What we collect.
And what we don't.
We need an email for your Stripe payment receipt, a card to charge, and the inputs you send a bot to write your report. We hold your inputs only until the run is done, keep the report built from them for 90 days, don't sell anything to anyone, and don't run third-party tracking pixels. The same applies when you use botx402 through an AI assistant (our MCP connector): see section 03.
The data controller is Arnhem Labs Pty Ltd (ABN 53 696 663 297), an Australian proprietary limited company, trading as "botx402". When this notice says "we" or "us", that means Arnhem Labs Pty Ltd. For privacy questions or requests, email hello@botx402.io.
If you reach us as an autonomous agent paying with USDC over x402, we additionally record your signing wallet address — see section 02.
What we collect
Email address — the one you give us at checkout (or that your AI assistant passes on for you, see section 03). Stripe sends a payment receipt to it, and we email you a link to your finished report. We may also email you about a run or a refund you start. Agents may give one optionally.
Payment method — card payments are handled entirely by Stripe (PCI Level 1). We never see your card number; Stripe sends us a confirmation that the charge succeeded, and its session id, which we keep on the run record. Agents paying in USDC are covered in section 02.
The inputs you send a bot — for example the stock and sales figures you paste for a reorder plan. For a card checkout we check them, then hold a copy while you pay (see section 05), and read it once when Stripe confirms the payment.
The data you submit for a run, while it is processed: in the job queue and in memory until the report is generated.
Receipt ID, run timestamps, run status — kept in our jobs table for refund and audit purposes.
Receipt PDF — a separate document we generate at delivery time that records the sale (Arnhem Labs Pty Ltd as vendor + ABN, your email or wallet address as the buyer, the receipt ID, the line item, the amount). It's stored encrypted alongside the report PDF and accessed via the same `&t=…`-gated /results URL.
IP address — used, never stored as such: a card checkout started on the website counts against a daily limit keyed on a hash of your IP address and browser user-agent (kept about 36 hours). Our request logs record a daily-rotating hash of IP address and user-agent instead of the address, plus the user-agent itself, the pages and API endpoints called, and receipt IDs. They never contain your inputs, your email address or your access token.
If you visit on prd, anonymised analytics (page views, no individual identifiers) via Plausible — a privacy-friendly analytics tool that doesn't use cookies and isn't shared with third parties.
What we collect from agent (x402) callers
If you call our agent endpoints (paying with USDC over x402), we collect these items.
Payer wallet address — the EIP-55 lower-cased 0x… address that signed the EIP-3009 authorization. We log it on the Job row and in CloudWatch logs. We need it to: (a) refund manually to the right wallet if a settled run is disputed, (b) prove on-chain provenance during accounting reconciliation, and (c) feed the rate-limit fingerprint below. The wallet address is already public the moment any transaction touches the chain — we don't treat it as a secret, but you should know we record it.
Caller fingerprint — sha256(wallet || user-agent), truncated to 8 bytes (16 hex chars). Used only to enforce the per-caller daily USDC spend cap (clause 04 of the Terms). Kept in a separate DynamoDB table with a ~36h TTL after the day it was created; we do not link it back to a wallet address in any other store.
User-agent header — the standard HTTP one your client sends. Used as one input to the fingerprint above and in request logs.
On-chain transaction hashes — when we settle a payment, we store the Base mainnet/Sepolia tx hash on the Job. If we manually refund USDC, we store the outbound tx hash too. Both are public on the chain regardless; we keep them so the audit trail is complete on our side.
x402 authorization payload — what you signed (nonce, amounts, validBefore window). We pass this to the Coinbase facilitator at verify and settle time, and we keep it on the Job row until settle so we can broadcast after delivery. See clause 04 of the Terms for the settle-on-success mechanic.
Per-job access token — a 122-bit random token returned to your agent in the /run response, required on subsequent /runs/{id} polls. It's a bearer credential for that one Job's status — treat it like an API key for that specific receipt. Stored on the Job row alongside everything else.
Using botx402 through an AI assistant (MCP connector)
Our MCP server (https://api.botx402.io/mcp) lets an AI assistant such as Claude run a bot for you. You add it as a connector; there is no sign-in. The assistant calls our tools on your behalf, and what it sends us is what you shared with it for that purpose.
What we receive: the bot's inputs (for example the SKU sales and stock figures for a reorder plan) when the assistant checks them or starts a run; your email address when it starts a run; and the name and version your assistant's software reports (for example "claude-ai/1.0") and its user-agent.
How it's used. Checking inputs (validate) is free and nothing is stored: the inputs are checked and the answer is sent back. Starting a run (start) stores nothing until it has validated your inputs, then stages them in our storage bucket, creates a Stripe Checkout Session with your email, and writes a job record. The tool never charges anyone: you pay, or not, by opening the Stripe link yourself. Once you pay, the run proceeds exactly as a website checkout does (sections 01, 05 and 06).
Results: when the assistant asks for a finished run (get_run, which needs the access token returned when the run started), we return the report's JSON result and download links that work for 7 days. What we return goes into your conversation with the assistant and is then handled under that assistant provider's terms, not ours.
Limits: a checkout started through the assistant counts against a daily allowance keyed on a keyed hash of your email address (never the address itself), kept about 36 hours.
Logs: for each call we log the tool step (connect, list tools, validate, checkout started), a daily-rotating hash of IP address and user-agent, the user-agent, the assistant software's name and version, and the receipt ID once there is one. Never your inputs, your email address or your access token.
What we don't collect
We don't run third-party tracking pixels (no Facebook Pixel, no Google Analytics, no LinkedIn Insight Tag).
We don't fingerprint your browser, build a profile, or share you with ad networks.
We don't ask for a phone number or your company's structure beyond what you choose to put in your email address.
We don't store your card details. Stripe does — we never see them.
We don't keep marketing or newsletter lists. The emails you'll receive in connection with botx402 are: (a) your Stripe payment receipt, sent by Stripe, (b) where available, a link to your finished report, and (c) responses from us to support requests you start.
How long we keep things
Inputs staged for a card checkout (website or AI assistant): stored in our storage bucket while you pay, and deleted automatically after one day (the superseded stored version is removed a day after that). If you never pay, that is the end of it.
Your input data during a run: in the job queue (up to 4 days if a run is retried) and in memory until the run finishes, and not kept after delivery. A run that fails repeatedly moves to a dead-letter queue, where it is deleted after 14 days at the latest.
Report files (PDF and, for bots that produce one, JSON): kept encrypted at rest for 90 days, then deleted; the stored copy is purged 30 days after that. They contain the figures you sent. They are reached through your /results URL, which is gated by a per-Job access token (the `&t=…` — see section 02), or by your AI assistant with the same token. Each request creates a fresh download link that works for 7 days. Download a local copy if you need it longer than 90 days.
Receipt PDF (sale record from Arnhem Labs Pty Ltd): same lifecycle as the report files — encrypted at rest, deleted after 90 days. Download a local copy if you need it for tax or accounting records for longer.
Job record (receipt ID, status, timestamps, customer email, payer wallet for agent runs, settlement and refund tx hashes, references to the report and receipt PDFs, the per-Job access token, and whether it came through the AI assistant connector): kept for refund support, on-chain reconciliation and accounting. Job records are not deleted automatically; we delete yours when you ask, except where we must keep a record of a sale for tax purposes.
Rate-limit counters (hashed, see sections 01 to 03): about 36 hours after the UTC day they count against, then removed automatically.
Do-not-email list: if an email we send you bounces or you mark it as spam, we keep that address on a suppression list so we don't email it again. It is not deleted automatically; ask us to remove it.
Logs: server logs 90 days, fulfillment logs 30 days (7 days for both in our test environment). Wallet addresses appear in agent-flow log lines and roll off on the same schedule.
If you ask us to delete you sooner, we will — write to hello@botx402.io.
Who we share with
Stripe — to take card payments. Stripe receives your email and card details; it sends us the confirmation and session id.
Coinbase x402 facilitator (facilitator.x402.org) — for agent runs only. We POST your signed authorization payload + the route's payment requirements to them at verify time, and again at settle time after delivery. They broadcast the USDC transfer to Base on our behalf. We never hold private keys; the agent signs, the facilitator broadcasts.
Base mainnet / Sepolia public RPC — for agent runs only. The facilitator submits transactions to the chain; the resulting tx hashes are public on Basescan. We don't operate our own RPC node.
AWS — to host the service, store run data and logs, and send our emails (Amazon SES sends the report-link email to your address). Anything we store is encrypted at rest.
Your AI assistant's provider (for example Anthropic, for Claude) — only if you use our MCP connector: the results your assistant fetches go into your conversation with it (see section 03).
Plausible — privacy-friendly page-view analytics on botx402.io, with no cookies and no personal identifiers.
Cloudflare — DNS for botx402.io.
We don't share your data with anyone else. We don't sell, rent, or syndicate.
Where the data lives
All run data, encrypted tokens, and PDFs are stored in the United States.
We're an Australian-based business. By using the service you're agreeing to your data being processed and stored in the US.
We rely on standard contractual clauses where applicable.
On-chain data (USDC settlement and refund transactions) is, by definition, public and replicated worldwide once written to Base. We have no control over it after broadcast.
Your rights
You can request a copy of any data we hold about you, request deletion of all of it, or correct anything that's wrong. Email hello@botx402.io.
We aim to respond within 30 days. Australian residents have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles; UK and EU residents have rights under UK GDPR / GDPR; California residents have rights under CCPA. We'll honour them either way.
On-chain transactions (settlements, refunds) cannot be erased — they're public records of the chain. Deletion requests cover only what we hold off-chain.
Security
All traffic to and from the site is HTTPS (TLS 1.2+). The DynamoDB table holding run records is encrypted at rest with a per-environment AWS KMS key.
Card data is handled by Stripe (PCI Level 1) — we never see it.
For blockchain payments: agents sign the authorization client-side, the Coinbase facilitator broadcasts it on-chain. We don't sign on behalf of any customer wallet and never custody customer funds. We do operate one recipient wallet on Base mainnet — its private key is held by Arnhem Labs Pty Ltd directly, under standard hot-wallet hygiene (separate device, offline seed backup, no shared access), and is used solely to send manual outbound USDC for disputed-run refunds.
If we ever discover a breach affecting your data, we'll email everyone affected within 72 hours of confirmation.
Cookies
We don't use cookies for tracking. The site works without them.
On checkout, Stripe sets cookies necessary for the payment flow — these are first-party to checkout.stripe.com and are out of our control.
Children
The service is not directed at anyone under 18. If we learn we've collected data from a child, we'll delete it.
Changes
If we materially change this notice we'll update the "effective" date at the top.
Contact
Privacy questions, deletion requests, security reports, anything else: hello@botx402.io. We read every email. Arnhem Labs Pty Ltd, Australia.