1.Who we are
Foundry runs usdf.fi and the API at api.usdf.fi and decides how the data below is used.
2.What we collect
When you sign in: your email address or wallet address and the Privy user id, and the wallets you link. For each request: the account and key it was made with, model, token or unit counts, cost, latency, status and time. For payments and withdrawals: wallet addresses and transaction hashes. API keys are stored only as hashes. If you write to us, we keep the message.
3.What we do not keep
We do not keep prompt or completion text in our database. Without no-logs mode, a report about a failed request can include part of it; a key in no-logs mode keeps prompts, completions and tool arguments out of every log line, alert and error report, and every private-tier key is in no-logs mode. Batch results and generated videos are kept until they expire (at most 30 days) so you can collect them, then deleted; their status, cost and receipt remain.
4.Public by design
A request's receipt (token counts, cost, price-sheet version and status, never its content) can be read by anyone who has its request id, and every request is a leaf in a public usage log anchored onchain, so it cannot be removed later. Deposits, withdrawals and payments are transactions on a public blockchain.
5.How we use it
To run the service and bill requests, to show you your activity and statements, to secure the service and prevent abuse, to publish the reserve, status and usage proofs, and to meet legal obligations. We do not sell personal data, do not use it for advertising, and do not train models on your requests.
6.Who receives it
Model providers receive the content of your requests in order to answer them, under their own terms; private-tier requests run on attested hardware. Privy receives your email or wallet address and IP address when you sign in, and its sign-in window may run Cloudflare's bot check. Our hosting and database providers process data on our behalf. WalletConnect is used when you connect a wallet through it. Fonts are loaded from Google Fonts, which receives your IP address. We share data with authorities only where the law requires.
7.Browser storage
The site keeps your sign-in session and a few settings (such as the code language you chose in the docs) in your browser's storage. It uses no advertising or analytics cookies and no third-party trackers.
8.How long we keep it
Account details are kept while your account is open. Request and payment records are kept as long as they are needed for billing, statements and the public usage log; log entries and onchain records cannot be deleted. When you ask us to delete your account, we delete what we are not required to keep.
9.Your choices and rights
You can revoke keys, turn on no-logs mode, use the private tier and withdraw your balance at any time from the dashboard. Depending on where you live, you can ask to see, correct, export or delete your personal data, or object to how it is used, and complain to your data-protection authority. To make a request, contact us as below.
10.Security
Traffic is encrypted, keys are stored as hashes, the site sends a strict Content-Security-Policy with every page, and access to production systems is limited. No system is perfectly secure; tell us at once if you believe your account or a key has been compromised.
11.Changes
We change this policy by updating this page with a new effective date.