Legal
Privacy Policy
What we collect when you use WEIR, why we collect it, who helps us process it, and the choices you have.
Last updated September 15, 2026
01
Who we are
WEIR Labs (“WEIR”, “we”, “us”) runs the website at weirapp.io, the API at api.weirapp.io and the MCP endpoint that AI apps such as Claude and ChatGPT connect to. WEIR gives AI agents a USDC wallet with spending limits and passkey approvals.
This policy explains what personal information we collect when you use WEIR, why we collect it, who helps us process it, and the choices you have. Questions: support@weirapp.io.
02
Information we collect
- Account information from Google. When you sign in with Google we receive your name, email address, profile picture and your Google account identifier. We never see your Google password.
- Passkeys. We store the public key, credential ID and basic authenticator details for each passkey you create. Your fingerprint, face or device PIN never leaves your device and is never sent to us.
- Agents and wallets. Agent names, their wallet addresses, the spending policies and limits you set, and your approval decisions.
- Transactions. Amounts, recipient addresses, memos, status, transaction hashes, network fees and timestamps for payments and deposits.
- Connected apps. Which AI apps you authorized, their client identifiers, the permissions and agents you granted, and the tokens needed to keep that connection working.
- Requests from AI apps. When a connected app uses WEIR, we receive the tool request it sends (for example “pay 5 USDC to 0x…”) and its parameters. We do not receive your full conversation with that app.
- API keys. We store only a one-way hash of each key and its last four characters.
- Technical and security data. IP address, browser and device information, request identifiers, timestamps, error logs and a security audit log of sensitive actions.
03
How we use information
- To create your account, sign you in and keep your session secure.
- To create and operate agent wallets and to carry out payments within the policies you set.
- To ask for your passkey approval when a payment or setting requires it.
- To screen transactions for sanctions and fraud, and to prevent abuse of the service.
- To show you balances, transaction history and connected apps, and to send service notices.
- To keep the service reliable, investigate problems and meet legal obligations.
We do not sell personal information and we do not use it for advertising.
04
Google user data
WEIR requests only the basic Google sign-in permissions (openid, email and profile). We use that information only to create your WEIR account, sign you in and contact you about your account.
WEIR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to others except as needed to provide the service, for security, or to comply with the law, and we never use it for advertising.
05
Blockchain transactions are public
Payments made through WEIR are recorded on the Arc blockchain. Wallet addresses, amounts and transaction details on a public blockchain are visible to anyone and are permanent. We cannot change or delete information once it is recorded on-chain.
06
Service providers
We use trusted providers to run WEIR. They process information on our behalf and only as needed:
- Circle: wallet infrastructure, transaction processing and compliance screening.
- Google: sign-in.
- Vercel: hosting for the weirapp.io website.
- Contabo: the server that hosts our API and database.
- Arc network infrastructure providers: reading blockchain data.
AI apps you connect (such as Claude or ChatGPT) are operated by their own companies under their own privacy policies.
09
How long we keep information
We keep account information while your account is active. If you ask us to delete your account, we delete or anonymize your personal information within 30 days, except records we must keep for security, fraud prevention, accounting or legal reasons (such as transaction and audit records), which we keep only as long as needed. Information recorded on the blockchain cannot be deleted.
10
Security
We protect information with encryption in transit (HTTPS), passkey authentication, hashed API keys, restricted access to production systems and secrets, and audit logging of sensitive actions. No system is perfectly secure, so please keep your devices and Google account secure and tell us right away if you suspect unauthorized use.
11
Your rights and choices
- Revoke any connected AI app at any time in Settings → Connected apps.
- Add or remove passkeys and API keys in your dashboard.
- Ask us to access, correct, export or delete your personal information.
Email support@weirapp.io to make a request. Depending on where you live, you may also have the right to complain to your local data protection authority.
12
International transfers
Our API and database run on servers in Japan, our website is served through Vercel's global network, and some providers process information in the United States and other countries. We rely on our providers' safeguards when information moves between countries.
13
Children
WEIR is not for anyone under 18, and we do not knowingly collect information from children.
14
Changes to this policy
We will update this page when our practices change and change the “Last updated” date. If a change is significant, we will tell you in the dashboard or by email before it takes effect.
15
Contact
WEIR Labs · support@weirapp.io
See also Privacy Policy · Terms of Service