Privacy Policy

Effective: April 1, 2026 · Format Dynamics, Inc. (DBA BlueFox)

1. Data We Collect

Account data: Email address provided during API key creation. Usage data: API endpoints called, timestamps, IP addresses, request metadata. Verification data: Claims submitted for verification — including the claim text and the resulting verdict — are stored in a per-agent audit record. PII is redacted from our application logs; the submitted claim text itself is stored as provided. Payment data: Subscription payments handled by Stripe — we do not store card numbers. x402 wallet addresses are public blockchain data. Device data: User-agent strings and IP addresses for security and rate limiting.

2. How We Use Data

We use collected data to: (a) provide and improve verification services; (b) enforce rate limits and prevent abuse; (c) compute agent trust scores and audit trails; (d) generate aggregate analytics (never sold to third parties); (e) communicate service updates and security notices.

3. Data Storage and Security

Data is stored on managed cloud infrastructure in the United States. Database connections are encrypted in transit (TLS). PII is automatically redacted from our application logs via a centralized logging filter. API keys are stored as SHA-256 hashes — we cannot recover your key after creation. Verification claim text is retained in audit records and is not separately field-encrypted at rest. If we determine that a security incident has affected your data or your receipts, we will notify the email address on your account within 5 business days of that determination, with what we know at that point and what we are doing about it.

4. Data Retention

Signed receipts carry their own retention: each receipt states a retention_tier and an expires_at, computed at mint (tier A: 365 days; tier B: 90 days; tier C: 30 days), and is eligible for automated purge after expires_at unless it is under legal hold. A receipt you hold remains verifiable against our published keys after our stored copy is purged. API usage logs and non-receipt audit records are currently retained without a fixed expiration period. Account data (email, API keys): retained until you request deletion. Trust score history: retained for the lifetime of the registered agent.

5. Your Rights

You may: (a) request a copy of your data; (b) request deletion of your account and associated data; (c) revoke API keys at any time via the API. To exercise these rights, contact support@bluefoxedge.ai.

6. Third-Party Services

We use the following third-party subprocessors: Stripe (payment processing — governed by Stripe's privacy policy), Resend (transactional email), Anthropic (LLM verification processing — claim text submitted for verification may be sent to Anthropic's API to compute the verdict), and our cloud hosting provider (infrastructure hosting in the United States). Of these, Anthropic may receive the text of the claims you submit. We do not sell data to any third party.

7. GDPR Compliance

For EU/EEA users: we process data under legitimate interest (providing the service you requested). You have the right to access, rectification, erasure, and data portability. A Data Processing Agreement (DPA) is available on request. Contact support@bluefoxedge.ai.

8. Cookies

BlueFox Edge is an API service. We do not use cookies, tracking pixels, or browser-based analytics. The frontend (if accessed) uses no third-party cookies.

9. Changes to This Policy

We may update this policy periodically. Registered users will be notified via email before material changes take effect.

10. Contact

Privacy questions? Contact us at support@bluefoxedge.ai.

← Back to BlueFox Edge