Skip to content
Public beta: payments use test USDC on Base Sepolia, not real money. Learn more

Legal

Privacy Policy

Last updated: September 24, 2026

This policy explains what data quarry labs, inc. ("we", "us") collects when you use quarry, how we use it, and the rights you have over it.

1. Data we collect

Creator accounts. Your email address, a public handle, and your authentication identity (email/password or Google or Apple sign-in, handled by our auth provider). We also store references to the payout wallet provisioned for your account and its on-chain address.

Uploaded content. The files you upload, and the parsed text, chunks, and embeddings derived from them to serve search results. We do not use your files to train models.

Questions.Agents can ask without an account. For each answered question we log the question text (truncated), how it was paid (x402, subscription, or free), the paying wallet address and settlement transaction hash for x402 payments, the amount, latency, the passages returned, the surface used (HTTP, MCP, or the agent API), and the client family taken from the client's name or User-Agent (for example “claude-code”), never the full User-Agent.

Agent search.Free searches across the catalog are not stored with the caller's identity. The search text is sent to our embedding and reranking providers to rank results, and the caller's IP address or account id is used for rate limiting. We keep a daily count of MCP connections and tool calls per client family, without IP addresses.

Subscriptions and agent access.For monthly subscriptions, Stripe processes payment details; we store the subscription, its quota and usage, and invoice references. When you connect an agent, we store the connector's name and when you approved it. API keys are stored only as a hash, with a name, a short prefix, and when they were created and last used.

Withdrawals. Destination address, amount, status, and transaction hash for each creator withdrawal.

2. How we use data

  • to operate the service: parse, index, and serve datasets,
  • to settle payments and payouts,
  • to power creator analytics: answered questions, revenue, latency, which passages were used, and a list of recent questions with their text, amount, paying wallet address, and transaction hash, shown to the dataset's creator only,
  • to show agents searching the catalog a free preview of up to 200 characters from a dataset's best-matching passage, when that dataset's creator allows it,
  • to measure which agent clients and surfaces are used,
  • for security, abuse prevention, and debugging.

We do not sell personal data or run third-party advertising.

3. Sub-processors

Depending on configuration, we may use the following providers to operate the service:

  • Supabase — Authentication and database (accounts, datasets, indexed content, query logs)
  • Cloudflare R2 — Object storage for uploaded dataset files
  • Privy — Managed creator payout wallets (receives your email and internal account ids)
  • Coinbase CDP / x402.org — x402 payment facilitation and settlement verification
  • Stripe — Monthly subscriptions: checkout, card payments, invoices, and creator payouts (Stripe Connect)
  • Upstash — Rate limiting and payment replay protection (IP addresses, account ids, and paying wallet addresses, kept for the length of the limit window)
  • OpenAI, Voyage AI, or Cohere — Embeddings and reranking (receive dataset chunk text, and the text of agents' searches and questions)
  • Mistral, Unstructured, LlamaCloud — Document parsing and OCR (receive uploaded document content)
  • Vercel — Hosting, background job scheduling, and cookieless page-view analytics

Each provider processes only what its role requires, under its own data-processing terms.

4. Cookies

We set only the session cookies our auth provider needs to keep you signed in. There are no tracking or advertising cookies. Page views are counted with Vercel Web Analytics, which is cookieless and reports aggregated statistics.

5. On-chain data

Payments and withdrawals settle on a public blockchain (Base). Wallet addresses, amounts, and transaction hashes are public, replicated across the network, and immutable — we cannot modify or erase them. Wallet addresses are pseudonymous, but anyone who links an address to you can see its transaction history.

6. Retention and security

Account data is kept while your account exists; uploaded content and derived indexes are kept until you delete the files or dataset; query and withdrawal logs are kept as long as needed for creator analytics, accounting, and abuse prevention. Data in transit is encrypted, storage access is credential-scoped, and payout wallets are held by a dedicated wallet-infrastructure provider — we never handle raw private keys.

7. International transfers

Our providers may process data in the United States and other countries. Where required, transfers from the EEA, UK, or Switzerland rely on adequacy decisions or standard contractual clauses.

8. Your rights (GDPR / EEA & UK)

We process account and content data to perform our contract with you, and query and security logs under our legitimate interest in operating a paid, abuse-resistant service. Where you are in the EEA or UK, you have the right to access, rectify, erase, and receive a portable copy of your personal data, and to object to or restrict certain processing.

To exercise these rights, contact hello@quarry.market. Note the limit in section 5: data recorded on a public blockchain cannot be erased. You can also lodge a complaint with your local supervisory authority.

9. Children

The service is not directed at anyone under 18, and we do not knowingly collect their data.

10. Changes and contact

We may update this policy; material changes will be announced on the site. Questions and requests: hello@quarry.market. See also our Terms of Service.