Privacy
Template, not legal advice. Last updated 2026-07-23.
What we store
- Designers: email address, display name, password hash, and the Hedera account id you give us for payouts.
- Buyers: no account. A purchase stores the paying Hedera account id (public on-chain anyway), the payment transaction id, and the license issued. If you explicitly opt into the license library from a paid receipt, we also store the email address you provide so we can send private library links; it is not published on-chain.
- Designer early access: if you submit the landing-page form, we store the email only to confirm the request and tell you when designer onboarding opens. It does not create an account, newsletter subscription, or public profile.
- On-chain: the payment transfer is public on Hedera. The current licence writer separately publishes only an opaque commitment to a public Hedera Consensus Service topic; the certificate, nonce, model, buyer hint, terms, and payment transaction remain in the holder's private proof bundle. A holder may choose to disclose that bundle.
What we don't do
- No advertising, no tracking pixels, no sale of data.
- Marketplace analytics are daily impression, detail-view, and initial x402 quote-request counters by model, surface, and human/agent channel. They do not contain a buyer id, account id, session id, IP address, query text, referrer, or user agent. Individual analytics events are not retained after aggregation; operational job data and server logs are rotated.
- Private keys never touch our servers — payments are signed client-side.
Removal
Designers can export their data and close their account from Account settings. Closure removes private profile, payout, import, and integration data; unpurchased listings are deleted. We retain the studio name, purchase-backed listing and transaction-time license evidence needed to keep existing receipts, downloads, certificates, and rights valid. Those listings are retired from all new sales. Closure is blocked while a real-money purchase or owed payout is unresolved. Optional buyer-library email and early-access addresses can be removed by email; on-chain payment and commitment records are permanent by design. Questions: see the repository README for contact.