PUBLIC POLICY PLAIN LANGUAGE

Privacy,
by design.

Utilia provides machine-payable API and MCP tools without requiring a Utilia account. This policy explains what information the website and service process, why it is needed, and the choices available to you.

Effective and last updated:

01 / SCOPE

Scope and operator

This policy applies when you visit utilia.ink, call api.utilia.ink, connect to a Utilia MCP remote, or use a third-party integration that invokes Utilia. Utilia operates these services. Privacy and data-protection questions can be sent to security@utilia.ink.

Third-party wallets, marketplaces, runtimes, registries, websites, and blockchain networks have their own privacy practices. This policy covers Utilia's handling of information, not theirs.

02 / DATA

Information processed

Website and device information

When you visit the website, hosting infrastructure processes your IP address and network metadata to deliver and secure the request. Vercel Web Analytics records anonymous, aggregated data points such as the page, referrer, timestamp, approximate location, browser, operating system, and device type. Vercel Speed Insights records website performance measurements. Utilia also records named product events such as a copied command or an opened quote, without adding personal data to those event names. Utilia does not use this information to build an advertising profile.

API and MCP request metadata

Service infrastructure processes the request time, method, route, response status, request identifier, network metadata, user agent, caller-supplied integration source, duration, and security or rate limit events. Access logs can include IP addresses. The proxy removes payment-signature headers and redacts selected credential query values. Application logging redacts authorization, cookies, payment headers, API keys, platform secrets, webhook signatures, selected query credentials, and complete request URLs.

Tool inputs and results

Depending on the tool, Utilia processes Solana transaction signatures, wallet or account addresses, token mint addresses, writable accounts, unsigned serialized transactions, simulation parameters, public PDF or audio URLs, or base64-encoded PDF and audio bodies. The service also processes the generated analysis, extracted text, normalized audio, measurements, and content digests needed to return the result.

PDF and audio bodies are processed in memory and are not intentionally persisted to disk. Access and settlement logs retain request and payment metadata, not media bodies. A URL-based media request also reveals the requested URL to Utilia and causes Utilia's infrastructure to contact the host you selected.

Payment and blockchain information

Paid calls process x402 payment requirements and settlement information, including the network, asset, amount, receiving address, payer address when returned by the facilitator, transaction hash, resource, request identifier, and Utilia receipt identifier. Blockchain addresses, transfers, and transaction hashes written to Solana or Base are public and may be permanent.

03 / PURPOSE

How information is used

Utilia processes information to:

  • provide the requested website, API, MCP, and media functions;
  • issue, verify, settle, and correlate x402 payments;
  • prevent abuse, enforce rate limits, and investigate failures;
  • secure, debug, maintain, and improve the service;
  • measure product performance and integration attribution;
  • keep accounting, compliance, and operational records; and
  • respond to support, privacy, or security messages.

Where applicable law requires a legal basis, processing is based on providing the service you requested, Utilia's legitimate interests in operating and securing the service, compliance with legal obligations, or consent when specifically requested.

Utilia does not sell personal information and does not use service data for targeted advertising.

04 / INFRASTRUCTURE

Service providers and public networks

Information may be processed by the following categories:

  • Vercel for website hosting, anonymous aggregate usage analytics, and performance insights. Vercel describes its Web Analytics data handling in its privacy and compliance documentation.
  • Infrastructure providers for API hosting, network delivery, monitoring, and security.
  • Solana data providers for current transaction, account, token, simulation, and priority-fee information.
  • x402 facilitators and public blockchain networks for payment verification and settlement.
  • Third-party media hosts when you ask Utilia to retrieve a public PDF or audio URL from that host.
  • Partner runtimes or marketplaces when you choose to access Utilia through their service.

These providers may process information in countries other than your own. Utilia uses providers for the purposes described above and applies safeguards required by applicable law.

05 / RETENTION

Retention and security

Utilia retains operational logs only as long as reasonably needed for service delivery, troubleshooting, security, abuse prevention, accounting, and legal obligations. Proxy access logs rotate based on configured size limits. Settlement and accounting records may be retained longer. Public blockchain records are controlled by their networks and cannot be deleted by Utilia.

Utilia uses transport encryption, restricted operational access, log redaction, bounded request sizes, network restrictions for fetched media, and fail-closed payment validation. No internet service is completely secure, so do not submit private keys, seed phrases, passwords, unnecessary personal information, or confidential media.

06 / CHOICES

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, or to receive a portable copy. You may also have the right to complain to your local data-protection authority.

Send a request to security@utilia.ink. Include enough information to identify the relevant request or transaction without sending a private key or payment signature. Utilia may need to verify your request. Some information cannot be deleted when it exists only on a public blockchain or must be retained for security, accounting, or legal reasons.

You can limit website telemetry with browser privacy controls, content blockers, or by calling the API directly. Utilia does not require an account cookie and does not set advertising cookies.

07 / UPDATES

Changes to this policy

Utilia may update this policy when the service or legal requirements change. The effective date at the top identifies the current version. Material changes will be described on this page or through another appropriate public notice.

08 / CONTACT

Questions or requests

Email security@utilia.ink for privacy questions, data-rights requests, or security reports. Do not include wallet secrets, private keys, or seed phrases.