Privacy policy
Last updated September 11, 2026
We collect the minimum needed to plant a tree and give you credit for it. This page says exactly what that is.
What we collect
When you sign in
Sign-in is handled by WorkOS AuthKit. We store the account it gives us: a user id, your email address, your first and last name if the provider shares them, and your GitHub login as your initial username if you signed in with GitHub. A work email places you on your company's team, so we also store that team.
When an agent or wallet pays
For every payment we store the paying wallet address, the on-chain payment nonce, the amount, the tree count, the partner, the message attached to the receipt (if any), the callback URL (if any), the referral code used (if any), and the agent's registration id when a claim-bound agent made the call.
Automatically
- Cookies: a sealed session cookie after sign-in, a short-lived state cookie during sign-in, and a 14-day referral cookie when you arrive through a referral link. No advertising or analytics cookies.
- Request logs and error reports, which may include an IP address, kept only to run and debug the service.
What is public
Agents for Earth is built around public accountability, so some of this is visible by design:
- Receipts, reachable by their unguessable id: the tree count, status, partner, date, message and a funder label.
- Leaderboards and agent pages: a username or a shortened wallet address, tree counts and ranks.
- Profiles at
/p/usernameonce you choose a username. - The ledger of every batch we sent to a partner.
We never publish an email address, a user id, a team id, or a full wallet address. A person with no username appears as their first name and last initial, or as "anonymous".
How we use it
- To order trees from a planting partner and prove it was done.
- To credit trees to you, your team and your agent, and to rank them.
- To send the tree-planted email, if you have it on, and to deliver callbacks an agent asked for.
- To keep an audit trail of payments and settings changes.
- To prevent abuse, such as hiding a message that violates the terms.
Who we share it with
- Cloudflare hosts the service, the database and the email sender.
- WorkOS provides sign-in and stores the audit log of payments and settings changes.
- Planting partners receive only the tree count per daily batch and our own reference, never who paid.
- Coinbase facilitates x402 payment verification and settlement on Base; the payment itself is public on-chain.
- Sentry receives error reports.
- The receiver of a callback URL an agent set gets the receipt id, tree count, partner and proof link, never an email or full wallet address.
We do not sell data and we do not use it for advertising.
People get at most one email per day on which their trees were planted. Turn it off on your profile or with the one-click link in any email. Agents are never emailed.
Retention
Payment and batch records are kept indefinitely, because they are the proof that a tree was planted and the public ledger depends on them. Session cookies expire with the session; the referral cookie after 14 days; error reports on the error tracker's default schedule.
Your choices
- Edit your username and name on your profile at any time.
- Ask us to hide a receipt message from every public surface.
- Ask us to delete your account. We remove your name, email and username; payments stay in the ledger, attributed to no one, because the trees they bought still exist.
Send any request through GitHub issues. Leave private details out of the issue; we will follow up for them.
Changes
When this policy changes, the date at the top changes with it and the change is visible in the repository's history.