Legal

Privacy

How Foundry works with your money, your data and the service.

Draft. This text is not final.

1.Who we are

Foundry runs usdf.fi and the API at api.usdf.fi and decides how the data below is used.

2.What we collect

When you sign in: your email address or wallet address and the Privy user id, and the wallets you link. For each request: the account and key it was made with, model, token or unit counts, cost, latency, status and time. For payments and withdrawals: wallet addresses and transaction hashes. API keys are stored only as hashes. If you write to us, we keep the message.

3.What we do not keep

We do not keep prompt or completion text in our database. Without no-logs mode, a report about a failed request can include part of it; a key in no-logs mode keeps prompts, completions and tool arguments out of every log line, alert and error report, and every private-tier key is in no-logs mode. Batch results and generated videos are kept until they expire (at most 30 days) so you can collect them, then deleted; their status, cost and receipt remain.

4.Public by design

A request's receipt (token counts, cost, price-sheet version and status, never its content) can be read by anyone who has its request id, and every request is a leaf in a public usage log anchored onchain, so it cannot be removed later. Deposits, withdrawals and payments are transactions on a public blockchain.

5.How we use it

To run the service and bill requests, to show you your activity and statements, to secure the service and prevent abuse, to publish the reserve, status and usage proofs, and to meet legal obligations. We do not sell personal data, do not use it for advertising, and do not train models on your requests.

6.Who receives it

Model providers receive the content of your requests in order to answer them, under their own terms; private-tier requests run on attested hardware. Privy receives your email or wallet address and IP address when you sign in, and its sign-in window may run Cloudflare's bot check. Our hosting and database providers process data on our behalf. WalletConnect is used when you connect a wallet through it. Fonts are loaded from Google Fonts, which receives your IP address. We share data with authorities only where the law requires.

7.Browser storage

The site keeps your sign-in session and a few settings (such as the code language you chose in the docs) in your browser's storage. It uses no advertising or analytics cookies and no third-party trackers.

8.How long we keep it

Account details are kept while your account is open. Request and payment records are kept as long as they are needed for billing, statements and the public usage log; log entries and onchain records cannot be deleted. When you ask us to delete your account, we delete what we are not required to keep.

9.Your choices and rights

You can revoke keys, turn on no-logs mode, use the private tier and withdraw your balance at any time from the dashboard. Depending on where you live, you can ask to see, correct, export or delete your personal data, or object to how it is used, and complain to your data-protection authority. To make a request, contact us as below.

10.Security

Traffic is encrypted, keys are stored as hashes, the site sends a strict Content-Security-Policy with every page, and access to production systems is limited. No system is perfectly secure; tell us at once if you believe your account or a key has been compromised.

11.Changes

We change this policy by updating this page with a new effective date.