# Privacy Policy

**Effective date:** 2026-07-28  
**Operator:** SQLGuard Inc / DoggyBagg  
**Contact:** hello@doggybagg.cc  
**Service:** SQLGuard (`https://sqlguard.io`)

This Privacy Policy explains what information SQLGuard processes when you (or your agents) use the Service. Related: [Cookies](/cookies), [DPA](/dpa), [Terms](/terms).

## 1. Summary

SQLGuard is built for machine clients. We minimize personal data. We do **not** require human account registration for core x402 purchase and SQL validation.

## 2. Information we process

### 2.1 Automatically / operationally

- HTTP request metadata (IP address, user-agent, timestamps, paths, status codes)
- Agent / wallet identifiers you supply (`X-SQLGuard-Agent`, request bodies, MCP args)
- Payment protocol metadata from x402 settlement (network, amounts, pay-to, settlement identifiers as provided by facilitators)
- Credit balances, Session tokens (hashed/stored as implemented), purchase/validate/bind receipts
- SQL / DDL / Intent Mandate text you submit for validation or binding (processed to provide the Service; not sold)
- Security, rate-limit, and abuse telemetry
- Optional handshake `need` text if you submit it

### 2.2 Voluntary

- Email or other contact details if you email us
- GitHub / marketplace profile data if you interact via public registries

### 2.3 We do not intentionally collect

- Government IDs, passwords, or private keys
- Payment card numbers (USDC settlement is wallet/protocol-based)

## 3. How we use information

- Provide, secure, and operate the Service
- Settle and reconcile prepaid SKUs and credits
- Detect abuse, fraud, and attacks
- Comply with law and enforce Terms
- Improve reliability (logs, error rates)

We do **not** sell personal information.

## 4. Legal bases (where applicable)

Depending on jurisdiction: contract performance, legitimate interests (security, operations), consent where required, and legal obligation.

## 5. Sharing and subprocessors

We may share data with:

- **Hosting / compute:** Fly.io (always-on), optionally Render or similar
- **Database:** Neon or other managed Postgres for credits/receipts when configured
- **Payments:** x402 facilitators (e.g. Coinbase Developer Platform / PayAI) and public Base chain
- **CDN / DNS / email** providers as needed to operate the domain and contact inbox
- **Font delivery:** Google Fonts on some human HTML pages (see [Cookies](/cookies))
- MCP / marketplace directories when you list or discover the Service
- Professional advisors or authorities when legally required
- Successors in a merger or asset transfer

On-chain USDC transfers are public by design.

## 6. Retention

- Credits / receipts / settlements: retained while needed for operations, disputes, and abuse prevention (typically up to 24 months unless longer retention is required)
- Request logs: shorter operational windows unless needed for security investigations
- Hosting filesystems may be **ephemeral**; durable money truth is the database/ledger and chain—not local disk. Do not rely on us as a backup of your SQL.

## 7. Security

We apply industry-reasonable measures (TLS via host, Helmet headers, rate limits, Ed25519 attestations, secret handling, fail-closed executor). No method of transmission or storage is 100% secure. Report vulnerabilities per [Security](/security).

## 8. International transfers

The Service may be hosted in the United States or other regions chosen by our providers. By using the Service you understand processing may occur outside your country.

## 9. Your rights

Depending on your location you may have rights to access, correct, delete, or restrict certain personal data, or to object to processing. Email hello@doggybagg.cc. We may need to verify the request and may retain data as permitted by law (e.g. security logs, settlement records).

## 10. Children

The Service is not directed to children under 16. Do not use it if you are under 16.

## 11. Agents and controllers

If you operate agents that submit others’ personal data in SQL/DDL/mandates, **you** are the controller (or equivalent) for that content and are responsible for lawful basis and notices. SQLGuard acts as a processor/service provider for that content solely to validate/bind as instructed. Platform customers: see [DPA](/dpa).

## 12. Changes

We may update this Policy by posting a new effective date. Material changes will be reflected on this page.

## 13. Contact

Privacy inquiries: hello@doggybagg.cc
