Last updated: July 23, 2026
Foundry Labs ("FoundryNet," "we," "us") operates the FoundryNet API, MCP server, and related services. This Privacy Policy describes how we collect, use, and protect your information.
When you create an API key, we collect your email address and payment information (processed by Stripe, we do not store card numbers, bank accounts, or payment credentials).
When you use the normalization and monitoring services, we receive and process the machine telemetry data you submit. This may include sensor readings, operational metrics, alarm codes, and machine identifiers (OEM, model, serial number, site location).
We collect information about your use of the Services, including API call counts, endpoints accessed, timestamps, and error rates. This data is used for billing, performance monitoring, and service improvement.
When data is settled on the Solana blockchain, the cryptographic hash of the data and associated transaction metadata become publicly visible and permanent. The raw underlying data is not published on-chain, only the hash.
- To provide, maintain, and improve the Services.
- To process billing and payments via Stripe.
- To normalize and process machine telemetry as requested.
- To improve the FoundryNet Canonical Schema mapping corpus using aggregated, anonymized field mapping patterns. Individual machine data is not shared across accounts.
- To communicate with you about your account, service updates, and changes to these policies.
- To detect and prevent fraud, abuse, and security incidents.
We do not sell your personal information or machine telemetry data. We may share information with:
- Stripe: for payment processing. Subject to Stripe's privacy policy.
- Solana blockchain: cryptographic hashes of settled data are published on the public Solana ledger. No raw telemetry is published on-chain.
- Infrastructure providers: Railway (hosting), Supabase (database). Subject to their respective privacy policies and data processing agreements.
- Law enforcement: if required by law, subpoena, or court order.
Machine telemetry and normalized history are retained for as long as your account is active. Upon account termination, we will retain data for 90 days to facilitate export, then delete it from our systems. On-chain settlement hashes are permanent and cannot be deleted.
Corpus feedback (field mapping corrections) may be retained indefinitely in anonymized form to improve the normalization engine.
We implement reasonable technical and organizational measures to protect your data, including:
- Encryption of webhook authentication secrets at rest (Fernet symmetric encryption).
- HMAC-SHA256 signing on all outbound webhook calls.
- API key authentication on all endpoints.
- Content-hash based idempotency to prevent duplicate processing.
- Supabase Row Level Security for account isolation.
No system is perfectly secure. We cannot guarantee absolute security of your data.
You may:
- Request a copy of your data by contacting [email protected].
- Request deletion of your account and associated data.
- Correct inaccurate information in your account.
- Opt out of non-essential communications.
The Services are hosted in the United States. If you access the Services from outside the US, your data may be transferred to and processed in the US. By using the Services, you consent to this transfer.
The Services are not directed to individuals under 18. We do not knowingly collect information from children.
We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 30 days before they take effect.
For privacy questions or data requests:
Foundry Labs
[email protected]