Privacy Policy
What we collect, what we deliberately do not, and what happens when an agent calls on your behalf.
1. What we collect
- Account: your email, display name and avatar, supplied by the sign-in provider you choose.
- API keys and usage: if you create an Earth API key we store the key against your account, plus a usage ledger: request counts per endpoint per day, and monthly totals. Daily detail is kept about a month and monthly totals about a year.
- Product usage: the analyses you run, the dashboards you save, and your watchlist. Saved dashboards live in your own browser storage, not on our servers.
- Technical data: IP address, user agent and request timing, used for security and rate limiting.
2. What we do not collect
- No card details: payments are handled by a third-party processor. Card data never reaches our servers.
- No wallet custody and no private keys: we never ask for a seed phrase or a private key, and we cannot move your funds.
- No model keys on our servers: if you connect your own AI model, that provider key is stored in your browser only.
- No selling of personal data, to anyone, ever.
3. Anonymous and keyed API calls
The Earth API is keyless, so most calls carry no identity at all. What that means in practice:
- Anonymous calls are counted in aggregate and rate limited by address. They are not tied to a person.
- Calls carrying your key are attributed to your account so you can see your own consumption. That ledger records which endpoint was called and when, not the response.
- Usage is counted where a request reaches our origin. Reads served from the edge cache never reach us and are never counted.
- Agents act as you: an agent using your key is recorded as your account. If you hand a key to an autonomous system, its calls are your calls.
4. Queries about places
Reads about a location are cached so that the next person asking about the same ground gets a fast answer. Those caches are keyed by the place, not by who asked. We do not build a profile of the locations an individual has looked at, and we do not use the service to track people.
5. How we use information
- To operate the service and show you your own usage.
- To enforce fair use and protect the platform from abuse.
- To send service messages about your account or plan.
- To improve reliability and coverage, using aggregate patterns rather than individual behaviour.
6. Sharing and processors
We do not sell your personal data. We share the minimum necessary with:
- Infrastructure and hosting providers that run the platform.
- A payment processor, which handles billing and holds card data under its own policy.
- Privacy-conscious product analytics, in aggregate form.
- Law enforcement, only where we are legally required.
Upstream open data providers receive no information about you. We query them for places, not for people.
7. Data storage and security
Data is held on infrastructure we control, with access limited to what operating the service requires. We use standard transport encryption and keep credentials out of source control. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
8. Your rights
You can:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and its data, including your API key and usage ledger.
- Rotate or revoke your API key at any time from the developer dashboard, which immediately stops the old one.
- Opt out of non-essential messages.
9. Cookies
We use cookies to keep you signed in and to understand aggregate platform usage. You can control them through your browser. Blocking them may sign you out but does not block the keyless API.
10. Contact
Privacy questions and data requests go to [email protected].
Last updated: 8/14/2026