# Privacy Policy

**Effective date:** 2026-07-27  
**Operator contact:** hello@doggybagg.cc  
**Service:** SQLGuard

This Privacy Policy explains what information SQLGuard processes when you (or your agents) use the Service.

## 1. Summary

SQLGuard is built for machine clients. We minimize personal data. We do **not** require human account registration for core x402 credit purchase and SQL validation.

## 2. Information we process

### 2.1 Automatically / operationally

- HTTP request metadata (IP address, user-agent, timestamps, paths, status codes)
- Agent / wallet identifiers you supply (`X-SQLGuard-Agent`, request bodies)
- Payment protocol metadata from x402 settlement (network, amounts, pay-to, settlement identifiers as provided by facilitators)
- Credit balances and purchase/validate receipts tied to agent ids
- SQL / DDL payloads you submit for validation (processed in sandbox; not sold)
- Security and rate-limit telemetry

### 2.2 Voluntary

- Email or other contact details if you email us or join partner waitlists using our address
- GitHub / marketplace profile data if you interact via public registries

### 2.3 We do not intentionally collect

- Government IDs, passwords, or private keys
- Payment card numbers (USDC settlement is wallet/protocol-based)

## 3. How we use information

- Provide, secure, and operate the Service
- Settle and reconcile prepaid credits
- Detect abuse, fraud, and attacks
- Comply with law and enforce Terms
- Improve reliability (logs, error rates)

We do **not** sell personal information.

## 4. Legal bases (where applicable)

Depending on jurisdiction: contract performance, legitimate interests (security, operations), consent where required, and legal obligation.

## 5. Sharing

We may share data with:

- Infrastructure providers (e.g. hosting such as Render, CDNs, logging)
- x402 facilitators and blockchain networks (public chains make settlement data public)
- MCP / marketplace directories when you list or discover the Service
- Professional advisors or authorities when legally required
- Successors in a merger or asset transfer

On-chain USDC transfers are public by design.

## 6. Retention

- Credits / receipts: retained while needed for operations, dispute handling, and abuse prevention (typically up to 24 months unless longer retention is required)
- Request logs: shorter operational windows unless needed for security investigations
- Hosting filesystems may be ephemeral; do not rely on us as a backup of your SQL

## 7. Security

We apply industry-reasonable measures (TLS in transit via host, helmet headers, rate limits, signed certificates, secret handling). No method of transmission or storage is 100% secure. Report vulnerabilities per [SECURITY.md](/security).

## 8. International transfers

The Service may be hosted in the United States or other regions chosen by our providers. By using the Service you understand processing may occur outside your country.

## 9. Your rights

Depending on your location you may have rights to access, correct, delete, or restrict certain personal data, or to object to processing. Email hello@doggybagg.cc. We may need to verify the request and may retain data as permitted by law (e.g. security logs).

## 10. Children

The Service is not directed to children under 16. Do not use it if you are under 16.

## 11. Agents and controllers

If you operate agents that submit others’ personal data in SQL/DDL, you are responsible for lawful basis and notices to those individuals. SQLGuard acts as a processor/service provider for that content solely to validate as instructed.

## 12. Changes

We may update this Policy by posting a new effective date. Material changes will be reflected on this page.

## 13. Contact

Privacy inquiries: hello@doggybagg.cc
