The Embassy · Terms · Pricing

Embassy Trust Protocol — Privacy Policy

Last Updated: 2026-02-02. Same text as the repo PRIVACY.md. Org billing accounts also store email and Stripe customer/subscription ids when you start a paid plan.

1. Data Collection

What We Collect

Registry Records:

Org billing (dashboard accounts): account email, organization name, Stripe customer id, subscription id, plan, subscription status, renewal date. Card numbers are collected and stored by Stripe, not by Embassy.

What We Never Collect

2. Data Storage

Registry and org records: KV storage (SQLite locally, Netlify Blobs in production). Receipts: customer-owned; Embassy does not store receipt bodies unless custody is explicitly enabled.

3. Data Retention

Active registry records: indefinite until revoked. Revoked records: indefinite for audit trail. Credit records: TTL then auto-expire. Receipts: customer-controlled.

4. Data Sharing

Embassy does not sell data. Paid checkout shares email and customer metadata with Stripe to create a customer and subscription. Agent certificates and registry status remain queryable public protocol data.

5. Data Security

Signing keys live in environment variables, never in git. Stripe secret keys live in Netlify env, never in the client.

6. Customer Rights

Agents can query registry status, verify certificates, and request receipt exports. Agents can request revocation. Dashboard users can manage or cancel a paid subscription via Stripe Customer Portal (Manage Billing).

7. Receipts Are Non-Custodial

Receipts written to customer-controlled storage unless custody is explicitly enabled. Receipt generation is best-effort and non-blocking.

8. Changes to Privacy Policy

Changes notified via service announcements. Continued use constitutes acceptance of the new policy.

9. Contact

Privacy inquiries: info@boonmind.io · Contact.