Privacy Policy
Effective July 2026
Cabrini was designed so there's almost nothing to have a privacy policy about. No accounts means no emails, no passwords, and no profiles. Here's the little we do handle.
What we process
- IP addresses — used only for rate limiting unpaid requests (30 per minute per IP; paid requests are unlimited)
- Request metadata — which endpoint, ticker, and date were queried, for monitoring and abuse prevention
- Payment signatures — x402 proofs, passed through to the payment facilitator for settlement
What we never collect
- No accounts, emails, passwords, or names
- No cookies, tracking pixels, or analytics scripts
- No stored wallet addresses — payment signatures are stateless
- No personal information beyond the IP address on each request
How long anything lives
Rate-limit counters are held in memory and vanish when the service restarts. We don't keep persistent logs of individual queries. The market data itself is stored encrypted at rest.
Payments
Payments settle on the Base network via the x402 protocol. Verification and settlement are handled by an x402 facilitator; we don't store wallet addresses or transaction hashes beyond what is inherently public on-chain.
Third parties
- x402 payment facilitator — on-chain payment verification and settlement
- Infrastructure providers — hosting, edge network, and encrypted storage
Questions
Anything unclear about how we handle data — get in touch.