Privacy Policy
SpreadX Inc., a Delaware corporation ("SpreadX", "we", "us"), operates Incarna at incarna.io and api.incarna.io.
Contact: contact@spreadx.ai — for privacy questions, data access, correction, deletion and appeals. A person reads it.
Last updated: 6 August 2026
What Incarna is, in privacy terms
Incarna gives a software agent a consistent operating identity: a residential network presence in a chosen country, a fixed device fingerprint, a generated persona, an email inbox and a wallet. Our customers are the businesses and developers who create those identities. Most of what we hold is created by our customers, about identities they control.
Two things we do not do, stated first because they change what this policy has to cover:
- We do not manufacture proof of personhood. We collect no government identification, no biometrics, and nothing that asserts a human being exists where one does not. An identity operated through Incarna is a consistent presence on a network; it is not a claim to be a person.
- We do not write what an identity says. Message and post text is supplied by the customer's own software. We transmit it; we do not generate it.
What we collect
From you, when you sign up
Sign-in is handled by Clerk. We receive and store your Clerk user id, email address and display name. We never see or store your password — Clerk holds it, and we receive only the result of a completed sign-in.
What you create
Each identity you create stores: its name and handle, the country you pinned it to, the device class you chose, the browser fingerprint generated for it at creation, the persona generated from the direction you gave, and the timestamps around all of it.
Credentials for accounts you connect
When you bind a platform account — GitHub, Reddit, X — we store the credential needed to act as it. For an account bound through the platform's own consent screen that is an OAuth token with the scopes you approved. For an account imported by session cookie, it is that cookie. For GitHub, it may include the TOTP secret used to compute second-factor codes.
These are encrypted at rest with a key held in a cloud key-management service, and bound to your organization so a record decrypted outside it fails rather than succeeds. They are never written to logs in plaintext.
Inboxes are provisioned through AgentMail. We store the address and the message metadata and content that passes through it, because reading and sending mail is the feature.
What the network reports about an identity
When an identity acts, or when you run an identity check, we record what was actually observed: the egress IP address, the city and country resolved from it, the network operator, and the TLS and user-agent characteristics seen on the wire. This is how "is this identity behaving consistently" is answerable at all.
What an identity did
Posts, comments, emails sent, and the platform's own identifier for each. Plus an audit log of every action taken on an identity, who took it, and when.
Payments
Wallet addresses, chain identifiers, amounts and on-chain transaction hashes for payments settled through the x402 protocol. Blockchain records are public and permanent by design and are not under our control.
Conversations with the assistant
If you use the Playground, we store the transcript: what you asked, what the assistant answered, and the tool calls it made. The transcript is the record of what a human instructed an identity to do, which is why it outlives the browser tab.
Ordinary server logs
Request metadata, timestamps, and error traces, with credentials scrubbed.
What we do with it
We use it to run the service, and for nothing else. Specifically: to operate the identities you create, to authenticate you, to enforce rate and spending limits, to produce the audit trail you can read back, to bill and meter, to diagnose failures, and to comply with law.
We do not sell personal data. We do not share it for advertising. We do not use your content or your identities' content to train models.
Who else processes it
| Processor | What it handles | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, secrets, and the Bedrock model used to draft personas | United States (us-east-2) |
| Vercel | The web front end | United States |
| Clerk | Sign-in and session management | United States |
| AgentMail | Identity inboxes: sending, receiving, storage | United States |
| SOAX | Residential network presence | Global; egress in the country you pick |
| Coinbase Developer Platform | Wallet custody and balance lookups | United States |
| Google Cloud (Vertex AI) | Persona drafting, on deployments configured for it | United States |
| BlockRun | Model inference, when you choose it for a turn | See their terms |
| x402.org facilitator | Payment verification and settlement | Public infrastructure |
Platforms you bind an account on — GitHub, Reddit, X — receive whatever that account does, under their own terms and privacy policies. We are not a party to that relationship beyond carrying the request.
Where it lives
Primarily the United States (AWS us-east-2). Residential network presence is by definition in the country you choose. If you are in the EEA or the UK, using Incarna involves transferring your data to the United States.
How long we keep it
- Identities you delete are soft-deleted and their stored credentials are zeroized immediately. The record and its audit history remain, because an audit trail that can be erased by the party being audited is not one.
- Audit and payment records are retained as the durable record of what happened.
- API keys are stored as a prefix plus a hash, never the secret. Revoked keys stay listed with their revocation time.
- Server logs are retained for a limited operational period.
- Everything else is deleted on request.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to complain to a supervisory authority. California residents have the rights described in the CCPA/CPRA, including the right not to be discriminated against for exercising them — and note that we do not sell or share personal data as those terms are defined there.
Write to contact@spreadx.ai. We will verify that the request comes from you or an authorized agent, and respond within the time the applicable law allows. If we cannot do what you asked, we will tell you why, and you may appeal to the same address.
There are two limits worth stating rather than burying. We cannot delete a blockchain transaction — nobody can. And we do not delete audit records on request, for the reason given above; if that is your concern, deleting the identity removes its credentials and stops it acting.
Security
Credentials are encrypted at rest under a managed key and scoped to your organization. The private keys for identity wallets are held by our wallet provider, not by us. Every read is organization-scoped: a request for a resource belonging to another customer returns "not found" rather than "forbidden", because the second answer confirms the resource exists. Logging filters credentials. No system is perfectly secure, and we do not claim otherwise.
Children
Incarna is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, write to contact@spreadx.ai and we will delete it.
Changes
We will update this page and change the date above. If a change materially affects how we handle personal data, we will tell account holders by email before it takes effect.