Legal

Privacy Policy

Effective Date: March 19, 2026

This Privacy Policy explains how MoltWall collects, uses, stores, and protects information when you use the MoltWall AI Agent Security Firewall platform at www.moltwall.xyz.

1

Who We Are

MoltWall (“we,” “us,” or “our”) is the operator of the MoltWall AI Agent Security Firewall platform, accessible at www.moltwall.xyz. We provide a production-grade security evaluation engine, TypeScript SDK, and security dashboard for teams building AI agents.

For privacy inquiries, you may contact our privacy team at privacy@moltwall.xyz.

2

Scope of This Policy

This Privacy Policy applies to:

  • Visitors to www.moltwall.xyz and all subdomains.
  • Registered users of the MoltWall security dashboard.
  • Developers integrating the MoltWall SDK (@moltwall/sdk) into applications.
  • Organizations whose AI agents submit Tool Call evaluations to the MoltWall API.

This Policy does not apply to third-party services linked from the Platform. Those services are governed by their own privacy policies. We encourage you to review them.

If you are using the Platform under a separate enterprise or data processing agreement with MoltWall, the terms of that agreement take precedence over this Policy where they conflict.

3

Information We Collect

3.1 Account & Identity Information

When you register for an Account via Privy, we receive the following information from the authentication flow:

  • Email address (if you sign in via email or Google).
  • OAuth profile data (name, profile picture URL) from Google or GitHub, if selected.
  • Wallet address (if you authenticate with a Web3 wallet). No private keys are ever transmitted.
  • Privy user ID — a stable identifier used to associate your Account with Activity data.

We do not store passwords. Authentication credentials are managed exclusively by Privy.

3.2 Tool Call & API Data (User Data)

When your AI agents interact with the MoltWall API, we process and store:

  • Action name — the label describing the operation the agent intends to perform.
  • Tool name — the identifier of the tool or system the agent is calling.
  • Tool Call arguments — the structured payload submitted for security evaluation. You are responsible for ensuring this data does not contain raw personal data, private keys, or payment credentials unnecessarily.
  • Agent ID — an identifier you assign to the agent submitting the request.
  • Source type — the trust tier of the request origin (e.g., user, system, web, external).
  • Risk score — the computed 0–1 risk score generated by our risk engine.
  • Decision — the policy enforcement outcome (allow, deny, sandbox, require confirmation).
  • Guardrail findings — any detected threats (prompt injection patterns, credential patterns, PII indicators) and their severity.
  • Timestamp — UTC timestamp of the evaluation.
  • Request latency — processing time in milliseconds.

3.3 Policy & Configuration Data

Data you enter when configuring your security policies in the dashboard, including:

  • Tool allow-lists and blocked tool patterns.
  • Trusted and blocked domain lists.
  • Spend limits and risk thresholds.
  • Custom action permission rules.

3.4 Technical & Usage Data

Automatically collected when you use the Platform:

  • IP address — used for rate limiting and fraud prevention.
  • Browser type and version — for compatibility and analytics.
  • Operating system — for compatibility.
  • Referring URL — to understand how users discover the Platform.
  • Pages visited and feature interactions — to improve dashboard usability.
  • API request metadata — endpoint, HTTP status codes, latency (not payload content).
  • Error logs — to diagnose and fix bugs.

3.5 Communications Data

If you contact us by email, live chat, or through a support channel, we retain the content of that communication and any contact details you provide, solely for the purpose of responding to you.

4

How We Use Your Information

We use the information we collect for the following purposes:

Provide the ServicesProcess Tool Call evaluations, enforce Policies, render security decisions, and display Action Logs in the dashboard.
Account managementCreate and maintain your Account, authenticate your sessions, and manage API Keys.
Security & fraud preventionDetect and prevent abuse, rate-limit API access, identify suspicious usage patterns, and protect the integrity of the Platform.
Service improvementAnalyze usage patterns, debug errors, and improve accuracy of risk scoring and guardrail detection models. Model training uses only anonymized, aggregated signals — never raw Tool Call payloads.
CommunicationsSend transactional emails (account notices, API key alerts, policy violation warnings). We do not send unsolicited marketing without consent.
Legal complianceComply with applicable laws, respond to lawful legal process, and enforce our Terms of Service.
BillingProcess payments if you subscribe to a paid plan (via a third-party payment processor).
5

Legal Bases for Processing (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing your personal data are:

Contract performanceProcessing necessary to provide the Services you have requested — evaluating Tool Calls, maintaining your Account, and enforcing Policies.
Legitimate interestsOperating, securing, and improving the Platform; detecting fraud and abuse; analytics. We balance our interests against your rights and only rely on this basis where the impact on you is minimal.
Legal obligationComplying with applicable law, court orders, or regulatory requirements.
ConsentWhere you have specifically opted in (e.g., marketing communications). You may withdraw consent at any time.
6

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data or User Data to third parties. We disclose information only in the following circumstances:

6.1 Service Providers (Sub-Processors)

We share data with third-party sub-processors listed in Section 7 to the extent necessary for them to provide their services to us. All sub-processors are bound by data processing agreements.

6.2 Legal Requirements

We may disclose information if required to do so by law, subpoena, court order, or other governmental authority, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

6.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity. We will notify you via email or a prominent notice on the Platform before data becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information with third parties when you explicitly direct us to do so.

6.5 Aggregated / Anonymized Data

We may share aggregated, de-identified data about Platform usage and security trends that cannot reasonably be used to identify any individual or organization.

7

Third-Party Sub-Processors

The following sub-processors handle personal data on our behalf. We maintain data processing agreements with each.

Sub-processorPurposeDataLocation
Privy (privy.io)Identity & authenticationEmail, OAuth profile, wallet addressUSA / EU
SupabaseDatabase — policies, tools, action logsUser Data, Action Logs, API Keys (hashed)USA
Upstash / RedisPolicy caching & rate limitingPolicy configs, rate limit counters (temporary)USA / EU
Vercel (if deployed)Platform hosting & CDNHTTP request metadata, IP address (ephemeral)Global CDN

To request our full sub-processor list or to object to a new sub-processor, contact legal@moltwall.xyz.

8

International Data Transfers

MoltWall operates primarily from the United States. If you are located in the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States and potentially other jurisdictions.

We rely on the following mechanisms to ensure adequate protection for international transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated in our agreements with EU-based sub-processors.
  • UK International Data Transfer Agreements (IDTAs) for UK-to-third-country transfers where applicable.
  • Adequacy decisions where the European Commission has determined a country provides adequate protection.

To request copies of the safeguards we rely on for international transfers, contact legal@moltwall.xyz.

9

Data Retention

Account informationRetained for the lifetime of your Account plus 30 days after deletion.
Action LogsRetained per your plan tier (configurable). Deleted upon account closure after a 30-day grace period.
Policy configurationsRetained while your Account is active. Deleted with your Account.
API Keys (hashed)Retained until you revoke them or delete your Account.
Technical logs (IP, request metadata)Retained for up to 90 days for security and debugging purposes, then automatically purged.
Redis cache entriesEphemeral — TTL-based expiry between 5 minutes and 24 hours depending on entry type.
CommunicationsRetained for up to 3 years to maintain a record of support interactions.

You may request deletion of your data at any time (see Section 12). Certain data may be retained longer where required by applicable law or for legitimate fraud-prevention purposes, but only to the extent necessary.

10

Security Measures

We implement a layered set of technical and organizational security controls to protect your data:

  • Encryption in transit: All data exchanged between clients and the MoltWall API is encrypted using TLS 1.2 or higher.
  • Encryption at rest: Database storage (Supabase) encrypts data at rest using AES-256.
  • API Key hashing: API Keys are stored as SHA-256 hashes. The plaintext key is only shown once at issuance.
  • Access controls: Production database access is restricted to authorized personnel via role-based access controls and audit logs.
  • Authentication: User authentication is handled by Privy, which supports MFA, phishing-resistant passkeys, and wallet authentication.
  • Dependency scanning: We perform regular scanning of SDK and platform dependencies for known vulnerabilities.
  • Incident response: We maintain an incident response process. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

No system is completely immune to security threats. We encourage you to protect your API Keys, use strong authentication methods, and report any suspected security issues to security@moltwall.xyz.

11

Cookies & Tracking Technologies

11.1 Essential Cookies

We use strictly necessary cookies and session tokens to maintain your authenticated session in the dashboard. These cannot be disabled without breaking core functionality.

11.2 Analytics

We may use privacy-respecting analytics (collecting only anonymized, aggregated data) to understand how the dashboard is used and where to focus improvement efforts. No cross-site tracking identifiers or third-party advertising cookies are used.

11.3 Local Storage

The dashboard uses browser local storage to persist your session state, recent activity, and UI preferences (e.g., selected filters, playback settings). This data stays in your browser and is not transmitted to our servers except as part of normal API interactions.

11.4 Managing Cookies

You may manage cookies through your browser settings. Blocking essential cookies may prevent the dashboard from functioning correctly. For EU users, we will request consent for non-essential cookies if we introduce them.

12

Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data:

AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of inaccurate or incomplete personal data.
Erasure (Right to be Forgotten)Request deletion of your personal data, subject to our legal retention obligations.
RestrictionRequest that we restrict processing of your data in certain circumstances.
PortabilityRequest your data in a structured, machine-readable format (JSON) to transfer to another service.
ObjectionObject to processing based on legitimate interests or for direct marketing purposes.
Withdraw consentWithdraw consent at any time where processing is based on consent (e.g., marketing).
Lodge a complaintFile a complaint with your local data protection authority (e.g., ICO in the UK, your national DPA in the EEA).

To exercise any of these rights, submit a request to privacy@moltwall.xyz. We will respond within 30 days (or the period required by applicable law). We may need to verify your identity before processing your request.

12.1 Account Deletion

You may delete your Account at any time through the dashboard settings. Deletion triggers a 30-day grace period during which you may export your data, after which all associated data is permanently purged from our systems (except where retention is legally required).

12.2 Opting Out of Communications

You may unsubscribe from non-essential communications using the unsubscribe link in any email, or by contacting privacy@moltwall.xyz. Transactional communications (security alerts, account notices) cannot be opted out of while your Account is active.

13

Children's Privacy

The Platform is not directed to individuals under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will promptly delete it. If you believe a child has provided us with personal data, please contact privacy@moltwall.xyz.

14

AI-Specific Data Practices

Because MoltWall is a security platform for AI agents, we have specific practices around how AI-related data is handled:

14.1 Tool Call Payloads

Tool Call argument payloads are processed by our security evaluation engine in real-time. Payloads are stored as part of Action Logs for audit purposes. We do not use raw Tool Call argument content to train external AI models without your explicit consent.

14.2 Guardrail Findings

When our guardrail engine detects threats (e.g., prompt injection patterns, PII indicators), the finding type and severity are recorded in the Action Log. Detected PII is flagged but not extracted or stored in isolation — only the presence and category of the detection is logged.

14.3 Risk Scoring Models

Risk scores are computed by deterministic, rule-based scorers and do not involve training on your personal data. We may use aggregated, anonymized statistical signals to calibrate scorer weights over time.

14.4 Agent Identifiers

Agent IDs you assign are treated as operational data associated with your Account. They are not shared with third parties and are used solely for log attribution and policy scoping.

14.5 No Re-Training on User Data

MoltWall does not use your Tool Call payloads, Action Logs, or Policy configurations to train, fine-tune, or improve AI models operated by third parties without your explicit, opt-in consent.

15

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights:

Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the sources, our business purposes for collecting it, and the categories of third parties with whom we have shared it.

Right to Delete

You have the right to request deletion of personal information we have collected from you, subject to certain exceptions (e.g., information necessary to complete a transaction or comply with a legal obligation).

Right to Correct

You have the right to request correction of inaccurate personal information.

Right to Opt-Out of Sale / Sharing

MoltWall does not sell personal information and does not share personal information for cross-context behavioral advertising. No opt-out action is required, but you may contact us to confirm.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To submit a verifiable consumer request, contact privacy@moltwall.xyz. We will respond within 45 days, with a possible 45-day extension with notice.

16

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes — those that affect your rights or how we process your personal data — will be communicated via:

  • Email notification to your registered address at least 14 days in advance.
  • A prominent banner or notice in the dashboard.
  • An updated “Effective Date” at the top of this page.

Non-material changes (e.g., clarifications, corrections) take effect upon posting. We encourage you to review this Policy periodically. Continued use of the Platform after the effective date of changes constitutes acceptance of the updated Policy.

17

Contact & Data Requests

For any privacy-related questions, requests, or complaints, please contact our privacy team:

Company: MoltWall

Website: www.moltwall.xyz

Privacy inquiries: privacy@moltwall.xyz

DPA / legal requests: legal@moltwall.xyz

Security vulnerabilities: security@moltwall.xyz

If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Last updated: March 19, 2026

Read our Terms of Service →