Privacy Policy
Last updated: February 23, 2026
1. Information We Collect
We collect the minimum information necessary to provide the Service:
- Phone number — used for OTP authentication. Stored as a hashed value.
- Wallet address — used for SIWE authentication and on-chain deposit verification.
- Agent metadata — namespace names, agent configurations, domain settings.
- Billing data — credit balances, transaction history, and payment records.
- API usage logs — API request metadata for security, debugging, and abuse prevention.
2. How We Use Your Information
- Authenticate your identity and secure your account
- Provision and manage infrastructure resources
- Process payments and maintain billing records
- Detect and prevent abuse or fraudulent activity
- Debug issues and improve the Service
- Communicate service updates or critical notices
We do not sell your personal information. We do not use your data for advertising or marketing purposes.
3. Third-Party Services
We use the following third-party services to operate the platform:
- Twilio — SMS delivery for OTP verification. Your phone number is shared with Twilio for this purpose.
- Payment processor — Credit card payment processing. Payment details are handled entirely by our payment processor and are not stored on our servers.
- Cloudflare — DNS, CDN, and SSL certificate provisioning for agent domains.
- Vultr — Infrastructure hosting (VMs, K3s). Agent VMs and platform services run on Vultr infrastructure in the Seoul (Korea) region.
Each third-party service has its own privacy policy. We encourage you to review them.
4. Blockchain Data
If you authenticate via wallet or make on-chain deposits, your wallet address and transaction data are publicly visible on the blockchain. This is inherent to blockchain technology and outside of our control. We store wallet addresses and transaction hashes to verify deposits and maintain billing records.
5. Data Storage & Security
Your data is stored in a PostgreSQL database. We implement industry-standard security measures including encrypted connections (TLS), network isolation, and role-based access control. API keys are stored as hashed values — the original key is shown only once at creation.
6. Data Retention
- Account data is retained as long as your account exists.
- Agent data (VM snapshots) is deleted after a grace period following service suspension due to zero balance. Agent configurations are retained.
- Billing records are retained for accounting and legal compliance purposes.
- API logs are retained for up to 90 days for security and debugging purposes.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data (subject to legal retention requirements)
- Export your agent configurations
To exercise these rights, contact us at [email protected].
8. Cookies & Tracking
We use essential cookies for authentication session management. We do not use third-party analytics, advertising trackers, or non-essential cookies. No cookie consent banner is required as we only use strictly necessary cookies.
9. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance.
11. Contact
For privacy-related inquiries, contact us at [email protected].