Privacy Policy
Last updated September 28, 2026. This policy explains what Toll402 (https://toll402.dev) collects when you use the site or the API, why, and what you can do about it.
1. What we collect
- Request logs: for every API call we keep the endpoint, timestamp, latency, status, the client type derived from the user agent, the caller's IP address and, for paid calls, the paying wallet address or account id and the amount. We use this to run the service, detect abuse, price tools and report usage. IPs are kept for up to 90 days; aggregated statistics are kept indefinitely.
- Tool inputs and outputs: the data you send to a tool (a URL, a company name, keywords…) is processed to answer the call and forwarded to the upstream vendor when the tool is a provider API. We do not sell it. Some inputs are retained in short logs for debugging and, for the business directory, search terms are kept to decide which regions to seed.
- Credits accounts: an account id, a hash of your API key (never the key itself), your balance and ledger, the names and daily caps of the API keys you create, and the email you give us for receipts and recovery. Card details go directly to Stripe; we never see or store them. Stripe sends us the payment status and the email on the receipt. If you turn on automatic top-up, Stripe keeps the card for future charges and we keep only its brand and last four digits to show you which card is on file. The answers of paid credits calls are stored for 24 hours so you can fetch them again, then deleted. Reviews you or your agents leave about a call (useful or not, and an optional reason) are kept and aggregated to rank tools.
- x402 payments: wallet addresses, amounts and transaction hashes, which are also public on the Base blockchain.
- Usage analytics: we use PostHog (United States) to understand how the site and the API are used. On the site it runs without cookies or local storage and without session recording: it counts page views, clicks and the page you came from. For the API we send, from our server, one event per request with the endpoint, the tool, a short redacted summary of the input (keys, tokens and passwords are never included), the outcome, the price, the client type, and the approximate location and network derived from the IP address. Events of a credits account are linked to its account id. PostHog processes this data on our behalf.
- Site: no advertising cookies. The credits page can store your API key in your browser's local storage, on your device only, for convenience; clear it there.
2. Who else processes data
Stripe (payments and receipts), Fly.io (hosting, USA), treg.to and the upstream data vendors it routes to (provider endpoints receive the parameters you send), Anthropic (the language model behind extraction, summarisation, judging and forging tools receives the text you submit to those tools), the x402 facilitators (Coinbase, PayAI) that verify and settle USDC payments, PostHog (product analytics, USA) and Resend (account emails). Each acts under its own privacy policy.
3. Business directory data
The directory lists businesses, not private individuals, using public sources (OpenStreetMap, Wikidata, official registries, the business's own website) with dated evidence. If you own a business and want its record corrected or removed, claim it for free through the API or write to us.
4. Legal basis and retention
We process data to provide the service you request (contract), to protect it from abuse and to keep financial records (legitimate interest and legal obligation). Payment and ledger records are kept for as long as tax law requires; request logs as described above; account data until you ask us to delete it, after which the account is removed (any remaining balance is forfeited, as credits are non-refundable).
5. Your rights
You can ask what we hold about you, have it corrected or deleted, rotate or revoke your API key, and object to processing. Write to hello@toll402.dev with your account id or wallet address; we answer within 30 days. Residents of the EU/EEA, UK, Mexico and California have the additional rights their laws grant.
6. Security
API keys are stored only as hashes; traffic is encrypted in transit; card data never touches our servers; forged tools run in a sandbox without file-system access. No system is perfectly secure, so keep your key private and rotate it if in doubt.
7. Changes and contact
We will update the date above when this policy changes. Questions: hello@toll402.dev · Terms of service.