processes payment details; card numbers and bank details are never sent to or stored by recallsapi.com.
Who else processes data
- Cloudflare hosts this website, the API, the MCP server and the database, and delivers the emails we send (API keys and alerts).
- Stripe processes payments for paid plans under its own privacy policy.
- NHTSA: when you look up a VIN, the VIN is sent to NHTSA's vPIC service to decode it, and the decoded make, model and year are sent to NHTSA's recall lookup.
- Your webhook endpoint receives the match data you configure it to receive.
How we use it
To provide the service (sending your API key by email, matching, alerts, quotas and billing), to secure it and prevent abuse, to answer support requests, and to tell you about changes that affect your account. We do not sell personal data or share it for advertising.
This website
The recallsapi.com website sets no cookies and loads no analytics, advertising or third-party scripts. Our hosting provider processes standard request data (such as IP address and user agent) to deliver pages and protect the site. The dashboard keeps the API key you enter in your browser's local storage on your device, so you stay signed in; it is sent only to the API, and signing out removes it.
Retention and deletion
- Account, catalog and usage data are kept while your account exists.
- Deleting a catalog through the API (
DELETE /v1/catalogs/{id}) removes its items and matches at once. - To delete your account and its data, or to get a copy of it, email hello@recallsapi.com from the account's email address. We may keep billing records where the law requires.
Security
All traffic uses HTTPS. API keys are stored only as hashes. Webhook payloads are signed so you can check they came from us.
Children
The service is for businesses and developers and is not directed at children.
Changes
We will post changes on this page and, for material changes, email account holders before they take effect.