Last updated: September 18, 2026
Foundry Labs ("FoundryNet," "we," "us") operates the FoundryNet API, MCP server, and related services. This Privacy Policy describes how we collect, use, and protect your information.
When you create an API key, we collect your email address and payment information (processed by Stripe, we do not store card numbers, bank accounts, or payment credentials).
When you use the normalization and monitoring services, we receive and process the machine telemetry data you submit. This may include sensor readings, operational metrics, alarm codes, and machine identifiers (OEM, model, serial number, site location).
We collect information about your use of the Services, including API call counts, endpoints accessed, timestamps, and error rates. This data is used for billing, performance monitoring, and service improvement.
When data is settled on the Solana blockchain, the cryptographic hash of the data and associated transaction metadata become publicly visible and permanent. The raw underlying data is not published on-chain, only the hash.
- To provide, maintain, and improve the Services.
- To process billing and payments via Stripe.
- To normalize and process machine telemetry as requested.
- To improve the FoundryNet Canonical Schema mapping corpus using aggregated, anonymized field mapping patterns. Individual machine data is not shared across accounts.
- To communicate with you about your account, service updates, and changes to these policies.
- To detect and prevent fraud, abuse, and security incidents.
We do not sell your personal information or machine telemetry data. We may share information with:
Our current sub-processors are:
- Railway (application hosting, United States).
- Supabase (database, European Union, Ireland). See section 7.
- Cloudflare (DNS, TLS termination and edge delivery).
- Stripe (payment processing). Subject to Stripe's privacy policy.
- Resend (transactional email delivery).
- Anthropic (AI assistant). Used only if you use the optional chat assistant; the content of that conversation is sent to Anthropic to generate a reply.
- Plausible Analytics (website analytics on foundrynet.io). Cookieless and aggregate; it does not track individuals across sites.
- Solana blockchain: only if you explicitly enable on-chain settlement, which is off by default. When enabled, cryptographic hashes are published to the public Solana ledger and are permanent. No raw telemetry is ever published on-chain.
- Law enforcement: if required by law, subpoena, or court order.
We will update this list before adding a new sub-processor that processes personal data. If you require advance notice of sub-processor changes, ask us for a data processing agreement.
Machine telemetry, normalized history and uploaded files are retained for as long as your account is active. We do not currently apply an automatic time-based expiry to that data: it is kept until you ask us to delete it, or until your account is closed and you request deletion.
To have your data deleted, email foundrynet@proton.me. We will confirm your identity, provide an export if you want one, and delete your telemetry, uploads, normalized history and account record within 30 days of the request. This is currently a manual process carried out by a human, not an automated job.
API usage metadata (endpoint, timestamp, status code, IP address, user agent) is deleted automatically after 90 days.
Two categories cannot be deleted on request, and we would rather say so plainly than surprise you:
- Safety and contract audit records. Records of a guardrail that blocked an action, and of a contract trigger or settlement, are deliberately append-only. They are the record that a safety control fired, and removing them would defeat their purpose.
- Hashes published on-chain, if you enabled that optional feature. A public ledger cannot be rewritten. These are hashes only and contain no telemetry.
Corpus feedback (field-mapping corrections) may be retained indefinitely. It consists of tag names and the canonical field they map to (never measured values), and identifying tokens such as site and serial identifiers are stripped before it is stored.
We implement reasonable technical and organizational measures to protect your data, including:
- TLS on all connections; plain HTTP requests are redirected to HTTPS.
- API keys are stored as SHA-256 hashes, never in plaintext. Account passwords are hashed with bcrypt.
- Bearer-token authentication on all endpoints that read or write customer data. A small number of endpoints are intentionally public: service health, the published coverage list, and the demo sandbox.
- HMAC-SHA256 signing on outbound webhook calls.
- Encryption at rest for tool webhook authentication secrets, where a deployment encryption key is configured.
- Content-hash based idempotency to prevent duplicate processing.
- Row Level Security on account-scoped tables.
- Per-call audit logging of API access, retained 90 days.
We do not currently hold a SOC 2 or ISO 27001 certification, and we do not claim one.
No system is perfectly secure. We cannot guarantee absolute security of your data.
Whatever jurisdiction you are in, you may contact us at foundrynet@proton.me to:
- Request a copy of your data in a portable format.
- Request deletion of your account and associated data (see section 4).
- Correct inaccurate information in your account.
- Opt out of non-essential communications.
We respond to requests within 30 days and do not charge for them.
Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing, and the right to lodge a complaint with your national supervisory authority.
We process personal data on the basis of contractual necessity (to provide the Services you signed up for), legitimate interests (securing the Services, preventing abuse, and improving the normalization corpus using de-identified tag names), and consent where you have given it. Where you rely on consent, you may withdraw it at any time.
Personal data is stored in the European Union and processed on servers in the United States. See section 7 for how that transfer is handled. If you need a Data Processing Agreement with Standard Contractual Clauses, contact us and we will provide one.
Under the CCPA and CPRA you have the right to know what personal information we collect and how we use it, the right to request deletion, the right to correct inaccurate information, the right to data portability, and the right not to be discriminated against for exercising these rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer, because there is nothing to opt out of.
The categories of personal information we collect are identifiers (email address, IP address, account identifiers), commercial information (subscription and usage records), and internet activity (API call metadata). We collect these to provide, secure and bill for the Services. We do not collect sensitive personal information as defined by the CPRA.
To exercise any of these rights, email foundrynet@proton.me. You may use an authorised agent; we will ask for proof of authorisation.
Our infrastructure spans two regions, and we would rather be precise about it than give you a single misleading sentence:
- Application servers are in the United States (Railway, US West). This is where your requests are processed.
- The primary database is in the European Union (Supabase, Ireland, eu-west-1). This is where your account records, normalized telemetry history and uploaded files are stored at rest.
- Edge delivery and TLS termination are handled by Cloudflare's global network.
This means data is transmitted between the United States and the European Union in the course of normal operation. If you are in the EEA or the UK, personal data relating to you rests in the EU and is processed in the US. If you require Standard Contractual Clauses covering that transfer, contact us for a Data Processing Agreement.
If your organisation has a data-residency requirement that this arrangement does not satisfy, tell us before you sign. Forge can also be deployed entirely inside your own environment, in which case your telemetry never reaches our infrastructure at all.
The Services are not directed to individuals under 18. We do not knowingly collect information from children.
We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 30 days before they take effect.
For privacy questions or data requests:
Foundry Labs
foundrynet@proton.me