BoundID
Legal

Privacy

Last updated September 18, 2026

What we collect

  • Pilot requests: the email address and role you submit.
  • Console: your wallet address, the signatures you submit, and the agents, attestations, delegations and API keys you create. API keys are stored only as hashes.
  • API usage: request metadata and your IP address, used for rate limiting and abuse prevention.

What we don't collect

The sandbox never asks for identity documents, biometrics or private keys. Operator attestations in the sandbox record the operator name and jurisdiction you enter. Public registry records contain identifiers, claim status and policy parameters, never identity evidence.

Cookies and storage

We set one session cookie when you sign in to the console, plus a short-lived sign-in nonce. Sandbox wallets and agent execution keys live in your browser's local storage and never leave it. We don't use advertising or cross-site tracking cookies.

Public data

Passports are public by design: anyone with an agent reference can read its claims, delegation status and policy limits. Don't put personal information in agent names, descriptions or recipient labels.

Retention and requests

Sandbox data may be reset at any time. To delete your pilot request or console data, email hello@useboundid.com from the address you used or sign a request with your wallet.