Privacy Policy
P2Flux does not require your wallet private key or recovery phrase. Never provide them to P2Flux or to anyone claiming to represent P2Flux.
1. Scope
This policy explains how P2Flux — payment infrastructure operated by Modulout LLC, a Wyoming limited liability company ("P2Flux", "we", "us", "our") — handles information in connection with the P2Flux website and the P2Flux payment infrastructure.
P2Flux is non-custodial payment infrastructure. It is used by merchants, platforms and developers who integrate it into their own products. Because of that model, this policy is deliberately narrow: it describes only the limited categories of information P2Flux actually handles.
Where a merchant or platform uses P2Flux inside its own product, that merchant or platform is responsible for its own privacy notice and for its relationship with its customers. P2Flux does not host the merchant's customer records or order history as a merchant account.
2. What We Never Ask For
P2Flux will never request or store:
- wallet private keys;
- recovery phrases or seed phrases.
No P2Flux process, form, integration step or support request requires them. If anyone asks you for a private key or recovery phrase in the name of P2Flux, it is not us.
3. Data the Service Does Not Require
Using the P2Flux payment infrastructure does not require P2Flux to collect:
- buyer account profiles;
- buyer identity verification profiles;
- seller identity verification profiles;
- the merchant's customer database;
- the merchant's order history as a hosted merchant account;
- custody balances, because P2Flux does not hold merchant funds.
Buyers do not create a P2Flux account in order to pay, and merchants do not go through a P2Flux onboarding profile in order to integrate. Where P2Flux later introduces a feature that requires additional information, this policy will be updated before that feature applies to you.
4. Website Visitors
You can read this website without submitting personal information. Our web server records standard request information — IP address, date and time, the path requested, the response status, the referring page and the browser user agent — in order to serve and secure the site. Those server logs are kept for 14 days and then deleted.
P2Flux does not set cookies on this website, and the site uses no browser storage. We do not use advertising, behavioural or cross-site tracking, and we do not build visitor profiles.
5. Integration Enquiries
If you submit the integration enquiry form, we receive the information you choose to provide, which may include:
- name;
- work email;
- company;
- website or product URL;
- product type;
- the integration types you are interested in;
- approximate monthly payment volume, if you provide it;
- your message.
We use this information to evaluate the enquiry, understand the integration and respond to you. Company, website and payment volume are optional.
We do not use enquiry details for advertising, and we do not add you to a marketing list on the basis of an enquiry. Enquiry correspondence is retained only for as long as reasonably necessary to handle the enquiry and any resulting business relationship.
6. Developers and Platforms
If you integrate P2Flux, we handle the information needed to provide the integration to you, such as the contact address associated with your integration, credentials issued to you, and the technical records described in section 7.
You remain responsible for the information you and your product send to the Services, including whether you are permitted to send it, and for your own obligations towards your customers.
7. Operational and Technical Data
Operating payment infrastructure necessarily generates technical records. Depending on the feature used, these may include:
- API request metadata and timestamps;
- IP addresses and security logs;
- payment and subscription identifiers;
- transaction identifiers and blockchain transaction hashes;
- wallet addresses involved in processing a payment;
- error and debug information.
This is operational and technical data, processed to provide, secure, monitor and troubleshoot the Services and to report transaction status back to the integrating system. It is not used to build customer profiles, and P2Flux does not assemble it into a consumer identity record.
Not all of these records are retained indefinitely, and some exist only transiently. Operational data is retained only for as long as reasonably necessary for the purposes for which it is processed, subject to technical, security and legal requirements.
8. Blockchain Data
Payments made using P2Flux execute on public blockchain networks. Those networks independently contain transaction information, which may include wallet addresses, transaction hashes, token transfers, amounts and block or timestamp information.
This information is public on the relevant network independently of P2Flux, and it exists because a transaction was made on that network rather than because P2Flux published it.
P2Flux cannot delete, edit or reverse a transaction that has already been recorded on a blockchain network, and cannot remove such records from third-party explorers or indexers.
9. Payments by AI Agents
This section describes what is processed when the Services are used for payments by AI agents. It adds to, and does not replace, the rest of this policy.
When a site or API charges agents through P2Flux. The seller’s software sends P2Flux the seller’s wallet address, the price, the address of the page or route requested, and the payment the agent presented, which contains the paying wallet address and a signature. P2Flux uses this to check and settle the payment, and keeps the technical records described in section 7. The request comes from the seller’s server, so P2Flux does not receive the agent’s IP address and receives nothing about human visitors, who are not asked to pay.
Prepaid balances. To account for vouchers, P2Flux stores, for each payment channel, the paying wallet address, the seller’s receiving address, the amounts signed and claimed, the latest signed voucher and the time of the last request. This is kept for as long as the channel exists and removed when the channel is closed by a refund of its remaining balance. The deposits and payouts themselves are blockchain transactions and are public, as described in section 8.
Directory. If a seller has chosen to be listed, P2Flux reads the public document the site serves for that purpose and stores the site’s address, name, description, prices, what is paid for and the titles and addresses of up to ten recent paid items, together with the receiving wallet address, which is not shown in search results. This is public information published by the site. The listing is removed when the seller switches the option off or the site stops publishing the document. Search queries sent to the directory are handled like any other API request.
WordPress plugin. The Agent Paywall plugin stores on the seller’s own site a log of payments received: time, page, amount, paying wallet address, transaction reference and, where an agent proved its identity by signing its request, the agent’s name. To check such a signature the seller’s site reads the public keys the agent publishes on its own website. That log is under the seller’s control, not ours, and is removed when the plugin is uninstalled.
Software on your device. The P2Flux MCP server runs on your own computer. The wallet key, the spending log and the prepaid records it creates stay on that computer and are not sent to P2Flux. When you use it, it contacts the websites you or your assistant choose to read, which see the request as they would from any client, and the P2Flux directory when you search it. It contains no analytics and reports nothing about its use.
Remote MCP server and payment approval page. Assistants that cannot run software on your device can use a P2Flux server instead. It has no accounts and keeps no wallet, balance or history. When your assistant asks for a paid page, the server processes the address of that page and what the page costs; when you approve on the approval page, it processes your wallet address and the signature you gave for that one payment, sends the payment to the site, and holds the text of the page for your assistant. These are kept in memory for up to 15 minutes and are not written to storage. The approval page sets no cookies and loads nothing from third parties.
10. Cookies, Storage and Tracking
P2Flux does not set cookies on this website. The site and the hosted checkout also use no localStorage, sessionStorage or comparable browser storage, so there is nothing here to consent to and no cookie banner to dismiss.
We do not use advertising, behavioural or cross-site tracking, and we load no third-party analytics. Making a payment does require your browser to contact the P2Flux API and public Base network endpoints, which section 11 describes.
11. Service Providers and Infrastructure Providers
We use third-party infrastructure where necessary to host, secure, operate and communicate through P2Flux. Today that means server hosting (Vultr), email delivery for the enquiry form and operational alerts (Resend), business email for the addresses shown on this site (Google Workspace), and encrypted off-site backups of service configuration (Backblaze B2). Each handles only what its own service requires.
Executing a payment also involves public blockchain infrastructure. P2Flux reads from and writes to the Base network through node and RPC endpoints — currently Alchemy and PublicNode alongside Base’s own public endpoint — and when you pay through the hosted checkout your browser contacts those endpoints and the P2Flux API directly, so they receive your IP address as part of that request. Public network endpoints of this kind are independent infrastructure rather than parties processing information on our instructions.
We do not share enquiry or operational information with third parties for their own marketing purposes.
12. No Data Sales or Advertising
P2Flux does not sell personal information to advertisers. P2Flux does not use payment information to build advertising profiles or to target advertising.
13. Retention
Enquiry correspondence is normally retained for up to 24 months after the last substantive communication. If the enquiry results in an ongoing business relationship, relevant correspondence may be retained for the duration of that relationship and afterwards where reasonably necessary for contractual, accounting, dispute or legal purposes.
Web server logs are kept for 14 days. Service logs from the payment API are kept for roughly 15 to 30 days, bounded by a fixed size limit. Encrypted backups of service configuration are kept for 90 days.
Records already written to a public blockchain network are outside our control, as described in section 8.
14. Legal Bases
Where data-protection law applies to what we do, we rely on: the steps you ask us to take before entering a business relationship, together with our legitimate interest in answering business and technical enquiries; our legitimate interest in operating, securing, debugging and protecting the Services against abuse, for technical and security records; and a legal obligation, where one actually applies to the record in question.
This website has no consent mechanism, because it sets no cookies and runs no tracking that would require one.
15. Your Rights
Depending on where you live, applicable data-protection law may give you rights to access, correct, delete, restrict or object to certain processing of personal information we hold about you, or to complain to a competent supervisory authority. To exercise a right, contact contact@p2flux.com.
We may need to verify your request. Two limits apply: we cannot delete records held on public blockchain networks, and we may need to retain certain records where required by law.
16. Automated Decisions
P2Flux does not use personal information for advertising profiles, and does not make solely automated decisions that produce legal or similarly significant effects on individuals.
The Services do apply automatic technical controls: rate limiting, temporarily refusing sponsored transactions, blocking abusive requests and protecting relayer capacity. Those are infrastructure and security measures, not profiling.
17. Security
We use technical and organisational measures appropriate to the limited information we handle, including access controls and encryption in transit. No system is completely secure. Because P2Flux does not hold merchant funds or wallet keys, a compromise of P2Flux systems would not give access to your funds — but you remain responsible for the security of your own wallets, keys and credentials.
18. Changes to This Policy
We may update this policy as the product develops. The date of the current version is shown at the top of this page. Where a change is material, we will aim to give reasonable notice.
19. Contact
This policy is issued by Modulout LLC, a Wyoming limited liability company, operating as P2Flux.
Privacy and legal enquiries: contact@p2flux.com
Integration enquiries: integration enquiry form