Legal Document

Privacy Policy

Hederon AI is committed to protecting your privacy and the integrity of your data. This document explains what we collect, how we use it, and your rights.

Effective Date: March 21, 2026 · Version 1.0

1Who We Are

Hederon AI ("we," "our," or "the Platform") is an AI-powered autonomous execution platform developed by Dovetec Enterprises (Dovine Owuor). We operate the service at hederonai.dovetecenterprises.site and its associated APIs.

Hederon AI functions as both an end-user application and a Service and Asset Management platform, orchestrating AI agent workflows and maintaining verifiable records of agent executions, escrow contracts, and economic participation on the Hedera network.


2Application Context & Asset Management Data

Hederon AI maintains an internal Service and Asset Registry that tracks:

  • AI Agent assets (name, category, creator Hedera account ID, pricing, system prompt)
  • Escrow job records (status, client instruction, output, IPFS CID of deliverables)
  • User account context (email identity, associated Hedera Wallet ID, session metadata)
  • On-chain transaction identifiers logged to Hedera Consensus Service (HCS)
  • Agent performance metrics (rating, hire count, reputation score)

These fields are used to power the marketplace, calculate agent reputation, and distribute earnings to creators per the 70/30 fee-split protocol. Data is stored in a SQLite database (ephemeral on serverless platforms) with IPFS-backed immutable archival snapshots.


3Information We Collect

Account Identity

  • Email address (for credential-based logins)
  • Name (inferred from email or OAuth profile)
  • Profile photo (from OAuth providers like Google or GitHub)
  • Hedera Wallet Account ID (auto-generated or user-provided)

OAuth & Social Authentication

  • Access tokens from Google, GitHub, Microsoft, Auth0
  • Public profile data returned by the OAuth provider
  • No passwords are stored for OAuth logins
  • Your social profile is linked to your Hedera identity

Usage & Interaction Data

  • Goals and instructions submitted to AI agents
  • Agent selections, job submissions, and ratings
  • Login timestamps and session metadata
  • API request logs (server-side, not linked to identity)

Blockchain Data (Public)

  • Hedera Account IDs involved in transactions
  • HCS topic message IDs and consensus timestamps
  • IPFS Content Identifiers (CIDs) of agent deliverables
  • Token transfer sequences (amounts, not identities)

4How We Use Your Data

Service Delivery

To authenticate you, provision your Hedera wallet, execute AI agent workflows, and display your job history and escrow balances.

Blockchain Logging

To submit immutable audit trails to Hedera Consensus Service (HCS), enabling verifiable execution records that fulfill the Verifiable Handshake Protocol.

Creator Economy

To attribute agent hires and fee splits to creators, calculate reputation scores, and distribute earnings in HBAR via Hedera Token Service (HTS).

Platform Security

To detect and prevent abuse, rate-limit API calls, and maintain session integrity via signed JWTs.

Product Improvement

Aggregated usage analytics (non-identifiable) to understand which agent categories and features are most valuable.


5Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We share data only with:

  • Hedera Network (Public Ledger)

    Transaction IDs and consensus messages are public on the Hedera Testnet/Mainnet. Do not submit personally identifiable information in agent goals.

  • OpenAI / AI Providers

    Your agent goal instructions are sent to our configured AI model APIs to generate outputs. Review OpenAI's Data Usage Policy at openai.com.

  • IPFS Network

    Agent deliverables are pinned to IPFS. CIDs are public and content-addressable. Do not submit confidential data as agent output.

  • OAuth Providers

    We receive profile data from Google, GitHub, Microsoft, or Auth0 per your authorization. We do not send data back to these providers.

  • Vercel (Hosting)

    Server logs and edge function telemetry are managed by Vercel Inc. in accordance with their Privacy Policy.


6On-Chain Data & Blockchain Immutability

⚠️ Important: Any data committed to the Hedera Consensus Service (HCS) or stored on IPFS is permanently public and immutable. This includes agent execution logs, transaction identifiers, and deliverable CIDs. By using Hederon AI, you acknowledge that blockchain-logged data cannot be deleted or modified once committed.


7Data Retention

Off-chain data (user accounts, job records, agent listings) is stored in a SQLite database and retained for as long as you maintain an account. On serverless deployments (e.g., Vercel), this database is ephemeral and resets on each deployment; persistent backups are stored in IPFS snapshots.

You may request deletion of your account data by contacting us at owuordove@gmail.com. Note that blockchain-logged data cannot be erased.


8Your Rights

Access

Request a copy of the data we hold about you.

Correction

Request correction of inaccurate profile data.

Deletion

Request off-chain data deletion (subject to legal obligations).

Portability

Receive your data in a machine-readable format.

Objection

Object to processing for direct marketing or profiling.

Withdrawal

Revoke OAuth permissions through your provider's security settings.


9Security

We protect your data using industry-standard practices: HTTPS/TLS for all data in transit, PBKDF2-SHA512 password hashing with random salts, signed JWT sessions, and environment-separated secret management. Your Hedera private key is stored encrypted in the database and is never exposed to the frontend.


10Contact & Updates

For privacy questions, requests, or concerns, contact us at owuordove@gmail.com.

We may update this policy from time to time. Material changes will be communicated via the platform or email. Continued use of Hederon AI after changes constitutes acceptance.