Privacy Policy
This policy explains what the operators of Agent Tolls ("we", "us") collect, why, and what happens to it. Two groups pass through here: customers — site owners with an account — and visitors of the sites our gateway protects.
1What we collect from customers
When you sign in with Google or GitHub and set up sites, we store:
- your email address and display name, as your sign-in provider verifies them;
- account records, your site hostnames, and their DNS verification records;
- your pricing configuration;
- API keys, stored only as SHA-256 hashes — we cannot read the key back;
- a ledger of settled tolls and payouts for your sites;
- the address of the non-custodial wallet pregenerated for you through Privy, keyed on your verified email. We store only wallet addresses — never private keys, which we cannot see and never hold.
We use this to run your gates, verify you control your hostnames, show you your earnings, and pay out your share. Nothing else.
2What we process about visitors of gated sites
When anyone — human or agent — requests a page behind the gateway, we process request
metadata: IP address (passed to Cloudflare Turnstile for captcha verification and used
transiently to handle the request), user-agent, the requested path, and headers used to
tell humans from agents (for example Accept-Language). We do not read or
store the content of your browsing beyond this.
- Aggregated traffic counts may be recorded in Cloudflare Analytics Engine and kept for 90 days.
- Settled payments are recorded permanently: transaction hash, payer wallet address, amount, path, and hostname. The same facts also exist on the public Base blockchain, which nobody can edit or erase.
3Where it lives, and for how long
Data is stored in Cloudflare D1 and Workers KV, on Cloudflare's infrastructure. Customer account data is kept while your account exists and deleted on request. Aggregated analytics expire after 90 days. The toll ledger is kept as a financial record, and on-chain data is permanent by the nature of public blockchains.
5Subprocessors
We rely on a short list of providers to run the service:
- Cloudflare — hosting, storage (D1, KV), analytics, and Turnstile captcha;
- Privy (privy.io, a Stripe company) — non-custodial embedded wallets;
- the x402 payment facilitator (currently PayAI) — payment settlement;
- public blockchain networks — Base today; Solana planned.
6What we don't do
We do not sell personal data, we do not run advertising, and we do not track anyone across other sites. Data goes to the subprocessors above only so the service can work.
7Your rights
Email [email protected] to access, correct, or delete the data we hold
about you. We will act on it promptly. One honest caveat: records already settled on a
public blockchain cannot be deleted by us or anyone else.
8Children
Agent Tolls is not directed at children under 16, and we do not knowingly collect their data.
9Changes to this policy
Updates are posted on this page with a new effective date. For material changes we will notify customers by email before they take effect.
10Contact
Privacy questions, requests, or complaints: [email protected].