← Back to Dino

Legal

Privacy Policy

Last updated: August 14, 2026

Dino is the deterministic verification layer for APIs, operated by AltraBlock Inc, Wilmington, Delaware, United States (“Dino,” “we,” “us”). This policy explains, in plain English, what data we handle when you use Dino, how we use it, and the choices you have. It covers the CLI, the web console, and Dino Cloud.

The short version

  • Dino tests the APIs you point it at. It never reads, copies, or stores your production data.
  • We never sell your data, and we never use your API data, scan results, or AI conversations to train models.
  • Your scan results and API data belong to you. You can export them or delete them at any time.
  • Your data is stored in the region assigned to your workspace, encrypted in transit and at rest.

What we collect

  • Account and identity — your email, name, and organization membership, handled through our authentication provider.
  • Configuration — the APIs, environments, and auth profiles you set up, including the credentials they hold (stored encrypted).
  • Scan data — the scans you run and their results, findings, and replay artifacts.
  • Audit logs — security and administrative events in your workspace.
  • Billing — subscription and invoice records, handled by our billing sub-processor.
  • Operational analytics — tenant-anonymous product events that carry no tenant identifier, no credential, and no target data.

Dino sends test requests to the APIs you configure and validates the responses. The contents of your production API responses are not read, copied, or retained beyond what is needed to produce a finding.

How we use it

  • To run scans and deliver verdicts, documentation, and monitoring.
  • To operate, secure, and support the service.
  • To bill for paid plans.
  • To improve the product through tenant-anonymous analytics.

What we never do

  • We never sell your data — not to advertisers, partners, or anyone.
  • We never use your API data, scan results, or AI-assistant conversations to train AI models, and we configure our model providers so that content sent for inference is not used to train theirs.
  • We do not use cookies to serve third-party advertising.

How your credentials are protected

To test an authenticated API, Dino needs to call it as an authenticated client. The credentials you provide are encrypted at rest with AES-256-GCM using a key derived uniquely for each tenant, stored region-partitioned with the rest of your workspace data. Once stored, a credential is write-only: it cannot be read back through the product, only replaced or deleted. Plaintext credentials exist only briefly in memory on the runner during a scan. Credential values, tokens, cookies, and sensitive headers are redacted from logs, errors, and analytics.

AI processing

Dino uses large language models from Anthropic, OpenAI, and Cloudflare Workers AI to analyze APIs and power its AI features. We send a model only the content it needs — API structure, requests and responses, and findings context — and we redact secrets before any content reaches a model. Your content is not used to train these models. If you prefer, you can bring your own model-provider key, in which case AI requests run under your own account and terms.

Where your data lives

Dino is built on a region-partitioned architecture. A workspace is assigned a region when it is created, and your primary data — API definitions, encrypted credentials, scans, results, and runner records — is stored and processed in that region. We operate regions in the European Union, Eastern Europe, Western North America, Asia Pacific, and Oceania, plus a global default region. A small set of functions are global by design, including authentication, billing, and the routing lookup that maps an organization to its region.

Sub-processors

We engage a small number of trusted third parties to provide the service — for cloud infrastructure and storage, authentication, billing, AI inference, and product analytics. Each is bound by contract to protect your data and to process it only to provide the service, and we remain responsible to you for them. A current list is available on request at privacy@usedino.dev.

How long we keep it, and deletion

  • Account and identity — kept for the life of the account, then deleted within 30 days of account closure.
  • Configuration and scan data — kept for the life of the workspace or your subscription, and removed when the workspace is deleted.
  • Billing — kept as required for tax and accounting purposes.

Deleting a resource or workspace removes its data, including any encrypted credentials, after a confirmation step. Deleted data may persist briefly in encrypted, access-controlled backups until they cycle out. We may retain data where required by law, such as billing records or a legal hold.

Your rights and choices

  • Access and export — you can export your full workspace data at any time. Email support@usedino.dev if you need help.
  • Deletion — you can delete a resource or your entire workspace whenever you want.
  • Telemetry — console and CLI analytics are your choice: off, crash-only, or all.
  • Correction — contact us to correct your account information.

Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA, including access, portability, correction, and erasure. Where personal data is transferred across borders, we rely on the European Commission Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable. Regional residency is the primary way we help you minimize cross-border transfer in the first place.

Cookies

We use strictly necessary cookies for authentication, session management, and security; preference cookies to remember settings such as your theme; and tenant-anonymous analytics. We do not use advertising cookies. Where required by law, including in the EEA and the UK, non-essential cookies are not set until you consent.

Children

Dino is a tool for developers and organizations and is not directed to children. We do not knowingly collect personal data from anyone under 16.

Changes to this policy

If we make material changes, we will update this page and, for account holders, notify workspace administrators.

Contact

Privacy questions and data requests: privacy@usedino.dev. Security and vulnerability reports: security@usedino.dev. See also our Terms of Service.