Skip to main content
AIRIN
PricingSign in

Locus policy evolution

Before/after stance changes across captured policy versions, with exact citations. If no before/after delta is available yet, AIRIN shows the latest citation-backed stance events instead.

Diffs
0
Improved
0
Worsened
0
Changed
0
No before/after stance delta is available for this filter yet. Latest citation-backed stance events are shown below.
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

This Privacy Policy (the "Policy" ) explains how Locus Technologies Inc. , a Delaware corporation, and its affiliates (collectively, "Locus," "we," "us," or "our" ) collect, use, disclose, store, and otherwise process information when you ( "you" or "your" ) use our services, including our websites: https://paywithlocus.com , https://beta.paywithlocus.com , https://app.paywithlocus.com , and https://buildwithlocus.com as well as any other websites associated with Locus from time to time (collectively, the "Site" ), our applications, dashboards, software development kits, including the Locus Agent SDK ( "SDKs" ), and application programming interfaces ( "APIs" ) (together the "Platform" ), and related technologies (collectively, the "Service" ). By using the Service, you agree to the practices described here. If you do not agree, do not use the Service. The Service is intended for business and developer users only. You may not use the Service for personal, family, or household purposes.
Open citation
Jul 20, 2026retentionhigh

data sharing

Latest stance: sale or sell

(not a substitute for the full policy) We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers). We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, and improve our products (including via deidentified/aggregated data). We share data with service providers (e.g., blockchain infrastructure providers, cloud hosting, communications providers), with your direction, to comply with law, and in business transfers. We do not sell personal information. You may have rights to access, correct, delete, or opt out of certain processing depending on where you live. See Your Rights & Choices .
Open citation
Jul 20, 2026retentionmedium

data sharing

Latest stance: third party or vendor sharing

(not a substitute for the full policy) We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers). We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, and improve our products (including via deidentified/aggregated data). We share data with service providers (e.g., blockchain infrastructure providers, cloud hosting, communications providers), with your direction, to comply with law, and in business transfers. We do not sell personal information. You may have rights to access, correct, delete, or opt out of certain processing depending on where you live. See Your Rights & Choices .
Open citation
Jul 20, 2026trainingmedium

data sharing

Latest stance: third party or vendor sharing

We may share information as follows: Service Providers / Sub-Processors: Vendors who host, process, or support the Service, including: AWS (cloud infrastructure, authentication via Cognito, key management via KMS, job scheduling), Cloudflare (CDN and file proxy), SendGrid (transactional email), Twilio (SMS notifications), Google Analytics (analytics), and Basis Theory (PCI-DSS Level 1 card tokenization vault). These parties are bound by contractual obligations to protect your data. Pay-Per-Use API Providers: When you use our Wrapped API proxy service, we forward your request data to third-party API providers and store both request and response payloads in our database. We provide access to over 40 third-party APIs across categories including providers such as OpenAI, Anthropic, Google Gemini, Mistral AI, Perplexity, Brave Search, Firecrawl, Deepgram, Stability AI, DeepL and others for AI, search, data enrichment, and productivity Services. The ownership of prompts you submit and outputs generated is governed by the applicable upstream provider's terms of service. Locus does not claim ownership of your prompts or AI-generated outputs. However, our storage of request and response payloads is subject to this Privacy Policy. Each upstream provider has its own privacy policy and terms governing how they process the data we send them on your behalf, intellectual property rights, training data usage and content policies.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

Embedded Wallet Platforms: Third-party platforms may embed Locus wallet infrastructure into their products. When you use Locus functionality through such platforms, we share transaction data, wallet information, and user identifiers with the embedding platform as necessary to provide the integrated service. Affiliates: Within our corporate group for operations and support consistent with this Policy. Legal, Safety & Compliance: To comply with law, regulation, legal process, or governmental request; to enforce our terms; to protect the rights, property, or safety of Locus, our Users, or the public. Business Transfers: In connection with a merger, acquisition, financing, restructuring, or sale of assets; your data may be transferred as part of that transaction. With Your Direction or Consent. No Sale of Personal Information: We do not sell personal information. If we ever engage in activities that qualify as "sharing" for cross-context behavioral advertising under applicable law, we will provide a method to opt out (including honoring Global Privacy Control ( "GPC" ) signals where required).
Open citation
Jul 20, 2026commercial usehigh

data sharing

Latest stance: sale or sell

Categories Collected: Identifiers; commercial information; internet/network activity; geolocation (approximate, inferred from IP); inferences (e.g., risk scores). Sources & Uses: As described above. Disclosures for Business Purposes: To service providers, transaction counterparties and affiliates. Sale/Sharing: We do not sell personal information. We do not engage in "sharing" for cross-context behavioral advertising or "targeted advertising" unless expressly stated in the Service. If we introduce such activities, we will provide a clear in-product method to opt out (including GPC signal recognition). Retention: See Section 6. Non-Discrimination: We will not discriminate against you for exercising your rights.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

We use or disclose sensitive personal information for the following statutorily approved reasons ( "Permitted SPI Purposes" ): Performing actions that are necessary for our consumer relationship and that an average consumer in a relationship with us would reasonably expect. Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information. Defending against and prosecuting those responsible for malicious, deceptive, fraudulent, or illegal actions directed at us. Ensuring physical safety. Short-term, transient use, such as non-personalized advertising shown as part of your current interactions with us, where we do not disclose the sensitive personal information to another third party or use it to build a profile about you or otherwise alter your experience outside your current interaction with us. Services performed for us, including maintaining or servicing accounts, processing or fulfilling transactions, verifying consumer information, processing payments, or providing financing, analytic services, storage, or similar services. Activities required to verify or maintain the quality or safety of a product, service, or device that we own, manufacture, had manufactured, or control; or improve, upgrade, or enhance the service or device that we own, manufacture, had manufactured, or controlled. Collecting or processing sensitive personal information that we do not use for the purpose of inferring characteristics about a consumer. We do not use or disclose sensitive personal information for purposes other than the Permitted SPI Purposes.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

We have not disclosed consumers' personal information to third parties for a business purpose in the preceding 12 months beyond what is described in Section 4 of this Policy. We may disclose the personal information we collect to service providers and contractors for the business purposes described in the "How We Use Information" section, such as to support our business functions. We do not sell your personal information to third parties and have not sold it in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

We have not disclosed consumers' personal information to third parties for a business purpose in the preceding 12 months beyond what is described in Section 4 of this Policy. We may disclose the personal information we collect to service providers and contractors for the business purposes described in the "How We Use Information" section, such as to support our business functions. We do not sell your personal information to third parties and have not sold it in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

You have the right to request that businesses stop selling or sharing your personal information at any time (the "right to opt-out" ), including through a user-enabled opt-out preference signal. As we do not sell or share consumers' personal information, we do not currently provide this consumer right.
Open citation
Jul 20, 2026retentionmedium

retention

Latest stance: indefinite or necessity based

We retain information as long as necessary to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce agreements. Specific retention practices include: (a) blockchain transaction data is immutable and permanently public on-chain; (b) wallets, agents, policy groups, and contacts are soft-deleted (data retained with deletion flag); (c) escrow wallets expire after a configurable period (default 30 days) and are auto-reclaimed; (d) file tokens expire after 48 hours; (e) Wrapped API call request/response payloads are retained indefinitely and are not subject to automatic deletion to support audit trails, dispute resolution, and service improvement; (f) queue jobs are retained indefinitely for audit purposes. Locus has implemented formal data deletion procedures, data de-identification processes, and provides Users with the right to request deletion or access to their data, except where retention is required by law or for compliance purposes. Retention periods for all data types are defined and documented, and secure disposal of data is performed in accordance with SOC-2 requirements. Actions taken regarding retention and deletion are documented for audit purposes.
Open citation
Jul 20, 2026retentionlow

retention

Latest stance: deletion or time bound

We retain information as long as necessary to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce agreements. Specific retention practices include: (a) blockchain transaction data is immutable and permanently public on-chain; (b) wallets, agents, policy groups, and contacts are soft-deleted (data retained with deletion flag); (c) escrow wallets expire after a configurable period (default 30 days) and are auto-reclaimed; (d) file tokens expire after 48 hours; (e) Wrapped API call request/response payloads are retained indefinitely and are not subject to automatic deletion to support audit trails, dispute resolution, and service improvement; (f) queue jobs are retained indefinitely for audit purposes. Locus has implemented formal data deletion procedures, data de-identification processes, and provides Users with the right to request deletion or access to their data, except where retention is required by law or for compliance purposes. Retention periods for all data types are defined and documented, and secure disposal of data is performed in accordance with SOC-2 requirements. Actions taken regarding retention and deletion are documented for audit purposes.
Open citation

Generated from live stance events. Informational only, not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.