Privacy
Last updated: 2026-07-31.
SchemaSure is built for machine-to-machine use with no accounts and no API keys, so we collect as little as possible.
What we process
- Request content. Text, HTML, image bytes, JSON Schemas, and extracted output are processed transiently to fulfill the request and are not persisted by SchemaSure in production.
- Inference processing. Request content is transmitted over TLS to Google AI API solely to perform extraction. SchemaSure does not use customer content to train models. Processing by the configured inference provider is governed by that provider's API data terms.
- Operational metrics. We keep non-content reliability and commercial events for up to 365 days, including timestamps, request identifiers, API version, success/error code, latency, payment state, and payer address. Expired records are deleted when the analytics store initializes. These records exclude raw request content, schemas, signatures, private keys, and extracted output.
- Payment data. x402 settlement is handled on-chain via the payment facilitator; we do not store your wallet signatures or secrets.
What we do not do
- We do not sell your data.
- Raw request content is not logged, sampled, or retained in production. Because there is no stored request-content copy, there is nothing to delete after completion.
- Submitted content is isolated from system instructions and treated as untrusted data. Prompt-injection defenses reduce risk but are not represented as infallible.
Contact
Privacy questions: support@schemasure.com.