Legal

Privacy Policy

This policy explains how Xysera handles account information, payment information, and the public trust data required to verify agent identities.

Effective date: September 20, 2026.

This Privacy Policy explains how Xysera collects, uses, discloses, and protects information when you use Xysera websites, applications, APIs, SDKs, command line tools, documentation, and related services.

Xysera provides identity and revocation infrastructure for AI agents. Some agent trust information is intentionally public so third parties can verify identities. Private account information is handled separately from public agent trust information.

  • Account information, such as name, email address, authentication identifiers, organization membership, and account settings.
  • Organization and issuer information, such as organization names, issuer references, roles, permissions, and team membership.
  • API key metadata, such as key names, creation dates, last-used timestamps, scopes, and status. Xysera stores hashed user API keys and does not store raw API key values after creation.
  • Agent identity information, such as Agent IDs, issuer references, public credential material, public keys, status, registration metadata, rotation metadata, revocation metadata, and audit or trust history needed for verification.
  • Usage and request information, such as API requests, timestamps, status codes, quota usage, challenge or nonce activity, verification events, check-ins, IP addresses, user agents, and diagnostic logs.
  • Billing information for paid plans. Payment processing is handled by Stripe, and Xysera does not store full payment-card numbers.
  • Communications information, such as support requests, feedback, emails, and other messages you send to Xysera.
  • Cookie and device information used for authentication, session management, security, preferences, and basic site operation. Xysera does not currently use analytics providers.

Xysera is partly a public trust network. Information required to verify an agent identity may be publicly accessible through registry, API, SDK, CLI, or documentation surfaces.

  • Public trust information may include Agent ID, issuer reference, public key or credential metadata, registration information, credential status, revocation information, and limited audit or trust metadata.
  • An ACTIVE status should be understood as recent valid cryptographic proof associated with an identity, not a guarantee that an agent is safe, truthful, online, beneficial, uncompromised, or behaving correctly.
  • A REVOKED status means an identity or credential has been revoked according to Xysera's protocol. Xysera records and communicates revocation information, but third-party systems decide how they respond to it.
  • Private account information, billing information, and private dashboard data are not public merely because an Agent ID or trust record is public.
  • Operate, maintain, secure, and improve Xysera.
  • Authenticate users, manage accounts, support organizations, and enforce permissions.
  • Register agent identities, verify cryptographic proof of possession, rotate credentials, communicate status, and record revocations.
  • Provide public verification, registry lookup, audit, and trust-network functions.
  • Monitor usage, enforce quotas and rate limits, detect abuse, prevent fraud, and protect Xysera infrastructure.
  • Provide customer support, service notices, product updates, and administrative communications.
  • Process billing, subscriptions, taxes, and payment-related support if paid services are enabled.
  • Comply with legal obligations and enforce Xysera's Terms of Service.

Xysera does not currently use analytics providers. If you purchase a paid plan, payment information is processed by Stripe according to Stripe's terms and privacy policy. Xysera may add service providers in the future to operate, secure, or support the service, and will update this policy where appropriate.

We may disclose information if required by law, to protect rights and safety, to investigate abuse, in connection with a corporate transaction, or with your direction or consent.

We retain information for as long as needed to provide Xysera, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve trust-network integrity.

You may request account deletion by contacting help@xysera.com. Account information and personal information associated with the account will be deleted, subject to legal, security, and operational requirements. Agent information may be anonymized and retained where necessary for verification, abuse prevention, legal compliance, or integrity of the public trust network.

We use administrative, technical, and organizational measures designed to protect information. No system can be guaranteed to be completely secure. You are responsible for protecting your account credentials, user API keys, and agent credentials.

Depending on where you live, you may have rights to access, correct, delete, restrict, port, or object to certain processing of your personal information. You may exercise applicable rights by contacting help@xysera.com. We may need to verify your request before responding.

Xysera is not intended for children under 18. We do not knowingly collect personal information from children under 18.

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service or another appropriate method.

Contact: help@xysera.com.