Privacy policy
Last updated 25 September 2026
This page explains what data x402receipts handles, why, and what is public. We designed the service so that we hold as little as possible: there are no email addresses, no passwords and no names, and nothing about what your agents bought ever goes on a public ledger.
What we store
- Receipts sent by agents: the resource bought (a URL), the method, the time, the network, the amount and asset, the paying and receiving wallet addresses, the transaction reference, a hash of the request and of the response, whether it was delivered, and, when a seller provides one, the seller's signed receipt.
- Payments we read from public blockchains for the wallets connected to an account: transaction id, time, amount, receiving address.
- Wallet addresses used to sign in or connected to an account, and the time they were connected. A wallet address is public information on the blockchain; we treat it as an account identifier.
- Batches: the Merkle root of each group of receipts and where it was written on Hedera.
We do not store the messages you sign to sign in (they are checked and discarded), private keys, IP-based profiles, or analytics beyond ordinary server logs kept for a short time for security and debugging.
What is public
Only the Merkle root of a day's batch, the number of receipts in it, the time span and a link to the batch page are written to the Hedera Consensus Service. A root is a fingerprint: it cannot be reversed into the receipts. The message also carries an internal workspace identifier, which is a random id with no meaning outside our system.
Each receipt has a verification page at https://app.x402receipts.com/verify/<receipt id>. It shows that receipt's contents to anyone who has the link. Receipt ids are long random values; share a link only with people who should see that receipt.
Why we process this data
To provide the service you asked for: recording, reconciling and proving your agents' purchases (performance of a contract). To keep the service secure and to prevent abuse (legitimate interest). We do not sell data, do not use it for advertising, and do not share it with third parties except the infrastructure providers below.
Who else touches the data
- Vercel (hosting, United States) runs the application.
- Turso (database, United States) stores the data described above.
- Public blockchains (Base, Solana, Hedera) and their public mirror nodes and explorers, which we read from. Payments to us are settled by an x402 facilitator (currently PayAI), which sees the payment authorisation an agent signs, as any x402 payment would.
Data is stored in the United States. For users in the EU, transfers rely on the providers' standard contractual clauses.
How long
Receipts and payments are kept for as long as the account exists, because their purpose is to be an audit trail. If you ask us to delete an account, we delete its receipts, payments and wallet links from our database within 30 days. Roots already written to Hedera cannot be deleted by anyone; they contain no personal data.
Your rights
You can export everything filed under your account from the Activity page at any time. You can ask us to correct or delete data, or to explain what we hold, by writing to hello@x402receipts.com from a wallet-signed message or the address you used with us. If you are in the EU you also have the right to complain to your data protection authority.
Changes
If this policy changes in a way that matters, we say so on this page 30 days in advance. Questions: hello@x402receipts.com.