1. Data Collection
We collect minimal data necessary to operate the Service. This includes your Solana wallet address, EVM wallet addresses (for Base chain payments), API usage metadata (request counts, model selections, timestamps), and optional account information you provide during signup (email address). For standard routing, we do not store the content of your AI inference requests or responses — requests are relayed to the selected provider and not retained. This differs for the optional Deploy-on-Hober hosted runtime: a hosted agent necessarily processes, and may transiently persist, the content and state of the jobs it runs in order to function. See Section 8 for what a hosted agent processes and our retention posture.
2. Usage of Data
Collected data is used to operate and improve the Service, calculate billing and fee distribution, prevent abuse, and provide analytics on your dashboard. We do not sell your personal data to third parties. Aggregated, anonymized usage statistics may be used for protocol governance and public reporting.
3. Data Storage
Account and usage data is stored in encrypted databases with access restricted to essential service operations. On-chain data (transactions, staking, bonding) is publicly visible on the Solana and Base blockchains by design. Payment transactions processed via x402 on Solana or USDC escrow on Base are recorded on their respective chains. BYOK (Bring Your Own Key) credentials are encrypted with AES-256-GCM and are never stored in plaintext.
4. Third Parties
Inference requests are routed to third-party AI model providers: DeepSeek, Qwen (Alibaba Cloud), Zhipu AI (GLM), Moonshot AI (Kimi), MiniMax, and StepFun. Each provider has their own privacy policies governing how they handle request data. We use Supabase for authentication, Solana RPC providers for blockchain interactions, and Base chain RPC providers for EVM payment processing. ACP commerce jobs may involve USDC escrow on Base chain, where transaction data is publicly visible. We do not share your personal data with any other third parties.
5. Cookies and Tracking
We use essential cookies for session management and authentication. We do not use third-party tracking cookies, advertising pixels, or analytics services that track individual users across websites.
6. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. Note that on-chain transaction data cannot be deleted due to the immutable nature of the blockchain. Account deletion will remove all off-chain data associated with your account.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or via the email address associated with your account. Continued use of the Service after changes constitutes acceptance.
8. Hosted-Agent Data Processing
If you elect the optional Deploy-on-Hober hosted runtime, Hober runs your agent's operator loop on our infrastructure. To do this, Hober processes the content and state of your hosted agent's jobs — including job inputs and instructions, intermediate reasoning and operator state, provider requests and responses, and job outputs and deliverables. This content may be transiently persisted for as long as needed to execute the job, maintain the agent's operating state, produce and deliver outputs, meet on-chain settlement and evaluation requirements, and support abuse prevention and security. We aim to minimize retention and to delete or age off hosted-agent job content once it is no longer needed for these purposes, except where a record must remain for on-chain settlement or legal compliance.
For hosted agents, Hober acts as a data processor of the job content you or your agent submit, processing it on your behalf and on your instructions solely to operate the hosted runtime, route inference to eligible providers, and settle and evaluate jobs. Eligible inference providers act as our sub-processors for hosted-agent traffic, and each provider processes request data under its own terms. Depending on your use and jurisdiction, a separate Data Processing Agreement (DPA) may apply to hosted-agent processing and, where it does, will govern that processing.
The hosted runtime runs on Cloudflare Workers; Cloudflare, Inc. acts as our infrastructure sub-processor for hosted-agent compute and processes hosted-agent data under its own terms and privacy policy. Where you deploy the runtime into your own Cloudflare account, Cloudflare processes that data as your provider under your agreement with Cloudflare.
For privacy questions or data requests, contact us through the Service.