Privacy policy
Last updated 2026-10-07. This covers everything Settled runs: the website at settled.tools, the HTTP API and the MCP server (/mcp and /mcp/free), the settled-x402 npm package and agent skill, the Claude plugin, the Discord and X bots, and the crawlers described on our crawlers. Settled has no user accounts, sets no cookies, shows no ads, and does not sell or share data about who uses it. Scores are never for sale.
What Settled collects, by what you do
Visiting the site
Settled is hosted on Cloudflare. Cloudflare keeps request logs for the service (the IP address the request came from, the path and query string requested, the user agent, the response status) for up to 7 days; we read them to debug problems. Page views are counted with Cloudflare Web Analytics, which uses no cookies and no fingerprinting. Nothing is stored in your browser, except by the monitor page, which only an administrator uses.
Calling the API or the MCP server
- Rate limits. Free routes allow 30 requests a minute and 300 a day per client. The per-minute limit is enforced by Cloudflare on the connecting IP address (an IPv6 /64). The daily count is kept under a truncated hash of the IP address, so the row cannot be turned back into an address, and is deleted after 7 days. Requests from Cloudflare Workers are counted under the calling zone's name instead of an address. Holders of a day pass are counted by the pass, not by address.
- What you ask about. The endpoint URLs and wallet addresses you check are counted per target per day, with no link to who asked, so the monitor can show what gets checked most; those counts are deleted after 30 days. The same URLs also appear in the Cloudflare request logs above for up to 7 days.
- The public index. An endpoint URL you check or submit that Settled has not seen before is added to the public index and probed, as our crawlers explains. The URL is stored as you gave it, except that URLs carrying a username or password, and private-network or local addresses, are refused; the npm package and the skill send only the origin and path. Do not submit URLs that carry secrets or that you want kept private. A submission over HTTP is also logged with the time and a hash of the submitting IP address, for the per-client daily limit; those log rows are deleted after 30 days.
- MCP tool calls give Settled only the tool's arguments (a URL, an address, keywords, a transaction hash, a signature). Settled never sees the rest of a conversation, your files or your model.
- Submitted reports (
/v1/report,settled_report) store whether the paid call worked together with salted hashes of the transaction hash and of the reporting wallet, so that one payment backs one report and one wallet counts once per endpoint; neither the wallet nor the transaction can be read back from what is stored. Only per-endpoint tallies are published. - Seller claims (
/v1/claim,settled_claim) store the wallet address and the name, website, contact and documentation link the seller signed, and publish them next to that wallet's endpoints: that is what a claim is for. When the contact is an email address, Seller Watch alerts are sent to it through Resend. A seller withdraws a claim withaction: remove, which deletes the profile.
Paying for something
Paid routes settle over x402 in USDC on Base. A payment is a public blockchain transaction, and Settled records what it can read from one: the paying wallet address, the amount, the transaction hash and what was bought. Payments are verified and settled by Coinbase's x402 facilitator, which receives the signed payment payload. A day pass is a signed token; Settled does not store it, so it cannot be looked up later. A Watchdog stores the endpoint it watches, the paying wallet, and the webhook URL you gave, and sends signed alerts to that webhook until the watch expires. Settled never holds, custodies or moves your funds, and never asks for a private key.
Discord and X
Settled's bots post aggregate figures to the Discord server and to @settledfyi. They never name an individual seller, buyer or wallet. The Discord server itself is run by Discord under its own policy; Settled keeps no member data beyond what Discord shows us.
The npm package, the skill and the plugin
settled-x402 sends Settled only the origin and path of the endpoint an agent is about to pay (and, for the search action, the keywords, network and price limit). Keys, payment payloads and request bodies are never sent, and local or private addresses are never sent. The skill and the plugin make the same calls over HTTP or MCP; nothing runs on your machine except the optional settled_check.py script, which calls the free check.
Who processes data for Settled
- Cloudflare: hosting, the database, request logs and Web Analytics.
- Coinbase Developer Platform: the x402 facilitator that verifies and settles payments, and the Base node Settled reads the chain through.
- Resend: Seller Watch emails, sent from alerts@settled.tools.
- GitHub, Superteam Earn, Taskmarket and the public facilitator catalogs: public listings Settled reads; nothing about you is sent to them.
- Discord and X: the aggregate posts above.
Settled reads public blockchain data (USDC transfers on Base, ERC-8004 registrations) from public nodes and explorers. That data is public by design and is not personal data Settled collected from you.
How long things are kept
| Data | Kept |
|---|---|
| Cloudflare request logs | Up to 7 days |
| Daily quota counters (hashed client) | 7 days |
| What-gets-checked counters (per target, no client) | 30 days |
| Submission log (URL, time, hashed IP) | 30 days |
| The index: endpoints, probes, scout purchases, on-chain payment records, venue measurements | As long as Settled runs; it is the product, and daily signed snapshots keep its history provable |
| Seller claims | Until the seller removes them |
| Watchdogs and their alerts | Through the watch and its renewals; ask to have an expired watch deleted |
| Reports | As long as the endpoint is in the index |
| Backups of the database | Dated copies kept by the operator, for recovery |
Your choices
- To stop Settled probing an endpoint, or to correct a label, see our crawlers.
- To remove a seller profile, sign a claim with
action: remove. - To have a report, a Watchdog or anything else tied to your wallet deleted, message @settledfyi on X or ask in Discord from an account that can prove the wallet (a signed message is enough).
Settled is not directed at children, and nothing on it is meant for anyone under 18. If this page changes, the date at the top changes with it, and the previous wording stays in the site's public history.
Machine-readable: llms.txt · openapi.json · our crawlers