Legal

Privacy Policy

Last updated: July 23, 2026

This document is provided for transparency and should be reviewed by legal counsel before relied upon.

Foundry Labs LLC ("Foundry Labs," "we," "us," or "our") operates Assay, cross-platform infrastructure for AI agent identity, trust scoring, and capability attestation available at assay.foundrynet.io. This Privacy Policy describes what information we collect, how we use it, and the choices you have.

1. Information We Collect

Account Information

When you obtain an API key or authenticate via OAuth, we collect your email address and, for paid usage, payment information. Payments are processed by Stripe; we do not store full card numbers, bank account numbers, or other raw payment credentials.

Agent and Attestation Data

When you use the Services, we receive and store the data you submit to register agents and record outcomes. This may include agent names, owner-organization identifiers, declared capabilities, platform identifiers, task types, outcomes (success or failure), optional counterparty agent identifiers, and optional evidence hashes. From this attestation history we compute trust scores and verification results.

Usage Data

We collect information about your use of the Services, including API call counts, endpoints accessed, timestamps, and error rates. We use this data for metering and billing, rate limiting, security, and service improvement.

Technical Data

We may collect limited technical information such as IP address (used, among other things, to meter anonymous bootstrap calls) and request metadata for security and abuse prevention.

2. How We Use Your Information

  • To provide, maintain, secure, and improve the Services.
  • To compute agent identities, trust scores, verification results, and discovery listings.
  • To meter usage and process billing and payments via Stripe.
  • To communicate with you about your account, service updates, and changes to these policies.
  • To detect, investigate, and prevent fraud, abuse, gaming of trust scores, and security incidents.
  • To comply with legal obligations.

3. Attestation and Integrity Proofs

Assay's attestation feature produces tamper-evident, cryptographic proof references. When you record an attestation, the Services generate an opaque proof reference (an attestation_ref) that lets the integrity of that record be checked later without exposing its contents.

To make these proofs tamper-evident, the Services derive a one-way cryptographic hash of each attestation record and chain it to the prior proof, so that any later alteration is detectable. These proofs are maintained internally within the Services; nothing is published to any external or public ledger. Only opaque hashes are used for integrity, never personal data, never agent payloads, and never the raw content of any work. A hash cannot be reversed to reveal the underlying information.

Each proof is chained to the one before it, so any attempt to alter an earlier record is detectable. These integrity proofs contain no personal data or raw content, and, unlike a public ledger, they are held internally and are deleted together with your other data on account termination, as described in Section 5.

4. Data Sharing

We do not sell your personal information. We may share information with:

  • Stripe: for payment processing, subject to Stripe's privacy policy.
  • Infrastructure providers: hosting and database providers that operate the Services under confidentiality and data-processing obligations.
  • Discovery participants: agent identity, declared capabilities, and computed trust data are, by the nature of the Services, readable by other participants through public read and discovery endpoints. Do not place sensitive or personal information in agent names, capability labels, or other fields intended to be publicly discoverable.
  • Law enforcement or authorities: where required by law, subpoena, or court order, or to protect the rights, safety, and security of Foundry Labs, our users, or the public.

5. Data Retention

We retain account, agent, attestation, and usage data for as long as your account is active and as needed to provide the Services. Following account termination, we retain data for a reasonable period (generally up to 90 days) to facilitate export and to meet legal obligations, after which it is deleted from our active systems. Aggregated or de-identified data may be retained to improve the Services. Attestation records and their internal integrity proofs are deleted together with your other account data on the schedule described above.

6. Data Security

We implement reasonable technical and organizational measures to protect your data, including:

  • API-key and OAuth 2.0 authentication on protected endpoints.
  • Hashing of API keys at rest rather than storing them in plaintext.
  • One-way cryptographic hashing for integrity proofs, so raw content is never exposed.
  • Account and tenant isolation, transport encryption, and access controls.

No system is perfectly secure, and we cannot guarantee absolute security of your data.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Request a copy of the personal data we hold about you.
  • Request correction of inaccurate account information.
  • Request deletion of your account and associated personal data, subject to the permanence of integrity hashes described in Section 3 and to our legal obligations.
  • Opt out of non-essential communications.

To exercise these rights, contact us at forge@foundrynet.io.

8. International Data Transfers

The Services are operated from the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States. By using the Services, you consent to this transfer.

9. Children

The Services are not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via the email associated with your account or by posting notice at assay.foundrynet.io before the changes take effect.

11. Contact

Foundry Labs LLC
forge@foundrynet.io