SSeedhape← Back to Seedhape
LEGAL / PRIVACY

Privacy
Policy.

This Privacy Policy explains how Seedhape collects, uses, and protects information when you use the Seedhape control plane, agentic payment tools, MCP connection, and related services.

Effective date: September 11, 2026

1. Information we collect

Account and sign-in information. If you choose Google sign-in, Seedhape receives the Google account’s stable subject identifier, email address, and display name returned by Google after you authorize the requested OpenID Connect scopes. We do not receive or store your Google password. If you choose MetaMask, we receive the public wallet address and the signed authentication message needed to prove control of that address.

Service and transaction information. We store account-scoped mandates, policy limits, MCP tokens, payment attempts, settlement records, wallet addresses, consent records, and audit metadata needed to provide and secure the service. We do not store private keys in plaintext.

Technical information. We receive ordinary request, security, and diagnostic information such as timestamps, browser/network metadata, and error logs. Essential HTTP-only cookies maintain sign-in and OAuth security state.

2. Google API Services disclosure

Seedhape’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

  • Google data is used only to authenticate you, create or access your Seedhape account, display your account identity, and provide the Seedhape services you request.
  • We do not sell Google user data, use it for advertising, or use it to build advertising profiles.
  • We do not transfer Google user data to data brokers or unrelated third parties.
  • We do not use Google data for purposes unrelated to the requested Seedhape functionality.
  • We request only the OpenID Connect scopes required for identity, email, and profile display.

3. How we use information

We use information to authenticate accounts, maintain secure sessions, provision and operate requested managed agent wallets, enforce mandates and spending limits, process MCP connections, record payment and audit events, prevent abuse, provide support, and comply with legal obligations.

Signing in does not itself authorize a payment. Payment mandates, wallet signatures, funding transfers, and third-party checkout actions are separate user-controlled events.

4. Managed wallets and providers

Google onboarding can create encrypted managed authorization and agent-wallet records when the service is configured for custody. The agent wallet is used only within the limits of an authorization you approve. Base USDC purchases may be offered through third-party providers such as thirdweb. Those providers process their own payment, identity-verification, and transaction data under their respective policies; Seedhape does not receive your fiat payment credentials or KYC documents from them unless expressly stated in a provider flow.

5. Sharing and service providers

We share information only with providers needed to operate requested functionality, such as hosting/database services, authentication infrastructure, blockchain RPC/facilitator services, custody providers, and payment/on-ramp providers. We may disclose information when required by law, to protect users and the service, or in connection with a corporate transaction. We do not sell personal information.

6. Retention, security, and your choices

We retain account, mandate, payment, and audit records for as long as needed to provide the service, resolve disputes, meet security and accounting requirements, and comply with law. OAuth transaction cookies expire shortly after completion; the Seedhape browser session normally expires after 12 hours; MCP access tokens have their displayed expiration and can be revoked.

You can sign out, revoke MCP access, revoke mandates, disconnect Google access from your Google Account security settings, or request account/data deletion. Deletion may be limited where records must be retained for legal, fraud-prevention, payment, or audit purposes.

7. Contact

For privacy questions, Google data requests, or deletion requests, contact privacy@seedhape.com. Please do not include private keys, recovery phrases, or payment credentials in a support request.