What we do with your data.
Plain-language notice of what we collect, who sees it, and how long we keep it. Updated .
Who we are
This notice covers Paynnt: the website, the API, and the payment rail. Paynnt shares its account system with Xaish, so one sign-in covers both. Questions: privacy@xaish.com or /contact.
What we collect
- Account data: email, password hash (bcrypt), optional display name and workspace name, 2FA enrollment metadata.
- Session: an HttpOnly cookie named
xaish_session(a signed JWT, 14-day lifetime). See Cookies. - Usage events: workspace, agent id, endpoint, actor kind, HTTP status, timestamp. Used for quotas and billing reconciliation. Not the paste itself.
- Paynnt: public wallet address, encrypted server-custody secret if you use that mode, off-chain transfer summaries. On-chain data is public by design.
- Access logs: method, path, status, latency, client IP, request id. Request bodies are not logged in normal operation.
Fraud and risk screening
Sends of $50 or more are screened for fraud before they go out. The transaction context is sent to an AI provider for that analysis; today that provider is Anthropic (Claude). Anthropic is contractually restricted from training its general models on API customer prompts under its current commercial API terms.
Processors we use
- Anthropic — fraud and risk analysis of transaction context.
- Resend — transactional email (verify, password reset) when email is configured.
- Solana RPC operator (public devnet RPC by default, or a provider you configure such as Helius / QuickNode) — Paynnt reads and submits transactions. Public chain data is not private.
- Sentry — server error monitoring only if
SENTRY_DSNis set. Browser Session Replay is off. We do not set a public browser DSN by default. - Hosting / Postgres — the VPS or cloud host running the app and database.
We do not sell personal information. We do not share it for cross-context behavioral advertising.
Payment data and wallets
Card data never touches our servers.
- Server-custody (Paynnt default). We mint a Solana keypair and store the secret Fernet-encrypted under
PAYNNT_VAULT_KEY. It does not appear in logs or API responses in plaintext. Paynnt on this deployment is Solana devnet — test value, not mainnet funds. - External wallet. Connect Phantom, Solflare, or Backpack. We store the public key only.
Cookies
The only first-party cookie we set is the session cookie. It is strictly necessary to stay signed in. Details: Cookie notice.
How long we keep it
- Account + workspace: for the life of the account. We delete on a verified request to privacy@xaish.com.
- Usage events: 24 months, then eligible for purge. We can purge a workspace earlier on request.
- Access logs: about 14 days on the default single-host deploy; longer if your log aggregator is configured that way.
- Verify / reset tokens: deleted when used, or after 24 hours (verify) / 1 hour (reset).
- Paynnt on-chain history: immutable on Solana. We keep an off-chain summary for the UI until the account is deleted.
Your rights
You can ask for a copy of your data, a correction, or deletion, or close the account. Email privacy@xaish.com. We respond within 30 days. If you are in a jurisdiction with additional privacy rights (including the EU/UK GDPR and California CPRA), we will honor those requests through the same address.
International transfers
Anthropic and Resend may process data in the United States. Using the service means that transfer. If you need a data-processing addendum or SCCs for a paid enterprise contract, ask legal@xaish.com.
Children
Paynnt is not directed at children under 16. We do not knowingly collect their data.
Changes
We bump the date at the top of this page when the notice changes. Material changes to how we handle personal data are emailed to subscriber-tier accounts.