← Passport

Privacy Policy

Last updated: August 2026

What we store

Passport stores only cryptographic commitments (SHA-256 hashes) of agent identity, repository names, branch names, session logs, and payload contents. Raw agent data, source code, and personal information are never stored.

What we never store

  • Private keys or seed phrases
  • Raw agent payloads or source code
  • Passwords (authentication is via API keys or cryptographic proof)
  • IP addresses beyond rate-limiting windows
  • Personal identifying information beyond Stripe customer IDs

Stripe

Payment processing is handled entirely by Stripe. Passport receives only the Stripe customer ID and subscription status. Full card details never reach our servers.

Data retention

Receipts and evidence commitments are stored indefinitely as part of the verifiable audit trail. Revoked receipts are marked as revoked but not deleted — revocation is a status change, not a deletion. Operators may delete API keys at any time via the dashboard.

Third-party access

We do not sell or share data with third parties. Evidence ingestion is opt-in and controlled per-source-type. The public key and masked public profiles are intentionally public by design — that is the product.

Contact

For privacy questions, contact the operator at the domain registration contact for passport.metis.gold.