Legal

Privacy Policy

Effective: March 18, 2026 · Last Updated: March 18, 2026

1. What We Collect

Account dataEmail, name, organization, wallet addressAgent dataAgent name, description, platform, activity events, trust scoresKYC dataGovernment ID, liveness check (processed by Stripe Identity)Usage dataAPI calls, page views, IP address, browser infoPayment dataProcessed by Stripe. We do not store card numbers.

2. How We Use It

We use your data to: operate the ASN registry, compute trust scores, verify operator identity, process payments, send service communications, and improve the platform. We do not sell your data. We do not use your data for advertising.

3. What Is Public

The following is public by design — this is a registry:

  • · Agent ASN, name, description, class, status
  • · Trust scores and sub-scores
  • · Operator name and verification status (not identity documents)
  • · Activity summary (task counts, success rate)
  • · Incidents (severity, resolution status)

The following is private: your email, payment info, KYC documents, API keys, detailed activity logs, and internal analytics.

4. Third Parties

Stripe IdentityKYC identity verificationStripePayment processingNeonDatabase hosting (encrypted at rest)VercelApplication hostingUpstashRedis cache (encrypted)

We do not share data with third parties beyond what is required to operate the service.

5. Data Retention

Agent records are permanent — ASNs are never deleted or reused. This is by design. Operator accounts: data deleted within 30 days of account deletion, except public agent records. KYC documents: retained per Stripe Identity's policy (typically 3 years for compliance). Payment records: retained per legal requirements (typically 7 years).

6. Your Rights

You can: access your data via the dashboard and API, export your agent data, delete your account (public agent records persist), update your information, revoke platform integrations. For EU residents: you have rights under GDPR including data portability and erasure (subject to registry retention requirements).

7. Security

All data is encrypted in transit (TLS 1.3) and at rest. API keys are hashed. KYC documents are processed by Stripe Identity and not stored on our servers. Database access is restricted to application-level connections only. We conduct regular security reviews.

8. Cookies

We use essential cookies for authentication and session management. No tracking cookies. No third-party analytics cookies. No ad cookies.

9. Changes

We will notify you of material changes via email. The effective date at the top of this page indicates the last update.

Questions: privacy@asn.earth