Legal

Privacy Policy

This Privacy Policy explains how Roundhouse AI Ltd. collects, uses, discloses and protects personal data in connection with the Roundhouse Services.

Effective 5 August 2026

This Privacy Policy (the "Policy") explains how Roundhouse AI Ltd., a company incorporated in Singapore ("Roundhouse", "we", "us" or "our"), collects, uses, discloses and otherwise processes personal data in connection with https://www.roundhouse.studio (the "Site"), including its subdomains, APIs and agent-readable surfaces, and the dashboards, data feeds, AI SQL playground, app builder, x402 payment facilitator services and related services we provide (together, the "Services").

This Policy forms part of, and is incorporated by reference into, our Terms of Service, and should be read together with our Cookie Policy, Acceptable Use Policy and Data & Risk Disclaimer. All of our legal documents are listed at our legal hub.

This Policy is effective as of 5 August 2026. We may update it from time to time as described in the section on changes to this Policy below. If you do not agree with this Policy, you should not use the Services.

1. Introduction and scope

Roundhouse AI Ltd. is the entity responsible for the personal data described in this Policy. Our registered address is 101 Telok Ayer Street, #03-02, Singapore 068574. For general data protection matters, you can reach us at legal@roundhouseai.io. Enquiries for our Data Protection Officer can be sent to vanessa@roundhouseai.io, or by post marked "Attn: Data Protection Officer" at our registered address.

This Policy applies to personal data we process about visitors to the Site, holders of Roundhouse accounts, members of organisations and teams created on the Services, developers and autonomous agents that interact with our APIs, publishers who make content available through the app builder and paywall features, and other individuals who interact with the Services or correspond with us. In this Policy, "personal data" means data, whether true or not, about an individual who can be identified from that data or from that data together with other information to which we have or are likely to have access. Capitalised terms used but not defined in this Policy have the meanings given to them in our Terms of Service.

This Policy does not apply to the practices of third parties that we do not own or control, including public blockchain networks, wallet software, sign-in providers, or websites, applications and services operated by publishers or other users. Those parties process data under their own terms and privacy policies, as described further below.

The Services are designed around data that is already public. A significant part of what Roundhouse does is to index, organise and present records that exist on public blockchains. Because that raises distinct considerations, we address it in a dedicated section on public blockchain data below.

2. Personal data we collect

The categories of personal data we collect depend on how you interact with the Services. Much of the Services can be browsed without creating an account and without providing personal data directly to us.

Data you provide to us

  • Account data. When you create an account, we collect your email address, your name if you choose to provide one, and details of the sign-in method you use (for example, email magic-link or Google sign-in), together with any profile information you add.
  • Organisation and team data. If you create or join an organisation or team, we collect the organisation name, the identities and roles of its members, invitation details, and records of administrative actions taken within the organisation.
  • Wallet addresses. We collect blockchain wallet addresses that you submit to us, connect to the Services, or use to interact with the Services — for example, an address you use to make an x402 payment, to obtain a trial API key, to receive payments as a publisher, or to claim or annotate an entity profile.
  • Queries and prompts. We collect the natural-language prompts, SQL statements and other queries you submit to the AI SQL playground and to our APIs, together with associated metadata such as timestamps and the API key used.
  • Publisher and app content. If you use the app builder or paywall features, we collect the content, configuration and pricing information you provide, and metadata about how your published resources are accessed ("User Content" is addressed further in our Terms of Service).
  • Support and other correspondence. If you contact us — for example at legal@roundhouseai.io — we collect the contents of your correspondence and any information you choose to include in it.

Data we collect automatically

  • Usage and log data. We collect records of your interactions with the Services, including pages and profiles viewed, features used, queries run, Query Units consumed, API requests and responses metadata, error reports, and referral information.
  • Device and connection data. We collect technical information such as IP address, browser type and version, operating system, device identifiers, language settings and approximate location inferred from network information.
  • Payment-related metadata from x402 interactions. When you or your software make or receive an x402 payment through or in connection with the Services — including the small test payment used to obtain a trial API key, payments to publishers through the paywall, and payments verified or settled through our facilitator service — we collect the associated payment metadata, such as wallet addresses, payment authorisations, transaction hashes, amounts, asset and network identifiers, and verification and settlement outcomes. We do not hold your funds or your private keys at any time.
  • Cookies and similar technologies. We and our service providers use cookies and similar technologies as described in our Cookie Policy.

Data from third parties and public sources

  • Sign-in providers. If you sign in using a third-party provider such as Google, we receive the information that provider makes available to us for authentication, such as your email address and basic profile details.
  • Public blockchain and registry data. We collect publicly available data from blockchain networks and public identity registries, as described in the next section.
  • Service providers. We may receive data from providers that help us operate the Services, such as security, analytics and infrastructure providers.

We do not require you to provide a legal name to browse the Services, and many interactions with the Services are pseudonymous by design. However, a wallet address or other on-chain identifier may constitute personal data where it is or becomes associable with an identifiable individual, and we treat it accordingly where this Policy applies.

3. Public blockchain data

The core of the Services is an index of publicly available on-chain records. We collect and process data recorded on public blockchain networks such as Base and other EVM-compatible chains, including wallet addresses, transaction records (such as x402 settlements and stablecoin transfers), smart-contract events, and public identity records such as ENS names and ERC-8004 identity registry entries. From these records we derive entity profiles, flow-of-funds views, facilitator pages, network statistics and informational signals such as trust scores.

This data is public by design. It was made public by the participants in the relevant protocols when they broadcast transactions to, or registered records on, public, permissionless blockchain networks, and it is accessible to anyone who runs a node or queries the chain. Roundhouse does not create this data, does not control the blockchain networks on which it resides, and cannot alter, delete or erase records on the underlying blockchains. Blockchain records are, by the nature of the technology, permanent and immutable, and copies of them exist across many independent parties worldwide.

What we can influence is our own derived layer. Where appropriate, and subject to our legal obligations and the integrity of the dataset, we may de-link, correct, annotate or suppress attributions, labels or other derived records that we ourselves have generated — for example, an association between a wallet address and a name that we have inferred from public identity records or heuristics. Entity attribution on the Services is probabilistic and may be incomplete or wrong, as explained in our Data & Risk Disclaimer, and we may revise or remove our own inferences from time to time.

If you have concerns about the appearance of a wallet address, attribution or other on-chain-derived record on the Services — including a request to review or de-link an attribution relating to you — please contact us at legal@roundhouseai.io with sufficient detail for us to assess the request. We may review such requests in light of applicable law, the public nature of the underlying records and the informational purpose of the Services, and we may decline requests where the law permits.

4. How we use personal data

We use personal data for the following purposes:

  • To operate and provide the Services — including creating and administering accounts, organisations and teams; authenticating users; issuing and managing API keys; running queries you submit; publishing and serving paywalled resources on behalf of publishers; verifying and settling x402 payments at a party's request; and displaying indexed and derived data on the public surfaces of the Services.
  • Billing and metering — including administering Query Units, recording consumption of metered API and SQL access, applying free grants and any paid plans we may offer, detecting and correcting metering errors, and maintaining ledgers of credit movements.
  • Security and abuse prevention — including detecting, investigating and preventing fraud, abuse, unauthorised access, rate-limit evasion, denial-of-service activity and other conduct that violates our Acceptable Use Policy or applicable law, and protecting the Services, our users and third parties.
  • Legal and regulatory compliance — including complying with applicable laws, responding to lawful requests from authorities, establishing, exercising or defending legal claims, and enforcing our agreements.
  • Service communications — including sending you administrative messages about your account, transactions, security matters, and changes to the Services or our legal documents.
  • Improvement and analytics — including understanding how the Services are used, diagnosing and fixing problems, developing new features, improving the quality of our indexing, attribution and AI-assisted features, and producing aggregated or de-identified statistics that do not identify any individual.

We may also use personal data for other purposes that we notify to you or that are otherwise permitted or required by applicable law. Where we aggregate or de-identify data so that it no longer identifies an individual, we may use and disclose that data for any lawful purpose.

6. Disclosure of personal data

We do not sell personal data in exchange for money. We may disclose personal data in the following circumstances:

  • Service providers and processors. We engage third parties to perform services on our behalf, such as cloud hosting and infrastructure, database and storage services, content delivery, email delivery, authentication, analytics, and AI model providers used to deliver AI features. We take steps designed to limit these providers' use of personal data to the services they provide to us.
  • Within your organisation. If you are a member of an organisation or team on the Services, other members and administrators of that organisation may see information about you, such as your email address, role, API key usage and activity within the organisation.
  • Public surfaces of the Services. Data derived from public blockchains and public registries — including wallet addresses, transactions, attributions and informational signals — is displayed on the public surfaces of the Services and through our public APIs, as described in the section on public blockchain data above.
  • Professional advisers. We may disclose personal data to our lawyers, auditors, accountants, insurers and other professional advisers where reasonably necessary.
  • Authorities and legal process. We may disclose personal data to courts, regulators, law enforcement or other authorities where we believe disclosure is required or permitted by applicable law, or is reasonably necessary to protect the rights, property or safety of Roundhouse, our users or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, or sale of some or all of our business or assets, personal data may be disclosed to the parties involved and transferred as part of that transaction, subject to appropriate confidentiality arrangements.

7. International transfers

We are based in Singapore, and the Services are operated using infrastructure and service providers located in various countries. Your personal data may therefore be collected, stored and processed in Singapore and in other countries where we or our service providers operate, and those countries may have data protection laws that differ from the laws of your country of residence.

Where we transfer personal data out of Singapore or another jurisdiction whose law restricts such transfers, we take steps required by applicable law to ensure that the transferred data receives a standard of protection comparable to that required in the originating jurisdiction — for example, through contractual safeguards with the recipient or other lawful transfer mechanisms.

8. Retention

We retain personal data for as long as it is reasonably necessary for the purposes for which it was collected, or as otherwise permitted or required by applicable law. We do not apply a single fixed retention period; instead, retention is determined by criteria including:

  • whether you maintain an account or an ongoing relationship with us, and the period reasonably needed after an account is closed to complete administrative, billing and record-keeping matters;
  • our legal, regulatory, accounting and tax obligations;
  • the need to establish, exercise or defend legal claims, resolve disputes and enforce our agreements;
  • the need to maintain the security and integrity of the Services, including records used to detect and prevent fraud and abuse;
  • the operation of routine backup and disaster-recovery systems, from which data is removed in the ordinary course of their cycles; and
  • for data derived from public blockchains, the ongoing informational purpose of the public dataset, which may justify continued retention of indexed and derived records.

When personal data is no longer needed for any of these purposes, we take reasonable steps to delete it, de-identify it or cease retaining it in a form that identifies you.

9. Security

We implement administrative, technical and organisational measures that we consider reasonable and appropriate to the nature of the data we hold, designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. The specific measures we use vary by system and evolve over time, and no particular measure or technology is promised in respect of any particular data.

No method of transmission over the internet, and no method of electronic storage, is completely secure. We therefore cannot and do not guarantee the security of any personal data, and you provide personal data to us at your own risk. You are responsible for keeping your account credentials, API keys and wallet credentials confidential; we never ask for, and you should never provide to anyone, your wallet private keys or seed phrases. Where required by applicable law, we will notify affected individuals or authorities of data breaches.

10. Your rights

Under Singapore's Personal Data Protection Act 2012 (PDPA), you have the right, subject to exceptions under that Act, to request access to the personal data about you that we hold or control and information about how it has been used or disclosed within the preceding year, to request correction of an error or omission in that personal data, and to withdraw any consent you have given to our collection, use or disclosure of your personal data, on reasonable notice to us.

If you are located outside Singapore, you may have additional rights under the laws of your location, which may include rights to erasure, restriction of processing, data portability, objection to processing, and the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at legal@roundhouseai.io with enough information for us to identify you and understand your request. Please note the following:

  • We may need to verify your identity before acting on a request, and may ask you for additional information for that purpose. For requests concerning a wallet address, we may ask you to demonstrate control of that address.
  • We may refuse, or only partially fulfil, a request where applicable law permits or requires us to do so, and where we refuse we will generally tell you why, unless the law prevents us from doing so.
  • We may charge a reasonable fee for responding to a request where applicable law permits.
  • If you withdraw consent, we may not be able to continue providing some or all of the Services to you, and withdrawal does not affect processing carried out before the withdrawal or processing conducted on a basis other than consent.
  • Rights of erasure and correction cannot be applied to records on public blockchains, which we do not control and cannot alter, as explained in the section on public blockchain data above; where appropriate, we may instead act on our own derived records.

If you are not satisfied with our handling of your personal data or of a request, you may lodge a complaint with the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg). We would appreciate the chance to address your concerns first.

11. Cookies and similar technologies

We and our service providers use cookies and similar technologies to operate the Site, keep you signed in, remember preferences, secure the Services and understand how they are used. For details of the technologies we use and the choices available to you, please see our Cookie Policy.

12. AI features

Some features of the Services use artificial intelligence — for example, the AI SQL playground, which generates SQL from natural-language prompts, and app-generation features of the app builder. When you use these features, the prompts, queries and related context you submit are processed to deliver the feature, and this processing may be carried out in part by third-party AI model providers engaged to help deliver the feature.

You should not include sensitive personal data, confidential information or secrets (such as passwords, API keys or private keys) in prompts or queries. AI-generated outputs may be inaccurate, incomplete or unsafe, are provided for your review rather than for automatic reliance, and are addressed further in our Data & Risk Disclaimer and Terms of Service.

13. Third-party sites and services

The Services link to, interoperate with, and display information about third-party sites, services and protocols — including publisher resources behind x402 paywalls, wallet software, sign-in providers, blockchain networks, identity registries and external websites. We do not control these third parties, and this Policy does not apply to their collection, use or disclosure of your data. Your interactions with them — including connecting a wallet, signing a transaction, or purchasing a publisher's resource — are governed by their own terms and privacy practices, which you should review. Roundhouse is not a party to transactions between buyers and publishers.

14. Personal data in Publisher content

Where a Publisher's User Content or paywalled resources include personal data of other individuals, the Publisher is responsible for having the consent or other lawful basis required to collect, use and disclose that data and for responding to requests from those individuals. In hosting, storing and serving such content, Roundhouse acts as a data intermediary processing the data on the Publisher's behalf and pursuant to the Publisher's instructions, and our obligations in respect of that data are limited accordingly under the PDPA.

15. Children

The Services are not directed at, and are not intended for use by, persons under 18 years of age, and we do not knowingly collect personal data from persons under 18. If you believe that a person under 18 has provided personal data to us, please contact us at legal@roundhouseai.io so that we can review the matter and, where appropriate, delete the data from our systems.

16. Changes to this policy

We may update this Policy from time to time by posting a revised version on the Site. The revised version takes effect when posted, unless it states otherwise, and the effective date at the top of this Policy indicates when it was last revised. For changes we consider material, we may take additional reasonable steps to bring the change to your attention, such as a notice on the Site or an email to account holders. Your continued use of the Services after a revised Policy takes effect constitutes your acknowledgement of the revised Policy. We encourage you to review this Policy periodically.

17. Contact

If you have any questions, concerns or complaints about this Policy or our handling of personal data, or if you wish to exercise any of your rights, please contact us:

Our Data Protection Officer

You can contact our Data Protection Officer at vanessa@roundhouseai.io, or via the contact details published on the Singapore PDPC DPO Registry. Postal correspondence for our Data Protection Officer should be marked "Attn: Data Protection Officer" and sent to our registered address.

We will endeavour to respond to enquiries and complaints within a reasonable time, but we do not commit to any particular timeframe or outcome. This Policy, and any dispute or claim arising out of or in connection with it, is governed by the laws of Singapore.

Other policies

Roundhouse AI Ltd. · 101 Telok Ayer Street, #03-02, Singapore 068574 · legal@roundhouseai.io