The short version: licensed providers, not first-party mass scraping. The full version is on /security — this page is the plain-language summary.
Sources
Public sources.
Waterfall lookups execute against licensed third-party data providers. Every waterfall response names the provider that answered in its providerfield — there's no hidden middle layer.
Retention
What we store.
Lookup inputs
Names, domains, URLs, emails you submit — processed to execute the call, retained in request logs for billing and debugging, then purged.
Results
Returned to you; web-scraping endpoints cache results server-side for performance, paid-provider lookups are fetched live.
Logs
Structured, correlation-ID'd, with an automated zero-plaintext-PII policy.
Full retention windows and the compliance table live at /security.
Subprocessors
Subprocessors.
Infrastructure: AWS (API, EU region), Cloudflare (MCP edge), Supabase (auth/audit), Stripe (payments), Sentry (errors, PII-scrubbed). The full subprocessor list is maintained and available on request — privacy@richapi.ai.
Want your own data removed from our pipeline? See /opt-out.
Need the full compliance table?
The full access, isolation, and compliance picture lives on the security page.