Legal

Privacy Policy

Last updated: 25 June 2026

1. Who we are

Attestify OS (“Attestify”, “we”, “our”, “us”) operates the website at www.attestifyos.com and provides developer infrastructure for AI agent workflows, including x402-based payment routing, governance controls, agent memory management, and execution receipts on the Base network. Our primary contact email is hello@attestifyos.com.

For the purposes of the UK GDPR and the Data Protection Act 2018, Attestify OS is the data controller of your personal data.

2. What data we collect

We collect and process the following categories of personal data:

  • Account data: name, email address, company name, job title, account role (operator / tenant / founder)
  • Billing data: Stripe customer ID, subscription plan, billing address, VAT number, invoice history. Card numbers are processed and stored exclusively by Stripe — we do not store payment card data.
  • Execution and routing data: task inputs, agent selections, routing decisions, routing intent scores, run/loop IDs, timestamps, budget enforcement outcomes — used to generate cryptographic receipts and audit trails
  • Agent memory data: structured memory entries created by or for AI agents through the /api/memory route. Memory entries may include agent context, session state, preferences, and prior execution summaries. Memory data is stored in Redis and is scoped to your tenant.
  • Payment data: wallet addresses, USDC amounts, x402 payment receipts, Base network transaction hashes (see Section 3 on on-chain data)
  • Email notification data: email addresses collected via notification flows including spend-limit alerts (/api/notify-email) and plan upgrade prompts (/api/upgrade-email). Emails are processed by Resend (see Section 6).
  • Webhook configuration data: endpoint URLs and signing secrets you provide for webhook delivery
  • Usage data: API call counts, latency, error rates, plan tier, rate-limit consumption
  • Technical data: IP addresses, browser/runtime user-agent, request headers, session duration
  • Communications: emails, support messages, and any other correspondence you send us

3. On-chain data

Attestify OS settles peer-to-peer payments on the Base network (a public blockchain). On-chain data — including wallet addresses and transaction amounts — is permanently public and cannot be deleted by us or anyone else. By using the Service with x402 payment settlement, you acknowledge that settlement data will be recorded publicly on the Base blockchain (EIP-155 chain ID 8453). Cryptographic receipts generated by the Service reference on-chain transaction hashes and are stored by us for audit purposes.

4. How we use your data

  • To provide, operate, and maintain the Attestify OS platform and APIs
  • To generate and store execution receipts, cryptographic attestations, and audit trails
  • To process x402/USDC payments and Stripe subscription billing
  • To enforce budget caps, governance policies, and routing rules
  • To store and retrieve agent memory entries scoped to your tenant
  • To send transactional emails — including API key delivery, spend-limit alerts, and plan upgrade notifications — via Resend
  • To deliver webhook events to your configured endpoint
  • To monitor platform usage, enforce fair-use limits, and detect abuse
  • To respond to support requests and communications
  • To comply with legal obligations (tax, anti-money laundering, fraud prevention)
  • To improve the platform based on aggregated, anonymised usage analytics

We do not use your data to train third-party AI models, and we do not sell your personal data to third parties.

5. Legal basis for processing

  • Contract: processing necessary to deliver the service you have subscribed to, including payment processing, API access, memory storage, and webhook delivery
  • Legitimate interests: security monitoring, fraud prevention, abuse detection, platform improvement
  • Legal obligation: tax records, regulatory compliance, AML obligations
  • Consent: marketing emails (you may withdraw consent at any time)

6. Sub-processors and data sharing

We share data with the following third-party sub-processors. Each has been assessed for appropriate data protection safeguards:

  • Stripe (stripe.com) — subscription billing, payment processing, customer management, and invoice delivery. Stripe processes your name, email, billing address, and payment method. Acts as a data processor under a Data Processing Agreement. Stripe Privacy Policy | Stripe DPA
  • Vercel (vercel.com) — hosting, serverless compute, and global CDN. All application traffic and logs pass through Vercel infrastructure. Vercel Privacy Policy
  • Resend (resend.com) — transactional email delivery, including API key emails, spend-limit notifications (notify-email), and plan upgrade prompts (upgrade-email). Resend processes recipient email addresses and email content. Resend Privacy Policy
  • Upstash / Redis — Redis-compatible data store used for API key management, agent memory (/api/memory), rate-limit counters, webhook secrets, and session state. Data is scoped by tenant. Upstash Privacy Policy
  • xAI (Grok) (x.ai) — large language model inference. Agent task inputs and routing context are sent to xAI's Grok API for LLM inference. Review xAI's data usage policies before submitting sensitive data through agent workflows. xAI Privacy Policy
  • Base network — public blockchain (Coinbase); settlement data is broadcast and permanently recorded on-chain as described in Section 3

We do not sell your personal data to third parties. We do not share your data with advertisers.

7. Agent memory data

Agent memory entries created via the /api/memory route are a privacy-sensitive data type. Memory entries may contain agent context, session history, user preferences, task summaries, and execution state. This data:

  • Is stored in Redis (Upstash), scoped to your tenant key
  • Is accessible only to requests authenticated with your API key or operator key
  • Is retained for the duration of your subscription and deleted 90 days after account closure, unless you request earlier deletion
  • May be exported on request under your data portability rights (see Section 9)

You are responsible for ensuring that memory entries you create do not contain unlawfully obtained personal data about third parties.

8. Data retention

We retain personal data as follows:

  • Account and billing data: 7 years after account closure to comply with UK tax and financial record-keeping obligations
  • API call logs and execution receipts: 90 days by default; paid plans may configure longer retention periods
  • Agent memory data: for the duration of your subscription, plus 90 days after closure
  • Email notification data: retained as part of transactional email logs for 90 days; Resend may retain delivery metadata per their own policy
  • On-chain data: permanently recorded on the Base blockchain; cannot be deleted by us or anyone else

9. Your rights under UK GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you, including memory entries
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data (note: on-chain data cannot be deleted; memory data in Redis will be deleted on request)
  • Restriction — ask us to limit how we process your data
  • Portability — receive your account, execution, and memory data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — at any time, for processing based on consent (e.g. marketing emails)

To exercise any of these rights, email hello@attestifyos.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies

We use essential cookies to maintain your session and authentication state. We use analytics cookies (anonymised) to understand how the platform is used. You can disable non-essential cookies in your browser settings at any time. We do not use third-party advertising cookies or tracking pixels.

11. Security

We implement industry-standard security measures including TLS encryption in transit, encrypted storage at rest, API key hashing, HMAC-SHA256 webhook signing, and role-based access controls. Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it to hello@attestifyos.com.

12. International transfers

Our infrastructure providers (Vercel, Stripe, Resend, Upstash, xAI) may process data outside the UK and EEA. Where this occurs, it is subject to appropriate safeguards including Standard Contractual Clauses (SCCs) as recognised under UK GDPR. You can request details of the safeguards in place by emailing hello@attestifyos.com.

13. Children's privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, contact us immediately.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. The “Last updated” date at the top of this page will always reflect the most recent version.

15. Contact

For any privacy-related questions or to exercise your rights:
Email: hello@attestifyos.com
Website: www.attestifyos.com