Privacy
Effective 30 September 2026
This Policy
ZEAM Labs, LLC (“ZEAM Labs”, “we”, “us”) operates the websites zeamlabs.com, zeamprism.com and zeampass.com, the Prism endpoint at mcp.zeamprism.com and the Pass services at api.zeampass.com. This policy says what they collect, why, who else receives it and how long we keep it.
The same policy is posted on all three sites. Every section is shared except the last, which covers the product of the site you are reading. The product sections of all three are part of this policy: zeamlabs.com, Prism and Pass.
The Short Version
- We keep server logs, and we review them ourselves.
- No cookies, no third-party analytics or ad trackers, no accounts and no profiles.
- We do not sell or share our logs. Cloudflare carries the traffic as our network provider.
- Your wallet address is the only persistent identifier the paid services use. We never hold your money: deposits sit in settlement contracts on Base, not with us.
- Payments settle on Base, a public blockchain. Anyone can see them.
Server Logs
We keep server logs. For each request they record the IP address, the user agent, the referring page, the page or endpoint requested, the method, the time, the status and the size. We keep them to run, secure and understand traffic to our services, including who visits and which agents call them. We review them ourselves.
Our front web server writes these logs for every site and service. They rotate daily. We keep the current day and 14 daily rotations, about 15 days, and then they are deleted. Each site’s own web server also keeps a request log with the page requested, the time, the status, the referring page and the user agent; the product section says whether it holds your IP address. Those site logs are not rotated and have no automatic deletion date.
The one exception is a request that carries a credential in its path. The product section names it, and we do not log it.
How We Use Information
- To serve and bill paid calls, and to reconcile what was charged against what settled on chain.
- To return unspent balances to the wallets that funded them.
- To enforce free limits and rate limits, and to prevent abuse.
- To keep the Service secure and to debug it.
We do not build profiles, advertise, or use it for anything else.
Who Else Receives It
We do not sell, rent, trade or share our logs or any other data. The only others who receive it are:
- Cloudflare, our network and content delivery provider. Traffic to our public sites and services passes through Cloudflare on its way to our servers, so Cloudflare sees each request, including your IP address and the full path.
- Base, the public blockchain every payment settles on. What goes on chain is public by the nature of the chain.
- Sellers you call through Pass, who receive what their product section says.
- Anyone the law requires us to disclose to.
Chain Data Is Public
Deposits, charges and returns settle in USDC on Base. The wallet addresses, the amounts and the times are public and permanent. Neither we nor you can remove them. If that matters to you, pay from a wallet you are willing to have associated with the Service.
How Long We Keep It
- Front web server logs: the current day and 14 daily rotations, about 15 days.
- Each site’s own web server log: no automatic deletion date.
- Counters for free limits and rate limits: for the hour they count, as the product section states.
- Payment records, such as channel and pass records, deposits, charges and returns: kept for accounting and to return balances. They have no automatic deletion date.
- Any other log the product section names: as long as it states there. Where it states no period, there is no automatic deletion date, and we delete it on request.
- On-chain records: permanent, by the nature of the chain.
Your Rights
You can use the websites without connecting a wallet, and you can stop new collection at any time by ceasing to use the Service.
Write to info@zeamlabs.com to ask what we hold about a wallet, a pass or a channel, or to ask us to correct or delete it. If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR, including the rights of access, correction and deletion, and you can exercise them at the same address.
We cannot delete anything on chain. Deleting a payment record before its balance is returned can stop us from returning it, so we return the balance first.
Changes
We may update this policy from time to time. Changes are posted on all three sites with the same new effective date.
Contact
ZEAM Labs, LLC · info@zeamlabs.com
A Delaware limited liability company, file number 10206382.
Pass
- zeampass.com is static pages. It sets no cookies, stores nothing in your browser, and runs no analytics and no third-party scripts. Its fonts are served from the site itself. The /pass page talks to your browser wallet and to
api.zeampass.com; your wallet’s own provider handles its chain reads. The site’s own web server’s request log holds your IP address, as the front web server’s log does. - Pass runs on each seller’s own server with the seller’s own keys. A seller receives the calls your agent makes, the pass address and any grant. We do not run seller servers, and the seller’s own terms cover what it keeps.
- Buyer API and connector links. For each pass we keep the pass address, the seller and the terms it published, any grant, when the pass was made, the funding wallet address, the channel settings, the hashes and amounts of its deposits, charges and returns, and, once a withdrawal starts, the signed transaction that finishes it. We keep no pass keys. These records have no automatic deletion date.
- A connector link carries the pass key in its path (
/c/<key>/). The key is a credential, not visitor data, so our web servers do not log requests to connector links. Cloudflare carries them like all other traffic. Guard the link like a password. - While a connector link is in use, the service holds the pass key in memory so it can sign payments to the seller. It passes each tool call to the seller and returns the answer. It does not store what was asked or what came back.
- To limit abuse, the buyer API counts quotes and new passes per IP address, in memory, for one hour. Its process log names pass addresses, sellers, channels, funding wallets and transaction hashes, and has no automatic deletion date.
- Relay. It sends transactions to Base and pays their gas. It keeps no store. Its log records the transactions it sends and any errors, and rotates out once it passes 250 MB.
- Credits. It sells gate check credit. It keeps no store. Its log records the number of checks, the seller’s Pass name, the seller’s payout address and the transaction, and rotates out once it passes 250 MB. Gate checks run on the seller’s server and never reach us.
See also the Terms.