Privacy Policy
Draft — not yet in effect. This policy takes effect only once the items in the Operator fill-in block are completed and the effective date is set. It is provided as-is and is not legal advice.
Effective date: not in effect until set (see Operator fill-in). Last updated: see Operator fill-in.
Overview
Sigildex ("Sigildex", "we", "us") operates a headless skill-discovery and verification API for AI agents. There are no user accounts, no logins, and no user profiles. We have designed the Service to collect as little personal data as possible. This policy explains what the Service receives when an agent calls it, why we process it, who processes it on our behalf, and how long we keep it. It is published by the entity named in the Operator fill-in block below.
Note on query content: the natural-language queries you send to /discover are logged. Do not place secrets, credentials, proprietary code, private repository URLs, personal data, or other sensitive information in query text — treat everything you send as logged operational data.
Categories of data we collect, and why
Sigildex is an API. "Identity" on the Service is your request IP address (used for the free tier and rate limiting, and stored only in hashed form) and, for paid requests only, your calling wallet address. We do not ask for, and the Service does not handle, names, email addresses, passwords, or payment-card data. The categories of data the Service receives or records are:
- IP address (stored hashed). Received with every request. We use it to enforce the per-IP free tier (50 discovery workflows/day per IP) and rate limits and to detect and prevent abuse. We store it as a salted one-way hash (an "IP hash"), not as a raw IP address, and use the hash as the free-tier identifier.
- Query text. The natural-language query you submit to
/discover(and the optional short free-text "rationale" describing your task). We log query text — truncated for storage — to operate the Service, return relevant results, troubleshoot, and analyze and improve search and ranking quality. - Wallet address (paid requests only). The blockchain wallet address used to authorize a paid request via the x402 protocol, present only when you make a paid request (the free tier requires no wallet). The associated on-chain transaction reference is recorded to operate payment, accounting, and abuse prevention.
- Request and result telemetry. Operational metadata about each call — for example a generated request identifier and query identifier, the endpoint and outcome (success or error class), timestamps, latency measurements, the identifiers of the skills returned, and whether the call was paid. Used to operate, secure, debug, and measure the quality of the Service.
- Standard HTTP request logs. Ordinary server logs such as timestamp, requested endpoint, HTTP method, response status, and user-agent string, used to operate, secure, and troubleshoot the Service.
We do not use cookies, web beacons, browser fingerprinting, or third-party advertising or analytics trackers. Because there are no accounts, we hold no login credentials.
How we use this data (purpose of processing)
To be explicit about purpose: we use the data above to operate and secure the Service, enforce the free tier and rate limits, prevent and investigate abuse, settle and account for payments, debug, and analyze and improve our own search relevance and ranking quality and the quality of our safety analysis. Query text and result telemetry may be used in aggregate for these internal quality and product-improvement purposes. We do not use this data for advertising, for cross-context behavioral profiling of individuals, or to train third-party foundation models, and we do not sell it. (Our safety verdicts and rankings are computed from the indexed SKILL.md content and its public signals — not from your queries.)
Legal basis
Where a lawful-basis framework such as the EU/UK GDPR applies, we rely on our legitimate interests in operating, securing, and improving the Service (for example, enforcing rate limits, preventing abuse, and maintaining ranking quality), and on the performance of the service you request when you call a paid endpoint (processing the data needed to settle your payment). We do not use this data for advertising or for profiling of individuals.
We do not sell your data
We do not sell, rent, or trade personal data, and we do not share it for cross-context behavioral advertising. We do not build advertising profiles.
Service providers and subprocessors
We use a small number of third parties ("subprocessors") to run the Service. They process data only as needed to provide their function:
- Hosting and serverless compute — Vercel. Serves the API and static site and processes request data and logs as our hosting provider.
- Database — Supabase (managed PostgreSQL). Stores the skills index and the operational logs and telemetry described above (including the IP hash and query text).
- Embeddings and content analysis — OpenAI. We send
/discoverquery text to OpenAI to generate the search embedding used to find relevant skills, and we use OpenAI to analyze indexedSKILL.mdcontent for our safety signals. We do not send your IP address or wallet address to OpenAI. - Payment facilitator — Coinbase Developer Platform (CDP). Verifies and settles x402 payments in USDC on the Base network. Receives the payment-related data necessary to settle a paid request. See "Payments and the blockchain" below.
- Indexed-source platforms — e.g. GitHub. When the Service surfaces a result, it references and links to the original public source. Following such a link takes you to a third-party platform governed by that platform's own privacy policy. We index publicly available content from these platforms; we do not transmit your IP address, query text, or wallet address to them as part of indexing or serving results.
Payments and the blockchain
Paid requests use the x402 protocol and settle in USDC on the Base network (chain eip155:8453). Settlement is performed by a third-party facilitator (Coinbase CDP). Sigildex is non-custodial — we do not hold your funds beyond what is required to settle an individual request. Public blockchains are, by design, permanent and publicly visible: an on-chain payment and its associated wallet address are recorded on the Base network outside our control and cannot be edited or deleted by us. The free tier requires no wallet and creates no on-chain record.
Retention and deletion
We retain query text, the IP hash, and operational logs and telemetry for a limited operational period and then delete them or retain them only in aggregated or anonymized form for trend and quality analysis (target retention window: see Operator fill-in). Records reasonably required for payment, accounting, tax, security, fraud-prevention, or legal-compliance purposes may be retained for a longer period as required (see Operator fill-in). On-chain payment records are permanent and outside our control (see "Payments and the blockchain").
Security
We use reasonable technical and organizational measures appropriate to a minimal-data service to protect the data we hold — including transport encryption (HTTPS), access controls on our database and infrastructure, and storing IP addresses only as salted hashes. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Data-breach handling
If we become aware of a security incident affecting personal data we hold, we will investigate, take reasonable steps to contain and remediate it, and notify affected parties and any applicable regulators where and as required by applicable law and within any legally required timeframe. Because the Service holds minimal, largely pseudonymized data and no contact details, our ability to notify a specific individual directly may be limited; where direct notice is not possible we may provide notice through the Service or our website.
Law-enforcement and legal requests
We may access, preserve, and disclose data if we reasonably believe it is required to comply with a valid legal process (such as a subpoena, court order, or other lawful request), to enforce these terms, to detect or prevent fraud or abuse, or to protect the rights, safety, and security of the Service, our users, or the public. We will review requests for legal validity and, where permitted and appropriate, seek to limit the scope of any disclosure. Much of what we hold is pseudonymized (for example, an IP hash rather than a raw IP address), which may limit what can be produced.
Your access, deletion, and other rights
Because the Service holds no account and minimal, largely pseudonymized data, the most reliable way to limit what we receive is to send fewer or less-identifying requests and to avoid placing personal information in query text. Depending on your location, you may have rights to access, correct, or delete personal data we hold about you, or to object to or restrict certain processing. To make a request, contact us using the email in the Operator fill-in block; we will respond as required by applicable law. Please note that an IP hash or wallet address alone may not let us reliably identify or locate "your" data, that we may need information to verify a request, and that on-chain records cannot be deleted by us.
Children's data
Sigildex is a developer and agent API, is not directed to children, and is not intended for use by children under the age specified in the Operator fill-in block. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
International users
The Service and its providers may process and store data in the United States and other locations, which may be outside your country. By using the Service you understand that data may be transferred to and processed in those locations.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice. Continued use after an update constitutes acceptance of the revised policy.
Contact
Privacy questions or requests: use the contact email in the Operator fill-in block below (pre-launch interim contact: security@sigildex.ai). More contact options: sigildex.ai/about.
Operator fill-in
Operator fill-in (complete before publishing; the bracketed values are the only operator-specific identifiers in this document):
- Publishing entity name:
[Operator: Texas LLC legal name, once formed] - Contact email for privacy requests:
legal@sigildex.ai - Operational retention window for query text / IP hash / logs (e.g. 30–90 days):
[Operator: retention period — confirm with counsel] - Extended retention for payment / tax / compliance records (e.g. as required by law, typically multi-year):
[Operator: extended retention period — confirm with CPA/counsel] - Minimum age for the children's-data section (e.g. 13 or 16 per applicable jurisdiction):
[Operator: minimum age] - Effective date and Last updated date:
[Operator: dates — not in effect until set]