Spendkit
Spendkit

Privacy

Spendkit is designed so payment funds and protected-wallet private keys remain outside Spendkit.

Information processed

Sensitive credentials

Spendkit Server does not receive or store the Agent Payment Wallet private key. New Runtime client_secret values are encrypted at rest and can be viewed again by their authenticated Dashboard owner. Older connections created before encrypted storage may only have a one-way credential hash; those original secrets cannot be recovered, but an owner can import a secret they still have or replace the connection. The Payment Wallet key remains in local Runtime configuration and is never sent to Spendkit Server.

Service providers and public chains

The current service uses Google/Supabase for authentication and data services, Vercel for application hosting, and Arbitrum/RPC infrastructure for blockchain reads and transactions. Blockchain addresses, Policies and transactions submitted onchain are public and may be permanent.

Retention and deletion

Offchain records are retained as needed to operate the service, provide audit/reconciliation history, prevent abuse and satisfy security requirements. Policy-bound Agent records may be preserved as audit history even after the Policy is revoked. Onchain records cannot be deleted by Spendkit.

Current environment

The current public deployment is a developer/testnet product on Arbitrum Sepolia. Do not treat testnet assets as real-world stored value.