Account data: Email address provided during API key creation. Usage data: API endpoints called, timestamps, IP addresses, request metadata. Verification data: Claims submitted to the claim checks (the brand, price, competitive and spec checks) — the claim text and the resulting verdict — are stored in an audit record (on the brand check, linked to the agent when an agent token is supplied); the claim text itself is stored as provided. Claim verification and citation verification (POST /v1/verify/claim, POST /v1/verify/citation) keep less, although the full claim is still sent to our model provider whenever the verdict needs it (see §6): their audit records hold digests, not the claim text; the first 200 characters of a claim may be kept in our usage-analytics table, for keyed and keyless callers alike (see §4); and if a claim trips our prompt-injection check, its first 200 characters are written to our application logs. Our application logs pass through a filter that redacts email addresses, phone numbers and similar patterns; it does not catch every kind of personal data, such as names. No signed receipt carries claim text. A keyless x402 payer receives the verdict unsigned and no receipt on any of these doors; on claim and citation verification the only audit record kept for that call is the model-call record, which holds digests, not the claim text. Payment data: Card billing is queued but not live — no subscription payments are processed today; when they open they will be handled by Stripe, and we do not store card numbers. x402 wallet addresses are public blockchain data. Device data: User-agent strings and IP addresses for security and rate limiting.
We use collected data to: (a) provide and improve verification services; (b) enforce rate limits and prevent abuse; (c) compute agent trust scores and audit trails; (d) generate aggregate analytics (never sold to third parties); (e) communicate service updates and security notices.
Data is stored on managed cloud infrastructure in the United States. Database connections are encrypted in transit (TLS). Common PII patterns (email addresses, phone numbers and the like) are automatically redacted from our application logs via a centralized logging filter. API keys are stored as SHA-256 hashes — we cannot recover your key after creation. Claim text we keep — in the claim checks' audit records, the usage-analytics table and, when the prompt-injection check trips, our application logs, all described in §1 — is not separately field-encrypted at rest. If we determine that a security incident has affected your data or your receipts, we will notify the email address on your account within 5 business days of that determination, with what we know at that point and what we are doing about it.
Signed receipts carry their own retention: each receipt states a retention_tier and an expires_at, computed at mint (tier A: 365 days; tier B: 90 days; tier C: 30 days), and is eligible for automated purge after expires_at unless it is under legal hold. A receipt you hold remains verifiable against our published keys after our stored copy is purged. Separately from receipts, a scheduled job is configured to delete usage-analytics records — including any claim characters kept there — once they are 90 days old. Other API usage logs and non-receipt audit records are currently retained without a fixed expiration period; that includes the claim text in the claim checks' audit records. Account data (email, API keys): retained until you request deletion. Trust score history: retained for the lifetime of the registered agent. Correspondence you send us (including the doorbell question): retained while we handle your request and for up to 12 months after, then deleted — sooner on request.
You may: (a) request a copy of your data; (b) request deletion of your account and associated data; (c) revoke API keys at any time via the API. To exercise these rights, contact support@bluefoxedge.ai.
We use the following third-party subprocessors: Resend (transactional email), Anthropic (LLM verification processing — claim text submitted for verification may be sent to Anthropic's API to compute the verdict), and our cloud hosting provider (infrastructure hosting in the United States). Of these, Anthropic may receive the text of the claims you submit. Stripe (payment processing — governed by Stripe's privacy policy) is queued to become a subprocessor when card billing goes live; it processes no payments for us today. We do not sell data to any third party.
For EU/EEA users: we process data under legitimate interest (providing the service you requested). You have the right to access, rectification, erasure, and data portability. A Data Processing Agreement (DPA) is available on request. Contact support@bluefoxedge.ai.
BlueFox Edge is an API service. We do not use cookies, tracking pixels, or browser-based analytics. The frontend (if accessed) uses no third-party cookies.
We may update this policy periodically. Registered users will be notified via email before material changes take effect.
Privacy questions? Contact us at support@bluefoxedge.ai.