Privacy Policy
The short version
- TWZRD is a pre-spend trust gate for agents paying over x402. A free preflight returns allow, warn, or block. It is advice, not a guarantee.
- We read public on-chain payment activity about wallets. We do not try to find out who is behind a wallet.
- When you visit the site or call our APIs, we keep technical records, including your IP address or a keyed hash of it. We do not sell them to anyone.
- The site sets no cookies of its own. The app pages load fonts from Google, and the home page asks npm and PyPI for package versions, so those services see your IP address.
- The operator keeps the wallet and keys; the operator is you, or whoever runs the agent. TWZRD does not hold or custody funds and never receives private keys.
Who we are
TWZRD is operated by TWZRD, Inc., a Delaware corporation, which is the data controller for the information described here. This page explains, in plain words, what we collect and why.
Visiting twzrd.xyz
- Our web server records your IP address, your browser (user agent), the page you asked for, the time, and the request headers your browser sends (such as the referring page and your language). These logs are rotated when they reach a set size and deleted seven days after rotation, so an entry can live up to about two weeks.
- Cloudflare carries and protects all traffic to our sites. It sees the same technical details, gives us aggregate traffic statistics, and may set its own cookie if it shows you a security challenge.
- Your browser contacts some services directly. The app pages (the home page and its sections) load fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com); this page and our other plain pages use your device's own fonts. The home page asks npm (registry.npmjs.org) and PyPI (pypi.org) for the current versions of our packages. These services receive your IP address and browser details under their own privacy policies.
- Links to other sites, such as GitHub, Solscan, Smithery or Dune, only contact those sites if you follow them.
- If you email us, we keep the message so we can reply.
We don't sell or trade your information to advertisers or data brokers.
No cookies, no wallet sign-in
twzrd.xyz sets no cookies of its own and does not use your browser's storage to track you or to remember you between visits.
The site does not ask you to connect a wallet, and it has no embedded wallet or sign-in provider. The demo and the free preflight run without a wallet. TWZRD never receives private keys.
Calling our APIs
Our APIs (intel.twzrd.xyz, including our MCP tools, and api.twzrd.xyz) keep request records so we can run, secure, and measure the service. A "keyed hash" below is a one-way code that lets us tell repeat requests apart without storing the address itself.
- Every free preflight check is recorded: the wallet or resource checked, the result we returned, the time, your user agent, your IP address, and a label naming what sent the check (the site labels its own pages; an installed gate sends its package name and version).
- MCP tool calls and payment challenges have their own records: the tool or route, the time, your user agent, the client name and version it reports, and a keyed hash of your IP address.
- Other requests to intel.twzrd.xyz are sampled: about one in ten successful requests, and every failed one, with a keyed hash of the IP address.
- api.twzrd.xyz keeps its own operational request logs.
- When you pay for a call, we record the payment: your paying wallet, the transaction signature, the amount, and the endpoint.
- The paid page-read endpoint fetches the URL you submit for you through third-party web-fetching services.
Data for the trust rail
The trust rail is the service that answers a check. It reads public on-chain payment activity through blockchain data providers (such as Helius) and public on-chain records, and organizes it so an agent can see observed behavior before it pays. To answer a check, we may look up the addresses you ask about with those providers.
This is wallet-level information: public addresses and how they have transacted. We do not collect names, emails, or identities to build it, and we do not try to identify who is behind a wallet. A free preflight is advisory: allow, warn, or block. It is not a promise that a seller is safe.
From these public payment patterns we derive trust signals, for example to flag wallets that look like they are wash-trading. We tell you what a signal means, not the exact method behind it. Signals are about on-chain behavior, never about a person.
Most users of the trust rail are software agents. We do not profile individuals, we do not use your data to train models about you, and we do not build advertising profiles.
Receipts
When an agent buys a trust receipt, we issue a signed V7 receipt describing what we observed about a counterparty. You can store, share, and reuse it, and verify it offline with our open verifier library, without coming back to us. We keep a record of each paid settlement; if you lose a receipt, we can issue a fresh one for the same settlement. That is a new attestation at that time, not a copy of the original.
Who helps us run the service
- Cloudflare: carries and protects all traffic, gives us aggregate traffic statistics, and stores our nightly database backups.
- Google: web fonts on the app pages, and email for messages you send us.
- npm and PyPI: package-version lookups that your browser makes on our home page.
- Blockchain data providers (such as Helius): on-chain reads and payment activity feeds.
- Web-fetching services: only for URLs submitted to the paid page-read endpoint.
- Payment facilitators: for paid API calls, the facilitator used for the payment processes it under its own terms. We run one ourselves; see the Terms.
These providers process data only to help us run the service, and they have their own privacy terms.
What we don't collect
- No passwords or private keys.
- No tracking of your browsing outside TWZRD sites.
- No attempt to identify the person behind a wallet.
- No selling or trading your data to advertisers or data brokers.
How long we keep things
We hold information as long as we need it to run the service, answer you, stop abuse, or follow the law. In practice:
- Web server logs: up to about two weeks.
- API request records: we have not set an automatic deletion period for them yet.
- Payment records: as long as we need them for accounting and to resolve disputes.
- Database backups: nightly copies are kept 14 days. Older backup copies also exist, including a series from before our move to the current host.
- Messages you send us: as long as we need them to reply and keep a record.
You can ask us to delete what we control. If you do something on a public blockchain, that record is public by nature, and neither we nor you can delete it.
Your data rights
You can ask us to:
- access the personal data we hold about you;
- delete data we control (subject to legal limits);
- object to or limit certain uses of your data.
To make a request, email privacy@twzrd.xyz. On-chain activity stays public on the blockchain and is outside our control, and our trust signals are rebuilt from that public activity.
Age
You should be 18 or older to use TWZRD. We don't knowingly collect information from anyone under 18.
Keeping things safe
We use secure connections (HTTPS). No system is risk-free, but we take reasonable steps to protect what we hold.
Updates
If we change this page in a meaningful way, we will update the date at the top.
Questions
Reach us at privacy@twzrd.xyz.