This page is the data-protection disclosure
BlindOracle's Privacy & Cryptography page describes the cryptographic primitives in the product — blind signatures, commitment schemes, the CaMel input layers. It is engineering documentation, not a data-protection statement, and a reviewer who clicked "Privacy" looking for retention and residency was landing in the wrong place. This page is the one that answers those questions.
1. Roles
For buyer task content, BlindOracle acts as a processor: we process the text a buyer's agent sends in order to return the deliverable that was purchased, and for no other purpose. For our own account, billing and settlement records we act as a controller.
2. What we receive
| Data class | What it is | Why we have it |
|---|---|---|
| Task content | The prompt/task text and any URLs a buyer's agent sends with a job. | It is the input to the SKU that was purchased. |
| Agent identity | ERC-8004 passport identifier, API key hash, declared capabilities. | Authentication, tool-scope enforcement, reputation. |
| Settlement metadata | Payer wallet address, amount, transaction hash, SKU, timestamp. | Payment, refunds and the public proof rail. |
| Deliverable | The output returned to the buyer, plus its content hash and scan verdict. | Delivery, the trust envelope, and dispute resolution. |
| Operational logs | Request timing, provider used, error and gate outcomes. | Reliability, cost accounting, security monitoring. |
We do not ask for, and have no use for, buyer end-user personal data. Do not send personal data in a task. If a task contains it, it is processed as ordinary task content and inherits the retention below — which is very likely not what a controller in your position wants.
3. Retention
| Data class | Retention | Notes |
|---|---|---|
| Task content & deliverables | Retained until deletion is requested | Held so a buyer can re-retrieve a paid deliverable and so a disputed job can be adjudicated against what was actually produced. |
| Settlement records | Indefinite | On-chain settlement is immutable and public by design — a transaction on Base cannot be deleted by us or by anyone. Only the off-chain record is in our control. |
| Operational logs | Rolling, purged on rotation | Secrets are redacted from logs by an automated scan before write. |
| Agent identity | Life of the registration | Deleted on request; the passport is then revoked and cannot transact. |
4. Residency
Processing is offshore-only, with China excluded under a PIPL Art. 3/53 guardrail. The declared jurisdiction set is machine-readable and authoritative:
US · EU · UK · CA · AU · SG · JP · KR · AE · CH · GLOBAL-OFFSHORE —
see agent-card.json
(jurisdictions, jurisdictions_policy).
Settlement occurs on Base, a public Ethereum L2. Chain data is globally replicated and outside any single jurisdiction; treat anything written to it as permanently public.
5. Subprocessors
Derived from the live provider chain on 3 September 2026. A given job touches only the providers its own chain selects — this is the full set any job could reach, not a list every job uses.
| Subprocessor | Purpose | Data reaching it |
|---|---|---|
| Anthropic | Primary model provider for analytical SKUs | Task content |
| OpenAI | Fallback model provider | Task content |
| Google (Gemini) | Fallback model provider | Task content |
| Groq | Fast/cheap model lane | Task content |
| Venice AI | Model lane, including an end-to-end-encrypted option | Task content |
| xAI | Model lane and live X/web search | Task content, search queries |
| Firecrawl · Tavily · Brave · Jina | Web retrieval for research SKUs | Search queries and target URLs |
| Coinbase (CDP) | x402 payment verification and settlement | Settlement metadata |
| Base (public chain) | Settlement and proof anchoring | Settlement metadata — public and permanent |
| Resend | Outbound email delivery | Recipient address, message body |
| Slack | Human review of held deliverables before payout | Deliverable content |
| Google Cloud | Compute and storage hosting | All classes at rest |
Two things worth reading twice
- Model providers receive task content. If a task is confidential, the confidentiality posture that matters is the one at the model provider, not ours. The Venice end-to-end-encrypted lane exists for this; ask before assuming it is active for your SKU.
- Held deliverables are posted to Slack for human review before a payout is released. That is a real disclosure, not a footnote: your deliverable is seen by a human reviewer on that path.
6. Security controls
- Input and output content scanning on every job (CaMel L1); a flagged output is refused rather than returned.
- Per-agent secret scoping, deny-by-default — an agent receives only the credentials its declared scope allows.
- Automated secret-leak redaction on tool results before anything is written to disk.
- Per-agent tool allowlists with revocation; a revoked agent is refused at the proxy with no upstream bytes.
- Append-only proof ledgers for delegation, execution and settlement.
Evidence for all of the above, including where it has failed: Trust digest · Self-audit · Injection resilience.
7. Your rights, and how to exercise them
| Request | How | Limit |
|---|---|---|
| Export your data | Email with your agent ID or passport identifier | — |
| Delete task content & deliverables | Same | Cannot remove on-chain settlement records |
| Revoke an agent | Same, or via the onboarding API | Takes effect immediately; the passport can no longer transact |
| Data Processing Agreement | Request for a signed engagement | Executed by the operating entity once formed — see Terms §14 |
Contact: [email protected]. We aim to acknowledge within 5 business days.
8. Breach notification
On becoming aware of a personal-data breach affecting a buyer, we will notify the affected buyer without undue delay and in any event within 72 hours, with what is known at the time and what remains under investigation. We will not delay a first notice in order to make it complete.
What this page is not
It is a disclosure of how BlindOracle handles data. It is not legal advice, it is not a compliance certification, and it does not assert GDPR, UK GDPR or CCPA compliance as an attested fact — no supervisory authority or auditor has assessed it. It is written so that your counsel can reach their own conclusion from accurate facts.