This policy explains what personal data SELAT AI Labs, Inc. (“SELAT”, “we”) collects when you use selat.ai, our hosted services, the SELAT Router, and the SELAT CLI and plugins. It also explains how we use that data and the choices you have. SELAT is built to need as little of your data as possible: we never hold your keys or funds, and the CLI has no telemetry.
1. The short version
- Discovery is anonymous. Downloading the catalog or using the hosted discovery server requires no account. We receive only standard request data such as your IP address.
- Search intent can leave your machine. By default,
selat searchandselat runsend your search text to our re-ranking service, which passes it to an AI model provider (section 3.3). You can turn this off. - Paid calls pass through our Router. When you pay for a call, the Router sees what you asked for (the provider URL and request body) and which wallet paid (section 3.4).
- Your wallet, email, card, and identity details stay with your wallet and onramp providers. SELAT does not receive your wallet login email, card details, or anything you enter during identity verification (KYC).
- We do not sell your personal data.
2. Data that stays on your device
The SELAT CLI and plugins run locally. They keep these files on your machine, and none of them is uploaded to SELAT:
- configuration (router URL and your wallet address);
- a payment ledger (the endpoints you called, amounts, quote IDs, statuses, and short error excerpts from failed calls);
- your session budget and freeze state;
- catalog and lookup caches;
- sample responses from skill comparisons.
The CLI includes no analytics, telemetry, or crash reporting. When you sign in to your wallet, the CLI passes your email to the wallet provider's own software (for example, Circle's CLI) on your device. It is not sent to SELAT.
3. Data we receive
3.1 Website (selat.ai)
- Analytics. We use Google Analytics to understand site traffic. It sets cookies and collects data such as pages viewed, approximate location, device, and browser. Google processes this data under its own privacy policy. In the EEA, the UK, and Switzerland, analytics cookies are off by default. Analytics data is not linked to your wallet or to API activity.
- Hosting and fonts. Our host (Vercel) and font provider (Google Fonts) receive standard request data, such as IP address and user agent, when pages load.
- Docs. Pages under /docs are served by Mintlify, which receives the same standard request data.
- Email you send us. If you email us, we keep the message and your address so we can respond.
- Waitlist. If you join our waitlist, we store your email address, the page or campaign you joined from, and the time you joined. We use this to contact you about access. [Product: include only if the waitlist ships.]
3.2 Catalog API and hosted discovery server
Catalog downloads and hosted discovery-server calls carry no account or wallet data. Our servers receive your IP address, user agent, and the request. We use these for rate limiting, security, and operations. Rate-limit counters are held in memory only.
3.3 Search re-ranking
To rank results by fit, the CLI sends the following to SELAT's re-ranking service by default:
- your search text, cut to 500 characters;
- public catalog details of up to eight candidate endpoints.
It does not send your wallet address, prices, or quotes. The service forwards the same data to an AI model provider to be scored:
- Primary path: Vercel AI Gateway, with zero data retention requested.
- Fallback: TypeSafe, used only if the primary path fails.
We do not log your search text. Scores are cached for up to 24 hours under a hashed key. Avoid putting personal or confidential information in search text. To turn re-ranking off, use --rerank off or set SELAT_RERANK=off. [Product: confirm the TypeSafe fallback's retention terms, or remove the fallback.]
3.4 Paid calls through the SELAT Router
When you pay for a call, the Router receives:
- the provider URL, including any query parameters;
- the HTTP method and request body;
- your signed payment.
From that payment we record your paying wallet address and its network. We also record the quote, the amounts, the router fee, the provider's response status, and on-chain transaction references. Our servers also log your IP address, user agent, and the request URL.
We use this data to:
- execute and settle the call;
- prevent fraud and abuse;
- process refund claims;
- keep accounting records;
- compute endpoint reliability signals.
The Router forwards your request body to the provider to complete the call. It does not log or store the body; it keeps only a one-way hash of the request for matching and fraud prevention. Reliability signals are aggregated per endpoint and do not identify you.
3.5 Refund claims
When you file a refund claim, we receive the quote ID and a signature proving you control the paying wallet. We record the claim, the wallet address, the transaction, amounts, and our decision.
3.6 Funding
Onramp (buying USDC with a card) is provided by a third-party vendor: SELAT uses Circle's Onramp Kit, and the onramp itself is provided by Transak. The CLI asks SELAT to open an onramp session for your wallet address; that address is the only information SELAT sends or receives for it. Transak collects your card details and runs identity verification (KYC) in its own window, under its own terms and privacy policy. SELAT has no access to the data you enter during KYC or checkout. Crypto deposits go directly to Circle Gateway, or through Eco when you choose that route.
4. Data that others receive
- Providers. Before routing, the CLI contacts the provider directly from your machine to read its price. That request carries your IP address and request body. The Router then forwards your request body to the provider, but not your IP address or other client headers. Each provider handles that data under its own policy.
- Public blockchains. On-chain payments are public, permanent, and linked to wallet addresses. Neither SELAT nor anyone else can delete them.
- Service providers. We use vendors for hosting, infrastructure, analytics, model inference, and email. They process data for us under contract.
- Legal and safety. We may disclose data if the law requires it, or to protect the rights, property, or safety of SELAT, our users, or others.
- Business transfers. If SELAT is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction.
5. Legal bases (EEA/UK)
We process data:
- to perform our contract with you (running the Services and calls you request);
- for our legitimate interests (security, fraud prevention, improving the Services);
- to meet legal obligations (accounting and sanctions);
- with your consent, where the law requires it (for example, for analytics cookies).
6. Retention
We keep personal data only as long as needed for the purposes above. Server logs and request metadata are kept for 30 days, then deleted. Router transaction and refund records are kept for [N] years for accounting, fraud prevention, and dispute resolution. Waitlist entries are kept until you ask us to remove them or the waitlist closes. [Product: enforce 30-day log deletion on every service, and set the record retention period.]
7. Security
We use reasonable technical and organizational measures to protect data. No system is completely secure. Because SELAT is non-custodial, a breach of SELAT's systems cannot expose your private keys or move your funds.
8. Your rights and choices
- Access, correction, deletion, objection. Depending on where you live, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict how we process it. Email legal@selat.ai. We may need to verify that you control the wallet or email concerned. We cannot delete on-chain records.
- California. We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising your privacy rights.
- Opt-outs. To turn off search re-ranking, use
SELAT_RERANK=off. To block analytics cookies, use your browser settings or Google's opt-out tool. - Complaints. You may complain to your local data-protection authority.
9. International transfers
We and our vendors may process data in the United States and other countries. Where required, we use appropriate safeguards for these transfers, such as standard contractual clauses.
10. Children
The Services are not directed to children under 18. We do not knowingly collect their personal data.
11. Changes
We may update this policy. We will post the updated version here and change the date above.
12. Contact
SELAT AI Labs, Inc. · 131 Continental Dr, Suite 305, Newark, Delaware 19713 · legal@selat.ai