Skip to content

Privacy Policy

What we collect, why we collect it, and how to exercise your rights.

Effective May 11, 2026

1. Scope

This policy applies to infinihash.com, kyt.infinihash.com, kyc.infinihash.com, billing.infinihash.com, myaitoken.io, api.myaitoken.io, and any other property operated by Infinihash LLC ("Infinihash", "we"). It does not apply to third-party services we link to.

2. Information we collect

Account data (name, work email, organization) when you sign up for the API, billing data (last-4 of card, billing address) processed by Stripe — we never see full PANs — and usage data (screening counts, quota, API request metadata). For KYT screenings we store the wallet address you submitted plus the resulting risk profile. For KYC entity records we store the documents you upload so you can retrieve them later.

3. myaitoken.io — DePIN and node data

When you visit myaitoken.io or connect a node to the MyAI network, we additionally collect:

  • Wallet addresses you voluntarily connect or submit for token-gated features. These are public on-chain identifiers; we associate them with your account for reward attribution and compliance purposes.
  • On-chain data (transaction hashes, block references) retrieved from public blockchains to verify compute proofs and process token distributions. This data is inherently public.
  • Node telemetry (model served, request count, latency, GPU/CPU metrics, uptime) transmitted by the MyAI agent running on your hardware. This data is used to calculate your Proof-of-Compute score and reward allocation.
  • Analytics via Google Analytics 4 and Cloudflare Insights: page views, referrer, approximate geographic region, and device type. GA4 data is processed under Google's Data Processing Addendum. You can opt out via browser settings or a standard ad-blocker.

We do not collect private keys, seed phrases, or any data that could allow us to transact on your behalf. Node telemetry is transmitted over encrypted channels and retained for 90 days before aggregation.

4. Why we use it

To provide the service you requested, to bill correctly, to comply with applicable AML / KYT obligations, to calculate Proof-of-Compute rewards, and to investigate abuse. We do not sell personal information, and we do not use customer data to train external models.

5. Retention

KYT screening records are kept for 7 years by default to satisfy SAR recordkeeping under FinCEN guidance; you can shorten this for your organization in settings, subject to your own regulator's rules. KYC documents follow your retention policy (RETENTION_TTL_DAYS per tenant). Account records are retained for the life of the account and for 90 days after closure. Node telemetry is aggregated after 90 days and raw records deleted.

6. Your rights

If you live in the EEA, UK, or California you have rights of access, correction, deletion, and portability. Email [email protected] — we respond within 30 days. We may need to verify your identity before acting.

7. Cookies & analytics

Our marketing pages use Google Analytics 4 behind a consent banner (Google Consent Mode v2: analytics storage stays denied until you click Accept), and never on authenticated compliance routes. Your choice is stored in your browser as ih_cookie_consent for 365 days; we use no advertising cookies and no cross-site tracking. Every cookie and storage key we set, what each is for, and how to change your choice are in our Cookie Policy.

8. Changes

When we materially change this policy we'll email account owners and bump the effective date above. Continued use after the new effective date is acceptance.

Heads up: this is a v1 plain-language policy. A counsel-reviewed version is in progress with our SOC 2 audit. If you need a redlined enterprise privacy addendum, contact [email protected].
Privacy Policy | Infinihash