01Summary
- Prompts and responses are never stored.
- We keep billing metadata: model, token counts, cost and timing.
- You sign in with a wallet. Email is optional.
- One session cookie. No tracking cookies, no third-party analytics.
- We do not sell personal data.
This policy covers aggregat.xyz and the Aggregate API. “We” means the team that operates Aggregate.
02Prompts and responses
Zero data retention. Prompts, completions, embedding inputs and generated images pass through our servers in memory. They are never written to disk, logs, analytics or backups.
To answer a request we have to send it to OpenRouter and the model provider you chose, which process it under their own privacy policies. We apply the provider's data-retention controls where they are offered. Check a provider's policy before you send it sensitive data.
03What we collect
- Billing metadata, per request: API key id, model, endpoint, prompt and completion token counts, upstream cost, amount charged, discount applied, gateway and upstream latency, and the time.
- Account: the wallet addresses you verify by signature, an internal user id, your email and display name if you add them, your referral code and who referred you, your balances, and for each API key its label, spending limit, a hash and the first 12 characters.
- Transactions: purchases, orders, activations, stakes and launches, with amounts and Solana transaction signatures.
- Server logs: IP address, requested path, status code and user agent, kept for security and abuse prevention. Request bodies are never logged.
04Wallet addresses and email
A wallet address is a public identifier: what it does on Solana is visible to everyone, with or without us. We link the addresses you sign in with to your account. Signing the sign-in message costs nothing and gives us no access to your funds. We never ask for a private key or seed phrase.
Email is optional. If you add one, we use it only to contact you about your account and the service, never for advertising, and we do not share it for marketing.
06Analytics
None from third parties: no analytics scripts, advertising pixels or fingerprinting. The public numbers on /analytics are aggregates computed from billing and on-chain data and identify no one. If we add product analytics, it will be self-hosted, cookieless and aggregate, and this page will say so before it goes live.
07Third parties
We share data only with the services needed to run the product, and we never sell it.
- OpenRouter and model providers receive the content of your requests to answer them.
- Solana RPC providers see wallet addresses, transactions and IP addresses when your wallet or our servers read from or write to the chain.
- StonkFun processes token launches, trades and holder rewards through its public API and on-chain programs.
- Hosting and database providers store account and billing data on our behalf.
We may also disclose data when the law requires it, or to protect the service and its users from fraud and abuse.
08Data retention
- Prompts and responses: not retained.
- Account, billing and transaction records: while your account is open, then only as long as accounting, tax and anti-fraud obligations require.
- Sessions: 30 days at most, deleted when you sign out. Sign-in nonces expire after 5 minutes.
- Server logs: rotated and deleted within 14 days.
- On-chain data: permanent and public by design. Nobody, including us, can delete it.
09Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA), you can ask to access, correct, export or delete your data, object to or restrict its processing, and withdraw consent for optional uses such as email. You can also complain to your local data protection authority.
Write to hello@aggregate.xyz. We verify a request by asking you to sign a message with a wallet linked to the account, and we answer within 30 days. Deleting an account removes your email, display name, wallet links and API keys; records we must keep for accounting stay without them.
10Security
API keys are stored only as hashes, the session cookie cannot be read by scripts, and all traffic is encrypted with TLS. No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.
11Children
The service is not for anyone under 18, and we do not knowingly collect their data.
12Changes to this policy
We update this page when our practices change. The date at the top shows the current version, and material changes are announced on the website.
13Contact
Anything about privacy or your data: hello@aggregate.xyz. The data controller is the legal entity that operates Aggregate; its name and address will be published here before launch.