OpenAPI Credit does not collect, store, or transmit any personal data to Arpacore B.V. The only party it sends your credentials to is OpenAPI, the service whose balance it shows, and it does so because you asked it to.
This privacy policy explains how OpenAPI Credit (the "App") handles information. In short: the App runs on your Mac, talks to exactly two addresses on the internet — the OpenAPI service, to read your balance, and our release server, to check for updates — and sends nothing about you or your usage to us or to anyone else.
Arpacore B.V. — Coolsingel 65, 3012 AC, Rotterdam, The Netherlands
Contact email: privacy@arpacore.com
OpenAPI Credit places an icon in the macOS menu bar and shows next to it the remaining credit of your account with OpenAPI (openapi.it), a third-party API service that you subscribe to independently of us. At the interval you choose, and whenever you ask for a refresh, the App sends one HTTPS request to https://oauth.openapi.it/credit, authenticated with the email address and API key you entered in its settings, and displays the figure that comes back. It performs no other function.
The App does not read your documents, does not observe your screen or your keyboard, and asks for no access to your files, camera, microphone, contacts, calendar, photos, location, or accessibility features. It installs no daemon, no privileged helper and no kernel extension, and never asks for an administrator password.
To read your balance, the App needs the email address and API key of your OpenAPI account. You type them into the App's settings window; they are saved on your Mac, in a plain JSON file at ~/Library/Application Support/OpenAPI Credit/config.json, together with the refresh interval and the currency symbol you chose. The file is protected by the ordinary permissions of your user account but is not encrypted. It is never transmitted to Arpacore B.V.
With every reading, the App sends those credentials to OpenAPI over HTTPS, using HTTP Basic authentication, exactly as the OpenAPI documentation describes. That request is received and processed by the operator of openapi.it under its own privacy policy and terms, which we encourage you to read. We have no access to those requests, to their content, or to your OpenAPI account.
A few seconds after launch, and whenever you choose "Controlla aggiornamenti…" from the menu, the App downloads a small text file (the update manifest) from our release server, an Amazon S3 bucket operated by Arpacore B.V. in Frankfurt, Germany (AWS region eu-central-1). The request carries no identifier, no account information and no usage data; it contains only what any HTTPS request contains, namely the IP address your Mac connects from and the App's user agent string. Amazon Web Services may record that information in standard server logs for the purpose of delivering the file and maintaining the security of the service; we do not use those logs to identify or profile users. If you choose to download an update, the disk image is fetched from the same server in the same way and verified against the SHA-256 checksum in the manifest before it is shown to you.
The App has no user accounts of its own, no sign-up, no login, and no user profiles. We do not ask you for any personal information such as name, email address, or payment details; the email address you enter is for your OpenAPI account and is used only to authenticate with OpenAPI.
The App contains no analytics, no advertising SDKs, no crash reporting that transmits data off-device, no cookies, and no tracking technologies of any kind. We do not know who uses the App, when, or how.
Apart from the static release files described above, Arpacore B.V. operates no server, database, or cloud service in connection with this App. The App does not use iCloud or any other Apple cloud service to store or sync data. The only other address it can open is arpacore.com, and only when you click that link in the About window yourself, at which point your browser — not the App — makes the request.
OpenAPI Credit is distributed as a disk image (.dmg) downloaded directly from arpastore.com, not through the Apple App Store. It is signed with a Developer ID certificate issued to Arpacore B.V. and notarised by Apple. The download is served by our hosting provider, which processes standard web server request data (such as your IP address and browser user agent) for the purpose of delivering the file and maintaining the security of the service. This is the ordinary operation of any website and is described in the Arpastore website privacy policy; the App itself is not involved.
When you open a downloaded application for the first time, macOS checks its notarisation with Apple as part of its own security process. That check is performed by your operating system under Apple's privacy policy, and its results are not shared with us.
Because no data about you is stored on our servers, there is nothing for us to delete. To remove all App-related data from your Mac, quit the App, move it from the Applications folder to the Trash, and delete the folder ~/Library/Application Support/OpenAPI Credit, which holds your credentials and settings. Revoking or rotating the API key itself is done in your OpenAPI account.
The App is not directed to children and does not knowingly collect information from anyone, including children.
Because Arpacore B.V. does not collect or process any personal data through the App, rights such as access, rectification, erasure, restriction, portability, and objection do not practically apply to data held by us — we hold none. For the data you send to OpenAPI, those rights are exercised with the operator of openapi.it. If you have any questions or believe this is not the case, you may contact us at privacy@arpacore.com, and you always have the right to lodge a complaint with your national data protection authority.
If the App's behavior changes in a way that affects this policy, we will update this page. You are encouraged to review it periodically. Material changes will be reflected in the "last updated" date below.
Arpacore B.V. — privacy@arpacore.com
Last updated: September 7, 2026