Privacy Policy.
Effective 9 July 2026
Sella is a marketplace where people and their AI agents discover, pay for, and use machine-payable data and APIs. Agentic commerce moves money and data automatically, so this policy is unusually concrete about three things most policies gloss over: what your agent does on your behalf, how we handle the wallet and keys that let it pay, and the fact that on-chain payments are public and permanent.
1. Who this covers
This policy applies to the Sella marketplace, dashboard, documentation, the MCP endpoint at /api/mcp, the sella-cli tool, and related services (together, the “Service”). It covers three kinds of people whose information we handle:
- Operators / consumers: humans who create an account, fund an agent wallet, and set spend policies.
- Publishers: humans and organizations who upload, price, and sell datasets and APIs.
- Agents: the autonomous software you authorize to act through Sella. An agent is not a separate data subject; its activity is attributed to the operator who authorized it.
It does not cover third-party services you reach through Sella (marketplace providers, wallets, blockchains, or external sites we link to). Those operate under their own privacy policies. See Section 6.
2. Information we collect
Information you give us
- Account & identity: your email address, and a short-lived one-time code (OTP) used to verify it. We do not use passwords.
- Publisher content: datasets, API definitions, descriptions, prices, and metadata you choose to publish, plus any files you upload.
- Spend policies & settings: budgets, limits, and preferences you configure for your agent.
- Support & communications: messages you send us and any details you include.
Information created as you use Sella
- Credentials we issue: API keys (prefixed
sk_live_), OAuth tokens, and agent-wallet identifiers. Keys are stored hashed; we cannot recover a raw key after it is shown once. - Wallet data: blockchain addresses generated for your agent across supported chains, and, for the managed wallet, encrypted private keys (see Section 4).
- Usage & transaction events: which MCP tools were called, which datasets or providers were accessed, timestamps, prices, payment references, and outcome/status. This is how billing, spend policies, and publisher earnings work.
- Agent requests: the tool calls and query parameters your agent sends. Treat these like a public API request. Do not place sensitive personal data in queries; we cannot control what a query contains.
- Technical logs: IP address, request headers, and coarse rate-limiting counters, used for security, abuse prevention, and reliability.
We do not intentionally collect special-category data (health, biometrics, precise geolocation) and ask that you not upload it as dataset content without a lawful basis.
3. Agents and autonomous actions
Sella is built for autonomous use. Once you authorize an agent (by pairing a client, minting a setup code, or issuing an API key), that agent can search, preview, purchase, and paywithout a human in the loop for each action.
- Actions an agent takes with your credentials are attributed to you and treated as authorized by you.
- You are responsible for the prompts, policies, and permissions you give your agent, and for revoking its access if it is lost or misbehaving (Dashboard → Connected agents).
- We process agent activity to execute the action, enforce your spend policies, prevent abuse, and record the transaction. We do not use the content your agent retrieves to train models.
Bootstrap tools (email verification, setup-code claim) are callable without a token so an agent can onboard itself; they never expose another user’s data, and setup codes are single-use and short-lived.
4. Wallets, keys, and on-chain payments
To let your agent pay per call over x402, Sella provisions on-chain wallets and operates a managed “agent wallet” that can settle payments on your agent’s behalf.
- Custody, stated honestly. Private keys for the managed wallet are encrypted at rest (AES-256-GCM) and used only to sign payments your agent initiates within your policies. Because we hold encrypted keys server-side, this is a managed wallet, not a fully non-custodial one. Locally-stored keys delivered to you at pairing are your responsibility.
- Public ledger. Payments settle on public blockchains. Your wallet addresses, amounts, timestamps, and counterparties are publicly visible and permanent. Anyone can inspect them, and neither you nor Sella can alter or delete on-chain records. Consider addresses pseudonymous, not anonymous.
- Funding. If you add funds by card or bank through an on-ramp partner, that partner (not Sella) collects and processes your payment-card and identity details under its own policy and any KYC obligations. Sella receives confirmation and the resulting on-chain balance, not your card number.
- Platform fee. We record a small routing fee per settled call for billing and accounting.
5. How we use information
- Provide the Service: authenticate you, run MCP tools, route and settle payments, and deliver purchased data.
- Enforce spend policies, rate limits, and fraud/abuse protections.
- Calculate publisher earnings and buyer billing, and produce receipts and transaction history.
- Maintain security, debug, and keep the Service reliable.
- Communicate service and account notices (e.g., OTP codes, security alerts). We use email for transactional messages, not marketing, unless you opt in.
- Comply with law and enforce our terms.
Where required, our legal bases are: performance of a contract (running your account and transactions), legitimate interests (security, abuse prevention, improving reliability), consent (any optional communications), and legal obligation.
6. Data shared through the marketplace
Sella is an intermediary. When your agent uses a third-party provider listed in the market, your request (including any parameters it contains) is routed to that provider so it can fulfill the call. Providers are independent controllers of the data they receive and handle it under their own terms and privacy policies.
- We share with a provider only what the call requires: typically the query and a payment proof.
- We share the minimum needed for a purchase to complete; we do not hand providers your email or account identity unless the call itself requires it.
- Free, open catalog entries (for example, model-discovery APIs) may be called directly by your agent; review the provider’s terms before sending anything sensitive.
- Publishers receive transaction metadata for their own datasets (counts, timestamps, amounts), not your email or wallet keys.
We may also disclose information in a merger or acquisition, or to comply with law, valid legal process, or to protect rights, safety, and the integrity of the Service.
7. Service providers & sub-processors
We rely on a small set of vetted processors to run the Service. Categories include:
- Cloud hosting & database: application hosting and the managed database that stores accounts, catalog, and transaction records.
- Object storage: S3-compatible storage for publisher dataset files, served via short-lived signed URLs.
- Email delivery: to send one-time codes and transactional notices.
- Payment on-ramp: a merchant-of-record partner for optional fiat funding, which handles card/identity data directly.
- Blockchain networks & x402 facilitator: public networks that settle and verify payments.
Processors act on our instructions under contract. A current list of named sub-processors is available on request at rasesh@buildifi.ai.
8. Data retention
- Account and credential records are kept while your account is active and for a reasonable period afterward for security and audit.
- Transaction and billing records are retained as long as needed for accounting, dispute resolution, and legal/tax obligations.
- Revoked API keys and claimed/expired setup codes are retained (in hashed form) for audit and abuse-prevention, not for reactivation.
- On-chain data is permanent and outside our control; it cannot be deleted on request.
- Technical logs are kept for a limited window and then deleted or aggregated.
9. Security
We protect information with encryption in transit, encryption at rest for wallet secrets (AES-256-GCM), hashed credential storage, scoped tokens, least-privilege access, and IP-based rate limiting. Revocation is self-service in your dashboard. No system is perfectly secure; you are responsible for safeguarding any keys delivered to your machine and for promptly revoking compromised credentials.
10. Your rights and choices
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these directly:
- Rotate or revoke API keys and disconnect agents from your dashboard at any time.
- Request access to or deletion of account data by contacting us (see Section 14).
- Opt out of any optional communications via the unsubscribe link or by contacting us.
We do not sell personal information and do not “share” it for cross-context behavioral advertising. Two limits are inherent to the platform and not something we can override: on-chain records are immutable, and data already routed to a third-party provider is governed by that provider. We will respond to verified requests within the timeframe the law requires and will not discriminate against you for exercising a right.
11. International transfers
Sella operates online and may process information in countries other than yours. Where we transfer personal data across borders, we rely on appropriate safeguards such as standard contractual clauses or an equivalent mechanism. Blockchain networks are inherently global and distributed.
12. Children
Sella is not directed to children and is intended for users who are at least 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service evolves. Material changes will be posted here with a new effective date and, where appropriate, announced in-product. Continued use after an update means you accept the revised policy.
14. Contact us
Questions, requests, or a sub-processor list? Reach us at rasesh@buildifi.ai or through our team. For data-protection requests, please include enough detail for us to verify your account.
This document describes Sella’s current practices for an evolving product; it is not legal advice.