Privacy Policy
P2Flux does not require your wallet private key or recovery phrase. Never provide them to P2Flux or to anyone claiming to represent P2Flux.
1. Scope
This policy explains how P2Flux — payment infrastructure operated by Modulout LLC, a Wyoming limited liability company ("P2Flux", "we", "us", "our") — handles information in connection with the P2Flux website and the P2Flux payment infrastructure.
P2Flux is non-custodial payment infrastructure. It is used by merchants, platforms and developers who integrate it into their own products. Because of that model, this policy is deliberately narrow: it describes only the limited categories of information P2Flux actually handles.
Where a merchant or platform uses P2Flux inside its own product, that merchant or platform is responsible for its own privacy notice and for its relationship with its customers. P2Flux does not host the merchant's customer records or order history as a merchant account.
2. What We Never Ask For
P2Flux will never request or store:
- wallet private keys;
- recovery phrases or seed phrases.
No P2Flux process, form, integration step or support request requires them. If anyone asks you for a private key or recovery phrase in the name of P2Flux, it is not us.
3. Data the Service Does Not Require
Using the P2Flux payment infrastructure does not require P2Flux to collect:
- buyer account profiles;
- buyer identity verification profiles;
- seller identity verification profiles;
- the merchant's customer database;
- the merchant's order history as a hosted merchant account;
- custody balances, because P2Flux does not hold merchant funds.
Buyers do not create a P2Flux account in order to pay, and merchants do not go through a P2Flux onboarding profile in order to integrate. Where P2Flux later introduces a feature that requires additional information, this policy will be updated before that feature applies to you.
4. Website Visitors
You can read this website without submitting personal information. Our web server records standard request information — IP address, date and time, the path requested, the response status, the referring page and the browser user agent — in order to serve and secure the site. Those server logs are kept for 14 days and then deleted.
P2Flux does not set cookies on this website, and the site uses no browser storage. We do not use advertising, behavioural or cross-site tracking, and we do not build visitor profiles.
5. Integration Enquiries
If you submit the integration enquiry form, we receive the information you choose to provide, which may include:
- name;
- work email;
- company;
- website or product URL;
- product type;
- the integration types you are interested in;
- approximate monthly payment volume, if you provide it;
- your message.
We use this information to evaluate the enquiry, understand the integration and respond to you. Company, website and payment volume are optional.
We do not use enquiry details for advertising, and we do not add you to a marketing list on the basis of an enquiry. Enquiry correspondence is retained only for as long as reasonably necessary to handle the enquiry and any resulting business relationship.
6. Developers and Platforms
If you integrate P2Flux, we handle the information needed to provide the integration to you, such as the contact address associated with your integration, credentials issued to you, and the technical records described in section 7.
You remain responsible for the information you and your product send to the Services, including whether you are permitted to send it, and for your own obligations towards your customers.
7. Operational and Technical Data
Operating payment infrastructure necessarily generates technical records. Depending on the feature used, these may include:
- API request metadata and timestamps;
- IP addresses and security logs;
- payment and subscription identifiers;
- transaction identifiers and blockchain transaction hashes;
- wallet addresses involved in processing a payment;
- error and debug information.
This is operational and technical data, processed to provide, secure, monitor and troubleshoot the Services and to report transaction status back to the integrating system. It is not used to build customer profiles, and P2Flux does not assemble it into a consumer identity record.
Not all of these records are retained indefinitely, and some exist only transiently. Operational data is retained only for as long as reasonably necessary for the purposes for which it is processed, subject to technical, security and legal requirements.
8. Blockchain Data
Payments made using P2Flux execute on public blockchain networks. Those networks independently contain transaction information, which may include wallet addresses, transaction hashes, token transfers, amounts and block or timestamp information.
This information is public on the relevant network independently of P2Flux, and it exists because a transaction was made on that network rather than because P2Flux published it.
P2Flux cannot delete, edit or reverse a transaction that has already been recorded on a blockchain network, and cannot remove such records from third-party explorers or indexers.
9. Payments by AI Agents
This section describes what is processed when the Services are used for payments by AI agents. It adds to, and does not replace, the rest of this policy.
When a site or API charges agents through P2Flux. The seller’s software sends P2Flux the seller’s wallet address, the price, the address of the page or route requested, and the payment the agent presented, which contains the paying wallet address and a signature. P2Flux uses this to check and settle the payment, and keeps the technical records described in section 7. The request comes from the seller’s server, so P2Flux does not receive the agent’s IP address and receives nothing about human visitors, who are not asked to pay.
Prepaid balances. To account for vouchers, P2Flux stores, for each payment channel, the paying wallet address, the seller’s receiving address, the amounts signed and claimed, the latest signed voucher and the time of the last request. This is kept for as long as the channel exists and removed when the channel is closed by a refund of its remaining balance. The deposits and payouts themselves are blockchain transactions and are public, as described in section 8.
Directory. If a seller has chosen to be listed, P2Flux reads the public document the site serves for that purpose and stores the site’s address, name, description, prices, what is paid for and the titles and addresses of up to ten recent paid items, together with the receiving wallet address, which is not shown in search results. This is public information published by the site. The listing is removed when the seller switches the option off or the site stops publishing the document. Search queries sent to the directory are handled like any other API request.
WordPress plugin. The Agent Paywall plugin stores on the seller’s own site a log of payments received: time, page, amount, paying wallet address, transaction reference and, where an agent proved its identity by signing its request, the agent’s name. To check such a signature the seller’s site reads the public keys the agent publishes on its own website. That log is under the seller’s control, not ours, and is removed when the plugin is uninstalled.
Software on your device. The P2Flux MCP server runs on your own computer. The wallet key, the spending log and the prepaid records it creates stay on that computer and are not sent to P2Flux. When you use it, it contacts the websites you or your assistant choose to read, which see the request as they would from any client, and the P2Flux directory when you search it. It contains no analytics and reports nothing about its use.
Remote MCP server and payment approval page. Assistants that cannot run software on your device can use a P2Flux server instead. It has no accounts and keeps no wallet, balance or history. When your assistant asks for a paid page, the server processes the address of that page and what the page costs; when you approve on the approval page, it processes your wallet address and the signature you gave for that one payment, sends the payment to the site, and holds the text of the page for your assistant. These are kept in memory for up to 15 minutes and are not written to storage. The approval page sets no cookies and loads nothing from third parties.
10. Payment Links and P2Flux Gate
A merchant can create a payment link and send it to a buyer: an invoice, a fixed price, or a subscription. The payment terms — the receiving wallet address, the amount, the expiry, the schedule and the merchant’s optional description — are encoded in the link itself. P2Flux does not create a payment-link record merely because a link is created or opened. The link is carried in the part of the address that browsers do not send to web servers; the payment page sends it to the P2Flux API only to read and check its terms. Ordinary technical and security logs may still be processed as described elsewhere in this Policy.
To show a merchant what a link has collected, P2Flux keeps a small cache of what the blockchain has already answered about that link, such as the transactions that paid it.
For subscription links only, P2Flux keeps a record of each subscription so that it can collect each period without the merchant running a server: the buyer’s signed authorisation, the buyer’s and merchant’s wallet addresses, the amount and billing period, and collection state, including the last period collected, the last transaction and when the next attempt is due. A record is created only once the first period has been paid.
P2Flux does not require a buyer’s name, e-mail address or other contact details as part of a payment-link payment or subscription record. Merchants should not include sensitive personal information or unnecessary personal data in a payment-link description.
A subscription record is deleted from P2Flux’s active systems 30 days after the subscription ended; a record whose first payment did not go through after all is deleted within a few hours. Encrypted backup copies may retain those records for up to 90 days from the date of the backup, after which they are automatically deleted. Backups are used only for disaster recovery and are not used for ordinary processing; if a backup is ever restored, records that were already due for deletion are deleted again. Deleting P2Flux’s subscription record does not remove transactions or other information already recorded on a public blockchain. The buyer can stop future collection at any time by revoking the authorisation from their own wallet.
P2Flux Gate (Telegram). P2Flux Gate is a Telegram bot that lets the owner of a private Telegram channel or group admit members who subscribe through a P2Flux subscription link, and remove them when the subscription stops. Payment happens on the P2Flux payment page, never inside Telegram.
For this, P2Flux processes the Telegram user IDs of channel owners and of people who start a subscription through the bot, and the ID and title of the connected channel or group. The bot creates a random signup code for each person and payment link; it is added to the address of the payment page (including the short address on api.p2flux.com/g/ that the bot’s buttons use, which our web server may log) and stored with the subscription, so that the bot knows which Telegram account a subscription belongs to. The code contains nothing about the person. From the subscription record the bot receives only the subscription’s ID, state and how far it is paid; not wallet addresses and not amounts. We do not process names, phone numbers or messages of channel members; the bot reads only messages sent to it directly.
We process this to perform the service the channel owner and the subscriber asked for: admitting paying members and removing them when the subscription stops (contract). Telegram (Telegram FZ-LLC), which runs the platform the bot works on, receives the bot’s requests to admit, decline or remove members. The channel owner sees how many members have access.
A member’s record is deleted 30 days after their subscription ended, or 90 days after their access lapsed while the subscription was only paused — in both cases only once they are no longer in the channel. A signup that was never paid is deleted after 30 days. A channel’s record is deleted 30 days after the bot was removed from it and no member records remain. Encrypted backup copies may retain these records for up to 90 days from the date of the backup, as described above. On payment pages opened from P2Flux Gate, the buttons “Open in Coinbase Wallet” and “Open in Trust Wallet” send the address of that page (the public payment link and the signup code) to that wallet provider’s link service.
11. Cookies, Storage and Tracking
P2Flux does not set cookies on this website. The site and the hosted checkout also use no localStorage, sessionStorage or comparable browser storage, so there is nothing here to consent to and no cookie banner to dismiss.
We do not use advertising, behavioural or cross-site tracking, and we load no third-party analytics. Making a payment does require your browser to contact the P2Flux API and public Base network endpoints, which section 12 describes.
12. Service Providers and Infrastructure Providers
We use third-party infrastructure where necessary to host, secure, operate and communicate through P2Flux. Today that means server hosting (Vultr), email delivery for the enquiry form and operational alerts (Resend), business email for the addresses shown on this site (Google Workspace), and encrypted off-site backups of service configuration (Backblaze B2). Each handles only what its own service requires.
Executing a payment also involves public blockchain infrastructure. P2Flux reads from and writes to the Base network through node and RPC endpoints — currently Alchemy and PublicNode alongside Base’s own public endpoint — and when you pay through the hosted checkout your browser contacts those endpoints and the P2Flux API directly, so they receive your IP address as part of that request. Public network endpoints of this kind are independent infrastructure rather than parties processing information on our instructions.
We do not share enquiry or operational information with third parties for their own marketing purposes.
13. No Data Sales or Advertising
P2Flux does not sell personal information to advertisers. P2Flux does not use payment information to build advertising profiles or to target advertising.
14. Retention
Enquiry correspondence is normally retained for up to 24 months after the last substantive communication. If the enquiry results in an ongoing business relationship, relevant correspondence may be retained for the duration of that relationship and afterwards where reasonably necessary for contractual, accounting, dispute or legal purposes.
Web server logs are kept for 14 days. Service logs from the payment API are kept for roughly 15 to 30 days, bounded by a fixed size limit. Encrypted backups of service configuration are kept for 90 days.
Records of subscriptions collected through payment links are deleted from active systems 30 days after the subscription ends. Encrypted backup copies may retain them for up to 90 days from the date of the backup, after which they are automatically deleted; backups are used only for disaster recovery. See section 10. Records kept for P2Flux Gate (Telegram) are deleted as described in section 10. Information already recorded on a public blockchain cannot be deleted by P2Flux.
Records already written to a public blockchain network are outside our control, as described in section 8.
15. Legal Bases
Where data-protection law applies to what we do, we rely on: the steps you ask us to take before entering a business relationship, together with our legitimate interest in answering business and technical enquiries; our legitimate interest in operating, securing, debugging and protecting the Services against abuse, for technical and security records; and a legal obligation, where one actually applies to the record in question. For payment-link subscriptions, we process the information necessary to provide the recurring-payment service requested by the payer and to perform our agreement with the payer, including storing and acting on the payer’s signed authorisation. We may also process limited information where necessary for our legitimate interests in securing, operating and protecting the Services.
This website has no consent mechanism, because it sets no cookies and runs no tracking that would require one.
16. Your Rights
Depending on where you live, applicable data-protection law may give you rights to access, correct, delete, restrict or object to certain processing of personal information we hold about you, or to complain to a competent supervisory authority. To exercise a right, contact contact@p2flux.com.
We may need to verify your request. Two limits apply: we cannot delete records held on public blockchain networks, and we may need to retain certain records where required by law.
17. Automated Decisions
P2Flux does not use personal information for advertising profiles, and does not make solely automated decisions that produce legal or similarly significant effects on individuals.
The Services do apply automatic technical controls: rate limiting, temporarily refusing sponsored transactions, blocking abusive requests and protecting relayer capacity. Those are infrastructure and security measures, not profiling.
18. Security
We use technical and organisational measures appropriate to the limited information we handle, including access controls and encryption in transit. No system is completely secure. Because P2Flux does not hold merchant funds or wallet keys, a compromise of P2Flux systems would not give access to your funds — but you remain responsible for the security of your own wallets, keys and credentials.
19. Changes to This Policy
We may update this policy as the product develops. The date of the current version is shown at the top of this page. Where a change is material, we will aim to give reasonable notice.
20. Contact
This policy is issued by Modulout LLC, a Wyoming limited liability company, operating as P2Flux.
Privacy and legal enquiries: contact@p2flux.com
Integration enquiries: integration enquiry form