Privacy policy
Last updated August 27, 2026
What we collect
When you sign in with Google or GitHub, we receive the account identifier and basic profile information that provider shares, such as your email address. We also process API request metadata, quota usage, security events, and normal website logs.
How we use it
We use this information to create and secure your account, issue and verify API keys, measure quota, operate the service, prevent abuse, and respond to support requests. Narwhal stores a one-way verification value for your API key, not the complete key.
Service providers
We use infrastructure and identity providers to run Narwhal. Google or GitHub handles the sign-in step you choose. Supabase handles account authentication. Hosting and monitoring providers process the technical data needed to deliver and protect the service.
Your choices
You can stop using the service at any time. To request access to, correction of, or deletion of account information, email hello@narwhalapi.com. Some records may be kept when needed for security, legal obligations, or resolving abuse.