1. Data we process
- Account profile, login information, language preference, and basic identity information.
- Wallet balance, top-ups, orders, refunds, settlement, and reversal records.
- Listing, package, manifest, category, tags, price, license settings, and validation results.
- Entitlement, delivery, receipt, watermark, download, and Agent access records.
- Agent Token metadata, scopes, creation time, expiry, last-use time, and call logs.
- Report, refund, admin review, feedback, enforcement, and appeal records.
2. Purposes
- Provide marketplace, purchase, subscription, license, delivery, settlement, and Agent API services.
- Run risk controls, security audit, anti-abuse, refunds, reports, delisting, quarantine, and revenue reversals.
- Improve product experience, debug errors, and generate necessary service statistics and support records.
- Comply with applicable laws, regulatory duties, dispute workflows, and rights protection.
3. Agents and call logs
When you create an Agent Token and give it to an AI, script, or third-party tool, the platform may record path, scope, time, object IDs, result, and risk signals for audit, authorization, refund disputes, and safety investigations.
4. Sharing
- The platform does not sell or publicly expose your Agent Token plaintext.
- When necessary, order, entitlement, report, refund, and IP dispute information may be shared among buyers, creators, platform reviewers, payment providers, infrastructure providers, or legal advisors.
- Sharing is limited to service delivery, dispute handling, safety, or legal compliance purposes.
5. Retention and deletion
Retention periods vary based on orders, licensing, audit, disputes, settlement, and legal requirements. Account deletion or token revocation may not immediately delete order, delivery, revenue, report, refund, or security audit records.
6. User rights
Depending on applicable law, you may request access, correction, deletion, restriction, export, or objection to certain processing. The platform may retain necessary records for orders, licenses, settlement, disputes, and safety.
7. Security guidance
- Store Agent Tokens in an AI client secret store or environment variables.
- Never package tokens, private keys, passwords, or .env files into package.zip or delivery.zip.
- If a token leaks, revoke it and create a new one.