Privacy policy
Last updated May 12, 2026
This privacy policy explains how Openusdc, Inc. ("Openusdc", "we", "our", "us") collects, uses, retains, and protects personal data when you visit openusdc.ai and when you use the Openusdc service. We have written it in plain English on purpose. If anything below is unclear, write to support@openusdc.ai and we'll do our best to clarify.
Who we are
Openusdc is a Delaware C-corp. We act as the data controller for personal data collected through our marketing site and service, and as a data processor for personal data you choose to push into the service as part of operating your workspace.
The short version
- We collect what we need to operate the site and the Cloud service, and not much else. We do not sell personal data, ever.
- The SDKs do not phone home beyond the API calls your agent makes.
- Workspace data is encrypted at rest with AES-256-GCM and in transit with TLS 1.3.
- We retain audit logs for one year, billing records for seven years (because we have to), and most other personal data for the lifetime of your account plus 30 days.
Categories of data we collect
We group personal data into five categories. The category determines how long we keep it, who at Openusdc can see it, and what we do with it.
1. Account data
If you sign up for an Openusdc account, we collect your name, email address, password hash (Argon2id), workspace name, and any optional profile information you provide. We also collect technical metadata about the account — when it was created, when it was last used.
2. Operational data
When your agents make payments through Openusdc, we collect settlement metadata: the route a payment settled against, the chain it settled on, the destination wallet address, the amount, the trace ID, and the signed receipt. We do not see the contents of the underlying request or response — only the metadata used to reconcile and report on payments.
3. Telemetry
We collect aggregate usage telemetry — page loads, response times, error counts. We use Plausible Analytics, which is cookieless and does not collect IP addresses in any form we can read.
4. Communications data
When you write to us — support tickets, sales conversations, security disclosures — we keep the threads and any attachments.
5. Marketing data
If you opt in to our newsletter, we keep your email address and the history of which issues we sent you. You can opt out by emailing support@openusdc.ai.
Why we process this data
We process personal data only as necessary to operate and improve the service, respond to your communications, and meet our legal obligations. Marketing communications are sent only with your opt-in consent.
- Service operation — account data, operational data, communications about your account.
- Security and stability — telemetry, abuse prevention, security monitoring, audit logs.
- Consent — marketing emails, voluntary product research interviews.
- Legal obligation — financial recordkeeping and sanctions screening when applicable.
Who we share data with
We share personal data only with vendors who help us operate the service. The current list is:
- Amazon Web Services — primary hosting
- Cloudflare — edge network and DDoS protection
- Stripe — billing and tax reporting for subscriptions
- Plausible — privacy-respecting site analytics
We do not share personal data with any other third party. We do not sell personal data. We do not run advertising on our site.
Where we keep data
Personal data is stored in the region where your workspace is hosted. We do not replicate workspace data outside its assigned region.
How long we keep data
- Account data — for the lifetime of your account plus 30 days
- Operational ledger data — 13 months by default, or until you delete your workspace
- Telemetry — 30 days, anonymized
- Audit logs — 12 months
- Communications — 24 months after the conversation closes
- Billing records — seven years, as required by U.S. tax law
Your rights
You have the right to access, correct, export, and delete the personal data we hold about you. You also have the right to object to processing based on our legitimate interests, to restrict processing, and to lodge a complaint with your data protection authority. To exercise any of these rights, write to support@openusdc.ai. We verify identity before acting on a request and aim to respond within 14 days.
Cookies
We use a single first-party session cookie on the marketing site and in Cloud. We do not use third-party cookies, advertising pixels, or cross-site tracking. Our cookieless analytics provider is Plausible (open-source, EU-hosted).
Security
Data is encrypted at rest with AES-256-GCM and in transit with TLS 1.3. Engineering access uses single sign-on with FIDO2 keys; production access uses short-lived, purpose-scoped credentials recorded in our audit log. We publish independent audit reports under /security.
Children
Openusdc is not intended for children under 16, and we do not knowingly collect personal data from children. If you believe a minor has provided us with data, write to support@openusdc.ai and we'll remove it.
Changes to this policy
We may update this policy when we add features, change vendors, or when the law changes. Material changes are posted here and announced in our changelog at least 14 days before they take effect.
How to reach us
Email support@openusdc.ai.