← Back to Home
Privacy Policy
Effective Date: July 10, 2026
MetaMesh-UGA ("we", "our", or "us"), operated by SiouxTXT Labs, is committed to protecting your privacy. This Privacy Policy describes how we collect, use, and share information when you use our service, including our API, gateway, and websites.
1. Data Controller
The data controller responsible for your personal data is:
SiouxTXT Labs
Address: Milan, Italy
Email Contact: [email protected]
2. Information We Collect
We process personal data in accordance with the GDPR (General Data Protection Regulation). We prioritize data minimization and only collect metrics necessary to maintain service performance, security, and billing accuracy:
- Usage Metrics: We log HTTP request status, gateway latency (in milliseconds), requested tool name/namespace, and billing units.
- Identifiers: We collect and store hashed API keys (`api_key_hash`) and agent IDs (`agent_id`) to authenticate and verify billing quotas.
- No Content Logging: By default, we do not log request bodies, payloads, parameters, prompts, or response bodies. All telemetry logs are processed using allowlists to redact payload contents.
- Payment Data: All credit card transactions are handled by Stripe. We do not store or process payment card data. For cryptocurrency payments (x402), we verify EIP-712 signatures and record transaction hashes on the Base blockchain.
3. Purpose and Legal Basis
We process your data under the following legal bases:
- Performance of a Contract: To authenticate calls, enforce rate limits, manage prepaid credit balances, and route tools (Art. 6(1)(b) GDPR).
- Legitimate Interest: To monitor and maintain service health, detect and prevent fraud or system abuse, and optimize tool discovery latency (Art. 6(1)(f) GDPR).
4. Subprocessors
We share necessary data with the following subprocessors to deliver the service:
- Cloudflare, Inc. (USA/EU) — Web application firewall, DNS, edge compute, and storage.
- Stripe, Inc. (USA/EU) — Credit card payments and checkout sessions.
5. Data Retention
We apply the following retention schedules:
- Usage Logs: Deleted automatically after 30 days.
- Transaction Logs: Retained for 5 years for legal, accounting, and tax purposes.
- Agent Wallets & Accounts: Retained until the account is deleted by the user.
6. Your Rights (GDPR)
Under GDPR, you have the right to access, rectify, or erase your personal data, restrict or object to its processing, and request data portability. To submit a Data Subject Access Request (DSAR) or request account/log deletion, contact us at [email protected]. We respond to all requests within 30 days.
7. Zero-Retention Mode
For Enterprise accounts, we support a dedicated "Zero-Retention" mode where no usage logs are written to our databases, and all analytics are disabled.