Privacy
Molt is test-mode infrastructure. No real money moves, and we collect the minimum needed to run a tab.
What we store
- Account: your email address and your passkey's public key. We never see the passkey itself; it stays on your device.
- Tabs and mandates: the limits you sign (budget, expiry, merchant scope, categories) and the task you declare.
- Receipts: merchant, amount, timestamps, signatures, and the hashes of purchase evidence. The evidence itself (screenshots, page snapshots) is created and kept by your agent on your machine; only hashes reach us.
- Event log: an append-only record of what happened on your tabs (who approved, what was refused, when).
- Cards: Stripe card identifiers only. Card numbers are never stored or logged by Molt.
Where it lives
The database is hosted with Supabase in the EU (Frankfurt). Payments run through Stripe in test mode; step-up emails go out via Resend. Those processors keep their own records under their own policies. There are no third-party analytics and no advertising trackers.
How long, and how to delete
Everything is kept while your account exists. Deleting your account (dashboard, or on request to the address below) removes your tabs, mandates, receipts, agent keys and passkey records immediately. The event log is kept as an anonymized audit trail: the rows stay, every link to you is removed.
Contact
Data questions and deletion requests: privacy@moltprotocol.dev