Privacy.

What we collect, why, and the one thing on this network that cannot be deleted.

Effective 22 September 2026 · IOAI Global, Washington, DC · [email protected]

The short version

If you read this website, we collect very little. If you write to us, we keep what you sent so we can reply. If you transact on the network, some of what you do is recorded permanently and publicly, and nobody — including us — can remove it. That last point is the one worth reading properly, and it is in section 4.

1. Who we are

IOAI Global, of Washington, DC, is the controller of personal data described in this policy. Write to us at [email protected] about anything in it.

2. What we collect

  • Visiting this site. Our host records standard server logs: IP address, user agent, the page requested and the time. We use these for security and to understand traffic volume. We run no analytics product, set no cookies and embed no trackers.
  • Writing to us. Your name, email address, organisation if you give one, and the contents of your message. We use it to reply and to keep a record of the conversation.
  • Holding a licence or operating a node. Identity, billing and operational contact details, as required to administer the licence and meet our legal obligations. The agreement governing your licence describes this in full and takes precedence for licensed participants.
  • Calling the API. Request metadata, and the identity presented where one is required. Verification and identity-resolution endpoints require no credential, and we make no attempt to identify who is calling them.

We do not buy personal data, we do not sell it, and we do not use it to train models.

3. Why we are allowed to hold it

  • To answer you. Where you contact us, we rely on our legitimate interest in responding, or on steps taken at your request before entering a contract.
  • To run the service. Where you hold a licence, we rely on performance of that contract.
  • To keep the network secure. We rely on our legitimate interest in preventing abuse, and on our legal obligations.

4. The part that is permanent

Attestations, settlement records and anchored measurements are designed to be verifiable by anyone, indefinitely, without our involvement. That is the product working as intended, and it has a consequence we will not soften: once a record is anchored, we cannot delete it, amend it, or make it unverifiable. Neither can you.

Anything placed in a job specification becomes part of a record that outlives your relationship with us. Do not put personal data, credentials, or anything you may later need erased into a specification. Treat a specification the way you would treat a public filing.

Where data protection law gives you a right to erasure, that right cannot be exercised against an anchored record, and we will not pretend otherwise. We will erase what we hold off-chain, and we will tell you plainly which parts we cannot reach. If you need a design where nothing is permanent, this network is the wrong choice and we would rather say so before you build on it.

5. Who else sees it

We use service providers to host this site, deliver our email and manage support correspondence. They process data on our instructions and are not permitted to use it for their own purposes. We will name our current providers on request — ask at [email protected] and you will get a list, not a description.

Beyond those providers, we disclose personal data only where we are legally compelled. Where we are permitted to tell you that a disclosure was demanded, we will.

6. Where it goes

We are based in the United States and our infrastructure is operated on globally distributed networks, so data you send us is processed in the United States and may be processed elsewhere. Where we transfer personal data out of the European Economic Area or the United Kingdom, we do so under the European Commission’s Standard Contractual Clauses and the UK Addendum.

7. How long we keep it

Correspondence: as long as needed to deal with your enquiry and to keep a reasonable business record of it. Server logs: a short period for security and diagnostics. Licence and billing records: as long as the relationship lasts, and afterwards for as long as tax, accounting and limitation periods require. Anchored records: permanently, as section 4 describes.

8. Your rights

Depending where you live, you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to receive a copy in portable form, to object to or restrict how we use it, and not to be discriminated against for exercising any of those rights. Write to [email protected]. We will respond within thirty days, and sooner where the law requires it.

We do not sell or share personal information as those terms are defined under California law, and we do not use it for cross-context behavioural advertising.

If you are in the European Economic Area or the United Kingdom and you think we have handled your data badly, you may complain to your national supervisory authority. We would rather you told us first, but it is your call and you do not need our permission.

9. Cookies and fonts

This site sets no cookies and loads no third-party trackers. It does load typefaces from Google Fonts, which means Google receives the IP address of visitors in order to serve those files. Nothing else about your visit is shared with them.

10. Children

This is infrastructure for machine-to-machine commerce. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen.

11. Changes

If we change this policy we will update the effective date above. Where a change materially affects how we handle data you have already given us, we will say so here rather than rely on you noticing a date.