← BuyerAware API

Privacy Policy

Effective August 21, 2026 · BuyerAware, Ormond Beach, Florida, USA

This policy covers the BuyerAware API and MCP server at api.buyerawareapp.com (the "Service"), operated by BuyerAware ("we"). It describes what we collect when developers, AI agents, and applications use the Service, how we use it, and your choices.

What we collect

Account data. When an API key is created we store the email address supplied, an optional name, the key itself, the plan, a credit balance, and usage counters (calls made, timestamps). Email is used to identify your key, deliver purchased credits, and respond to support requests.

Request data. To produce a verdict we process the vehicle listing you submit: listing URL or text, VIN, vehicle details, asking price, seller claims, and any buyer context or location you include. We store each request and its result ("job") so it can be retrieved by your key, and we keep an internal usage log (timestamp, key identifier, event type, token usage, and error messages) for billing, abuse prevention, and reliability.

Payment data. Credit purchases are processed by Stripe. We never see or store card numbers. Stripe sends us the purchaser email, the amount paid, and a Stripe customer identifier so we can credit the correct key.

We do not collect the contents of your conversations with an AI assistant, your assistant's memory or history, or any files on your device. Only the arguments passed to our tools reach us.

How we use data

To operate the Service (run analyses, return results, meter credits), to prevent abuse and fraud, to debug failures, to communicate about your account, and to improve the accuracy of the analysis. We do not sell personal data and we do not use your listings for advertising.

Third parties

Verdict generation uses the Anthropic API (Claude) with web search and web fetch; the listing content you submit is sent to Anthropic to be analyzed and is subject to Anthropic's commercial terms, under which API inputs are not used to train models. Hosting and data storage are provided by Netlify (United States). Payments are provided by Stripe. Web searches run during analysis may reach public sites (NHTSA, KBB, forums, marketplaces) with the vehicle details you supplied.

Retention

Job records (inputs and results) are retained for 90 days and then deleted. Usage logs are retained for 13 months for billing and accounting. Account records persist while a key exists; write to us to delete a key and its associated records at any time.

Security

All traffic is HTTPS. API keys are bearer secrets: keep them private, and contact us to rotate or revoke one. Internal worker endpoints are protected by a separate shared secret, and admin functions require a separate token.

Your choices and rights

You can request a copy of the data associated with your key, correct it, or have the key and its records deleted by emailing us. Residents of jurisdictions with privacy laws (for example GDPR or CCPA) may exercise their rights through the same address. We do not knowingly collect data from children under 16.

Nature of the output

Verdicts are desk analyses generated from listing data and published information. They are not a physical inspection, not a guarantee of vehicle condition, and not financial or legal advice. Always obtain an independent pre-purchase inspection.

Changes and contact

We will post changes on this page with a new effective date. Questions, deletion requests, and security reports: hello@buyerawareapp.com.

See also the Terms of Service.