// legal
Last updated: May 2026
Form4API (“we”, “us”) operates the API and website at form4api.com. We provide programmatic access to publicly available SEC Form 4 insider trading filings. Contact: contact form
Account data
When you sign up, Clerk (our authentication provider) collects your email address and manages your session. We store your Clerk user ID linked to your API key and plan.
API usage data
We log every API request: timestamp, endpoint, HTTP status code, and your API key identifier. We use this to enforce rate limits, display your usage stats, and debug issues. Individual request logs are retained for 90 days.
Payment data
Payments are processed by Stripe. We do not store card numbers or bank details. We receive confirmation of your subscription plan and billing status from Stripe.
Technical data
Standard server logs may include IP addresses and user-agent strings. Vercel Analytics collects anonymised, cookieless page-view data. We also use Google Analytics 4 (see Section 4 and the Cookies section below), which sets cookies and collects data such as your approximate IP address, browser type, device, and pages visited. Google Analytics data is only collected after you give explicit consent via our cookie banner.
We do not sell your data, use it for advertising, or share it with third parties except as described in Section 4.
| Processor | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication | Email, session tokens |
| Stripe | Payment processing | Email, billing info |
| Vercel | Hosting & analytics | Anonymised page views |
| Google LLC | Analytics (GA4) | IP address, device, browsing behaviour — consent required |
| Hetzner | API server hosting | API request logs |
| Sentry | Error monitoring | Stack traces (no PII) |
We use one category of cookies:
| Cookie | Provider | Purpose | Expiry |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes users | 2 years |
| _ga_* | Google Analytics | Session state | 2 years |
| cookie_consent | Form4API | Stores your consent choice (localStorage) | Until cleared |
Google Analytics cookies are only set after you accept via our cookie banner. You can withdraw consent at any time by clearing your browser's local storage or cookies, which will cause the banner to reappear on your next visit.
Google LLC processes analytics data in the United States under Standard Contractual Clauses. Google's Privacy Policy.
You can request access to, correction of, or deletion of your personal data at any time via our contact form. We will respond within 30 days. You can delete your account at any time from the Clerk account settings.
All data is transmitted over HTTPS. API keys are stored hashed. We do not store plaintext credentials. If you believe your API key has been compromised, contact us immediately and we will rotate it.
We may update this policy. Material changes will be communicated by email to registered users. Continued use of the service after changes constitutes acceptance.