Privacy Policy
1. Who we are
Arcapis operates a gateway that meters and forwards calls to third-party AI APIs, settled in USDC on Arc. This policy covers arcapis.com, the dashboard, and the HTTP gateway.
For the data described below we act as the controller. Where a request is forwarded to an upstream AI provider, that provider is an independent controller of what it receives and applies its own policy.
2. What we collect
| Data | When | Why |
|---|---|---|
| Wallet address | When you connect a wallet or transact | Verify packet ownership on every call; show your packets and history |
| Request content | Every gateway call | Forward to the upstream provider; compute the cache key |
| IP address and user agent | Every request to the site or gateway | Serve the site, rate-limit, detect abuse. Written to server logs by our host |
| Usage counts | Every paid call and every reuse of a cached answer | Aggregate statistics: calls per hour, how often answers are reused, and by how many wallets. Stored with a one-way hash of the wallet, not the address |
| Email address | Only if you join a waitlist or sign in with email | Notify you about the feature you asked about; create your embedded wallet |
| IP + user agent with a waitlist signup | When you submit a waitlist form | Spam and abuse prevention |
| One-way hashes of your email address and IP | When you request an email sign-in code, use an email wallet, or join a waitlist | Limit how many requests can be made. The email and IP themselves are not stored in these records |
| One-way hash of your embedded wallet address | When you sign in with email | Tell email wallets apart from other wallets, so maintenance can pause one kind without the other |
| Google account identity | Only if you choose Google sign-in | Passed to Circle to create and unlock your embedded wallet |
| Transaction metadata | When you buy, transfer, list, or sell | Show status and history. Also published on-chain by the network itself |
3. What we do not collect
- No private keys, seed phrases, or recovery material. We never ask for them, and no part of the Service has a field to enter them.
- No payment card or bank details. Payment is on-chain in USDC.
- No third-party advertising or cross-site tracking. There is no ad network, no advertising pixel, and no cross-site profiling on this site.
- No accounts with passwords. There is nothing to breach.
4. Public and permanent data
This is where Arcapis differs most from a normal web service, so it gets its own section.
4.1 The shared cache on IPFS
For endpoints in cacheable categories, unless you turn the cache off for a call, the gateway encrypts the upstream response and pins it to IPFS, keyed by a hash of your request, and commits new entries to a public smart contract in batches (once 16 are waiting, or within 24 hours), with the batch list also on IPFS. IPFS is a public, content-addressed, peer-to-peer network. Consequences:
- Anyone can retrieve the encrypted content. The key is derived from the request itself, so anyone who sends — or can guess — the exact same request can read the response.
- Other nodes may copy and re-pin it independently of us.
- We cannot reliably delete it. Unpinning from our provider does not remove copies elsewhere.
- The cache key deliberately excludes your wallet address — that is what makes results reusable — so an identical request by any other user returns your cached result.
- The gateway also keeps its own copy of each cached response, encrypted the same way, with our hosting provider, to serve reuses quickly.
Never submit names, addresses, contact details, government identifiers, health or financial
information, API keys, passwords, private business data, or anyone else’s personal
data to a cacheable endpoint with the cache on. If you need confidentiality, send the call
with the header X-Arcapis-Cache: off — its response is then neither stored nor
shared — or use a non-cacheable category.
Which categories are cached:
| Category | Pinned to IPFS | Kept for |
|---|---|---|
| VECTOR (embeddings) | Yes | 30 days after its last use, at most 90 days |
| DATA (scraping) | Yes | 30 minutes |
| LLM | No | — |
| IMAGE | No | — |
| AUDIO | No | — |
Each reuse of an embedding renews it, up to 90 days after it was stored. When an entry runs out, we delete our copy and unpin it from our provider; copies other IPFS nodes made may remain. We may change categories and windows; check this page for the current policy before submitting sensitive material.
4.2 On-chain data
Every packet purchase, transfer, listing, and sale is a public blockchain transaction. Your wallet address, the endpoint you bought, the quantity, the price, and the timestamp are permanently readable by anyone, and are indexed by block explorers we do not control. Blockchain records cannot be edited or erased. A wallet address is pseudonymous, not anonymous: if it is ever linked to you, its whole history is linked to you too.
5. Why we process it
Where GDPR or a similar regime applies, our legal bases are:
- Contract — processing your wallet address, request content, and transactions to deliver the service you paid for.
- Legitimate interests — server logs, rate limiting, moderation, and abuse prevention, to keep the gateway usable and to avoid losing our upstream accounts.
- Consent — waitlist emails, and sending content to a cacheable endpoint with the cache on, knowing it will be published. You can withdraw consent for waitlist email at any time; consent to publish cannot be undone once content is on IPFS.
- Legal obligation — sanctions screening and responding to lawful requests.
We do not sell personal data, and we do not use it to train models.
7. How long we keep it
| Data | Retention |
|---|---|
| Server and function logs | As long as our host retains them, typically weeks |
| Waitlist email | Until you ask us to delete it, or the feature ships and the list is retired |
| Usage counts | Kept to report usage over time; they hold a wallet hash, never an address |
| Rate-limit records (hashes) | Up to two hours |
| Email-wallet marker (hash) | While the service runs; it identifies no one on its own |
| The gateway’s own copy of cached responses | Deleted when the entry runs out (section 4.1); earlier on request |
| Cached content on IPFS | Unpinned by us when the entry runs out; copies other nodes made are outside our control |
| On-chain records | Permanent — cannot be deleted |
| Browser local storage | Until you clear your browser data |
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port your personal data, and to complain to a supervisory authority. To exercise them, email contact@arcapis.com.
We can delete what we control: waitlist entries, any support correspondence, and the gateway’s own copy of a cached response, which we also unpin from our provider. We cannot delete blockchain transactions or content already pinned to IPFS — no operator can. If that limit is unacceptable to you, do not submit personal data to a cacheable endpoint with the cache on, and do not transact from a wallet linked to your identity. We tell you this in advance rather than promising an erasure we cannot deliver.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against anyone for exercising their rights.
9. International transfers
Our infrastructure and the third parties listed in section 6 operate globally, so your data is processed outside your country, including in the United States. Where required, transfers rely on Standard Contractual Clauses or an equivalent mechanism offered by the provider. Data published to a blockchain or to IPFS is, by design, available worldwide with no transfer mechanism possible.
11. Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has used the Service, contact us and we will delete what we control.
12. Security
Traffic is served over HTTPS. Upstream API keys are held server-side and never reach the browser. Each gateway call is authorised by a fresh short-lived EIP-712 signature rather than a long-lived token, so a leaked signature is worth one call rather than a whole packet.
No system is perfectly secure, and the smart contracts are unaudited. Protecting your own keys and sign-in credentials is your responsibility.
13. Changes
We may update this policy. The “Last updated” date changes when we do, and material changes — especially any change to what gets cached publicly — will be announced on the site.
14. Contact
Privacy questions and rights requests: contact@arcapis.com.
See also the Terms of Use, particularly section 6 on the shared cache and section 12 on risk.