Draft — pending legal review
This text describes how the testnet service works today. It has not been reviewed by counsel yet and may change before any mainnet launch.
Privacy notice
Last updated 4 October 2026.
How the Inferit project team handles data when you use the Inferit testnet website and API. In short: we keep what is needed to authenticate you, meter usage and settle it on-chain, and never store the content of your prompts or completions.
What we process
| Data | Why | How it is kept |
|---|---|---|
| Wallet addresses | Sign-in (you sign a message with your wallet), linking your account to the escrow, routing settlement | Stored with your account. Also public on the blockchain (see below). |
| API keys | Authenticating inference requests | Only a peppered SHA-256 hash and a short display prefix are stored. The full key is shown to you once. |
| Session tokens | Keeping you signed in for 24 hours | Signed tokens kept only in your browser's local storage; they expire after 24h. |
| Usage metadata | Billing, your usage log and CSV export, settlement | Time, model, token counts, cost, latency, settlement status. No prompt or completion text. |
| x402 payments | Paying for a request without an API key, and refusing a payment that is presented twice | The paying wallet address, the authorization's amount, nonce and expiry, the deposit transaction and its status. The signature itself is never stored or logged. The deposit is also public on the blockchain. |
| Seller offer data | Listing and routing to your endpoint | Endpoint URL (shown only to you), price, health. Endpoint tokens and upstream keys are encrypted (AES-256-GCM). |
| IP addresses | Rate limiting and abuse prevention | In server logs and the in-memory rate limiter. Logs are kept for up to 30 days. |
Prompts and completions
Request and response bodies are relayed, never stored or logged by Inferit. To answer a request, the API forwards it to the seller whose offer it was routed to. That seller is an independent third party running its own server and sees the prompt in plain text. Sellers agree not to log, retain or train on buyer requests, but we cannot technically verify this, so do not send personal or sensitive data in prompts.
Public blockchain data
Deposits, spending caps, withdrawals, seller registrations and every settlement line are transactions on Whitechain Sepolia, a public blockchain. They show wallet addresses and amounts to anyone, permanently. Neither we nor anyone else can delete or change them. Use a dedicated wallet if you do not want this activity linked to your other addresses.
Your browser
The site sets no cookies and uses no analytics or advertising trackers. It uses your browser's local storage for your theme, your session and, in development builds, the API address. When you use wallet features, your browser talks directly to the Whitechain RPC and block explorer, which are operated by third parties under their own policies.
Service providers
The website is hosted on Vercel; the API and its database on Railway. They process data on our behalf to run the service. Model inference is performed by the independent seller that serves each request.
Retention
- Server logs, including IP addresses: up to 30 days.
- Accounts, hashed keys and usage records: while the testnet runs. Testnet resets may delete them earlier.
- Revoked keys and deleted offers: the secret material is destroyed at once; the key hash or offer record may remain for billing history.
- On-chain data: permanent, outside our control.
Your choices and rights
You can revoke keys and delete offers yourself on the dashboard and the Sell page. Depending on where you live, you may also have the right to object to processing or to complain to a data protection authority.
Terms of use · Privacy · Acceptable use · Security · About