Privacy Policy

What we collect, why, and where it goes.

Effective 2026-06-12. The short version: we collect what's needed to run accounts, meter usage, and settle payments — and little else. Card numbers never touch us. We don't sell personal data.

1. What we collect

  • Account: the identity your sign-in provider shares with us (email, name, provider user ID) and the keys/sessions we issue you.
  • Usage & billing: API request logs (which capability, when, what it cost), your Aev ledger, and top-up records. This is the basis of metered billing and your own receipts — we keep it accurate and auditable.
  • Payments: processed by Stripe. We receive confirmation and order metadata; your card details go to Stripe only.
  • Your deployed content: the code and assets you upload so we can build and host them.
  • Arrival context: if you land with campaign parameters (e.g. utm_source), we record them once against your account to know which channel brought you. Organic visits record nothing extra.
  • Cookies: a signed session cookie for login, and privacy-friendly page analytics (Vercel Analytics). No cross-site ad trackers.

2. How we use it

To operate the platform: authenticate you, meter and bill usage, settle earnings, prevent abuse and fraud, debug failures, and improve the product. We do not sell personal data, and we don't use your deployed code for anything except building and serving it.

3. Your app's end users

When end users sign in to an app you deployed, SettleMesh processes their login and balance as the platform — the same way it does yours. What your app itself collects and does with their data is your responsibility as its developer.

4. Sub-processors

We rely on these providers to run the service:

  • Stripe — payment processing
  • Supabase — database and authentication infrastructure
  • Google Cloud — application runtime and builds
  • Cloudflare — edge routing, CDN, and worker runtime
  • Vercel — website hosting and page analytics
  • Render — API hosting
  • E2B — isolated sandboxes for agent/worker workloads
  • Model/data providers — when you invoke capabilities that route to them

5. Retention and deletion

Account and content data live for the life of your account. Billing and ledger records are retained as long as needed for financial accuracy and legal obligations. You can request account deletion at [email protected]; we delete personal data not subject to retention duties.

6. Security

See the dedicated Security page for how workloads, secrets, and money paths are protected.

7. Changes and contact

Material changes to this policy will be announced on the site. Questions or requests: [email protected].