Version 2026-09-26. This policy covers `https://cloud.trycorpus.ai`: the API, the hosted and
local MCP servers, the charts and the reference pages, operated by Julian
Traversa, trading as corpusAI (**corpusAI**, **we**). It describes what the
service records about a caller and why. The short version: no account is
needed (pay per call over x402 or MPP, or use a prepaid key), and there are
no cookies and no tracking. The service keeps the operational records needed
to serve, meter and secure paid calls, the records of any prepaid key, and
nothing else.

## What is recorded

- **Request logs.** Method, path, response status, timing and the
  `User-Agent` header of each request, kept in the hosting provider's log
  stream for operations and abuse handling. Query parameters appear in the
  log only for failed requests (status 400 and above) and for non-GET
  requests. Client IP addresses are visible to the hosting provider's edge
  (Fly.io) as part of ordinary connection handling; the application itself
  does not store them.
- **Payment records.** For x402 and MPP payments, the payer address, network,
  amount, resource path and settlement transaction are processed to verify
  and settle the payment; the settlement itself is a public blockchain
  transaction.
- **Prepaid keys.** The key itself is never stored: only its SHA-256 hash and
  its first characters, so a key can be recognized in support requests.
  Beside them we keep a label and optional notes set when the key is issued
  (for example who asked for it), the balance, amount spent and call count,
  the creation, expiry and last-use times, and a ledger of charges (time,
  path, amount), refunds and credits.
- **Card top-ups.** Card payments are processed by Stripe under Stripe's own
  privacy policy; card details go to Stripe and never reach us. The service
  receives the checkout session id and the credited amount, and records the
  session id on the credit. The checkout page shows the key's first
  characters and label so you can see which key is credited.
- **Contact.** If you email us, we keep the correspondence.

## What is not recorded

No sign-up forms, cookies, local storage, analytics scripts, tracking pixels
or advertising identifiers. The charts and pages load fonts and one
video from corpusAI's own domain and Google Fonts; no other third-party
resources are loaded.

## MCP servers

The hosted MCP server at `https://cloud.trycorpus.ai/mcp` forwards each tool call to the same
API in the same process, with the bearer key you send, and stores nothing
beyond the request logs, payment records and key records above. Tool inputs are query
parameters (instance types, regions, tickers) and never personal data. The
local MCP package runs on your machine; a wallet key given to it never
leaves your machine, and it signs payments locally.

## Use and sharing

Records are used to serve requests, meter and refund charges, detect abuse
and enforce the [data license](https://cloud.trycorpus.ai/license). They are not sold, and
they are shared only with the providers needed to run the service: Fly.io
(hosting and logs), Cloudflare (archive storage and backups of the key
records), Stripe (card payments), Circle and Coinbase (x402 payment
facilitators), and the public blockchains on which payments settle.

## Retention

Request logs are kept for the hosting provider's default window, currently
days, not months. Key ledgers are kept for as long as the key exists and for
accounting afterwards. Blockchain settlements are permanent by nature.

## Your rights and contact

You may ask what we hold about a key or an address you control, or ask for
a key and its ledger to be deleted, by writing to
[hello@trycorpus.ai](mailto:hello@trycorpus.ai). corpusAI may change this
policy by publishing a new version at `https://cloud.trycorpus.ai/privacy`.
