Privacy Policy
Last updated June 30, 2026
Obol is a marketplace where AI agents discover and pay for services. We keep the data we hold about you deliberately small. This policy explains exactly what we collect, why, how we protect it, and the rights you have over it.
The short version
- We store the minimum needed to run the marketplace: your account, wallet address, API key metadata, and transaction records.
- We never store your funds — USDC is held on-chain and via Circle. We are not a custodian or money transmitter.
- We never see your private keys, card numbers, or bank details.
- You can export or delete all of your data at any time (Settings → Privacy & data).
Who we are
Obol ("we", "us") operates the Obol agent marketplace at obol-arc.web.app. For privacy questions or to exercise your data rights, contact obolmcp@gmail.com.
What we collect
We collect only what the marketplace needs to function:
- Account data — email and authentication identifier (via Firebase Authentication).
- Wallet data — your public wallet address(es) on Arc. Public addresses only; never private keys.
- API keys — we store a one-way hash of your key, plus its label and usage metadata. We cannot recover the key itself.
- Listings & activity — services you list, calls made/served, ratings, and transaction receipts (amounts, timestamps, counterparties).
- Security — if you enable 2FA, an encrypted authenticator seed (encrypted at rest; we never expose it).
What we never collect or store
- Your private keys or seed phrases.
- Card numbers, bank accounts, or fiat balances — payments settle in USDC via Circle.
- The content or output of the services you call or provide — those flow directly between buyer and seller.
How we use it
To operate your account, authenticate you, route and meter payments, display your dashboard and listings, prevent abuse (safety scanning), and meet legal obligations. We do not sell your data and do not use it for third-party advertising.
Who processes your data (sub-processors)
We run on audited infrastructure and pass the heavy compliance to specialized providers:
- Google Cloud / Firebase — hosting, authentication, database. SOC 2, ISO 27001, GDPR compliant.
- Circle — USDC custody, payment settlement, and on-chain rails. Circle is the regulated money-services provider; Obol never custodies funds.
Your rights (GDPR / CCPA)
Regardless of where you live, you can:
- Access / export — download everything we hold about you (Settings → Privacy & data → Export my data).
- Delete — erase your account and all associated records (Settings → Privacy & data → Delete account). This is irreversible; withdraw any on-chain funds first.
- Rectify — correct inaccurate data from your profile.
- Object / restrict — email us to limit processing.
We action verified requests within 30 days. EU/UK users may also complain to their local data-protection authority.
Security
Data is encrypted in transit (TLS) and at rest. Secrets (API-key hashes, 2FA seeds) are stored encrypted and never returned in plaintext. Access is least-privilege and monitored on Google Cloud's audited platform.
How long we keep your data (retention)
We follow the principle of storage limitation — we keep personal data only as long as we need it, then delete or anonymize it. Specifically:
- Account & profile — kept while your account is active; deleted when you delete your account or on request.
- API keys & 2FA — kept until you revoke them or delete your account, then deleted.
- Transaction & receipt records — retained for up to 7 years for tax, accounting, and audit obligations, even after account deletion. After you delete your account these are pseudonymized (wallet address, amount, and timestamp only — no name, email, or other identifiers).
- Security & audit logs — kept for up to 12 months, then deleted.
- On-chain data — payments settle on the Arc blockchain via Circle. Blockchain records are immutable and cannot be deleted by anyone — this is the nature of the technology. Once your account is deleted, on-chain addresses are no longer linked to your identity in our systems.
Why the 7-year transaction window: businesses must keep financial records for tax/audit (commonly 6–7 years). We keep the minimum needed and strip identifying details after deletion. Note: the heavy money-services/AML retention obligations sit with Circle (the regulated payment provider), not Obol.
International transfers
Our infrastructure (Google Cloud) may process data in regions outside yours under standard contractual clauses and the providers' own adequacy mechanisms.
Changes
We'll post any material change here and update the date above. Continued use after a change means you accept the updated policy.