Privacy Policy
This Privacy Policy explains how Neosphere Inc., a Delaware C-Corporation, operating the D6N marketplace, the d6n.ai website, the D6N MCP tools, the D6N CLI and SDKs, and related services (collectively, the “Service”) (“D6N,” “we,” “us,” “our”) collects, uses, shares, retains, and protects information about you. It applies to buyers, sellers, browsers, AI agents acting on a user’s behalf, and visitors to our website. By using the Service you agree to the practices described here.
1. The information we collect
1.1 Information you give us directly
Account information
- Email address, display name, and any handle or organization name you choose;
- Authentication information from third-party sign-in providers (for example Google, Apple) where you elect to use them, including the identifiers and basic profile data those providers return;
- Password hashes (we never store passwords in plaintext) or equivalent credentials;
- Communication preferences, language, and timezone.
Seller onboarding information
If you list on D6N, Stripe Connect will collect identification and payout information directly from you, including legal name, date of birth, business name, business address, tax identification, and bank-account details. D6N does not store or have access to your bank-account number. We receive from Stripe only the verification status, the Connected Account identifier, payout currency, and operational signals required to route transactions and apply Stripe’s requirements.
Buyer payment information
If you save a payment method on D6N or pay using the Machine Payments Protocol (MPP) and a Stripe Single-Payment Token (SPT), the underlying card and bank details are collected and tokenized directly by Stripe. D6N receives only a payment-method identifier, the card brand, the last four digits, expiry, the issuing country, and the cryptographic credential needed to charge it through Stripe.
Listing content
When you publish a listing, we receive everything you submit to that listing: titles, descriptions, images, files, structured-schema fields, pricing, region restrictions, contact information you choose to publish, and the underlying digital assets you upload for Data listings.
Order and fulfillment information
To complete an order we collect the information necessary to fulfill it: shipping name and address for Physical Goods, and the files or access details needed for Data listings.
Communications
Messages you exchange with another user on an order, with our support team, or with our trust-and-safety team are retained for the periods set out in Section 4.
1.2 Information we collect automatically
- Device and connection. IP address, user-agent, operating system, device type, browser, language, referring URL, and similar technical signals.
- Usage and telemetry. Pages and listings viewed, search queries (including agent-issued queries), tools invoked, MCP-tool call traces (request and response shapes, latencies, error codes), correlation identifiers, and feature usage.
- Order-system signals. Order state transitions, SLA timestamps, return/refund events, fulfillment events from carriers (tracking updates), and payout events from Stripe.
- Cookies and similar technologies. Session cookies to keep you signed in, preference cookies to remember settings, and limited analytics cookies to understand aggregate usage. You can control cookies via your browser; disabling them may break parts of the Service. We do not use cookies for cross-context behavioral advertising.
- Approximate location. Derived from IP address and used for fraud prevention, currency presentation, regional availability, and tax routing. We do not collect precise GPS location.
1.3 Information about AI agent buyers
When an AI agent transacts on the Service using your credentials, we record information about the agent’s session that is necessary to operate the marketplace and support return, refund, chargeback, and order-support workflows: the agent platform / runtime identifier, the MCP tool calls issued, request and response payloads associated with the order, model identifiers where disclosed, spend caps and scopes you configured, and the cryptographic Payment-Credential used to complete payment. We treat this information as your information for the purposes of this Privacy Policy.
1.4 Information from third parties
- Payment partners. Stripe and any other payment processor we use return verification results, payout events, chargeback notices, fraud signals, and risk scores.
- Sign-in providers. If you sign in using a third-party provider, that provider sends us the identifiers and basic profile data described in Section 1.1.
- Carrier partners. For Physical Goods, shipping carriers return tracking and delivery events.
- Fraud-prevention and compliance vendors. Vendors that help us screen against sanctions lists, detect fraud, or verify identity may return match indicators and risk signals.
2. How we use information
We use the information described above to:
- Operate the Service, the catalog, search, listing surfaces, MCP tools, CLI, and SDKs;
- Categorize and rank listings, including via our proprietary categorization model;
- Take payment, hold and release funds via Stripe, issue refunds, contest chargebacks, and remit any tax we are required to collect as a marketplace facilitator;
- Route orders to the correct seller, fulfill orders, run order SLAs, and surface order events to both buyer and seller;
- Authenticate users, provision agent sessions, issue and validate Payment-Credentials, and enforce spend caps and scopes;
- Detect, investigate, and prevent fraud, abuse, prohibited listings, sanctioned-party transactions, account takeover, and other security events;
- Provide support, respond to questions, handle order-support workflows, and run trust-and-safety reviews;
- Send transactional messages (order updates, security alerts, refund notices, policy notices) and, where you have opted in or where the law permits, product or marketing messages you can unsubscribe from at any time;
- Measure and improve the Service, including reliability, latency, and conversion;
- Train, evaluate, and improve our categorization, search, and ranking models, using listing content, structured listing-schema data, and aggregated or de-identified interaction signals;
- Comply with law, court orders, regulatory requirements, and our agreements with payment partners.
2.1 Legal bases for processing (EEA / UK)
Where the EU or UK General Data Protection Regulation applies, our legal bases are: (a) performance of a contract (operating the Service and your transactions); (b) compliance with a legal obligation (tax, anti-fraud, sanctions, record-keeping); (c) our legitimate interests (operating, securing, and improving the Service, fighting fraud, marketing in a balanced way); and (d) your consent, where required (for example for non-essential cookies or marketing in some jurisdictions). You may withdraw consent at any time without affecting prior lawful processing.
2.2 AI model training
We use listing content, structured listing-schema data, and aggregated or de-identified interaction signals to train, evaluate, and improve D6N’s own categorization, search, ranking, and trust-and-safety models. We do not transmit your private order details, payment credentials, buyer-seller messages, or personally identifiable information to third-party model providers for the purpose of training their models, and we contractually require our processors (Section 3.1) to use the data we share with them solely to provide services to us.
2.3 No sale of personal information
We do not sell your personal information for money. We do not engage in cross-context behavioral advertising. We do not share personal information for the purpose of targeted advertising.
3. How we share information
3.1 Service providers (processors)
We share personal information with vendors that process it on our behalf and under written contract, including: cloud hosting (Google Cloud Platform), data storage and analytics, email delivery, error tracking, customer support, fraud-prevention, identity verification, and AI model providers used to run our own categorization, search, and moderation models (which may include Anthropic, Google, and others we may engage from time to time). These processors are required to use personal information solely to provide services to us and to keep it secure.
3.2 Counterparties on a transaction
To complete an order we share the information each side needs:
- To sellers, we share: buyer display name, the message thread on the order, and the fulfillment information for that order, such as shipping name and address for Physical Goods.
- To buyers, we share: the seller’s listing-public information, the message thread on the order, the seller’s name as published in the listing, fulfillment events (tracking, label generated, etc.), and any information the seller needs the buyer to receive (check-in instructions, license keys, links, attachments).
- To AI agents you authorize, we expose the listing data, order data, and confirmation details necessary for the agent to complete the workflow you delegated to it. You are responsible for the agent’s downstream handling of that data.
3.2.1 Payment partners
We share with Stripe (and any other payment processor we use for your transaction) the information necessary to charge a payment method, settle funds, issue payouts, contest chargebacks, and meet anti-money-laundering and sanctions requirements. Stripe’s use of that information is governed by Stripe’s own Privacy Policy.
3.3 Carriers and channel partners
For Physical Goods we share shipping details with the carrier the seller selects.
3.4 Legal, safety, and compliance
We may disclose information when we believe in good faith that disclosure is required by law, regulation, subpoena, warrant, or court order, or is necessary to enforce our Terms, to investigate or prevent fraud or abuse, to comply with sanctions and other regulatory regimes, or to protect the rights, property, or safety of D6N, our users, or the public.
3.5 Corporate transactions
If Neosphere Inc. is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to the counterparty. We will require the recipient to honor this Privacy Policy or to give affected users notice of any change.
3.6 With your consent or at your direction
We may share information with other parties where you direct us to do so (for example, by enabling an integration) or where you otherwise consent.
4. How long we keep information
| Category | Retention |
|---|---|
| Account data (email, display name, authentication identifiers) | For the life of the account; deleted or anonymized within 30 days of account closure, except where retention is required by law. |
| Listing content | For as long as the listing is published, plus the period needed to honor open orders, contest chargebacks, and meet legal record-keeping. |
| Order, payment, and tax records | At least seven (7) years, to meet tax and financial-services record-keeping obligations. |
| Order messaging and support tickets | Up to two (2) years after the order’s terminal state (completed, returned, cancelled, or expired), and longer if needed for an open support, refund, or chargeback matter. |
| Telemetry, MCP-tool traces, server logs | Up to twelve (12) months, then aggregated or deleted, except for security-relevant events which may be retained longer. |
| Stripe Connect identity and payout data | Held by Stripe under Stripe’s schedule; we retain identifiers, statuses, and payout events as required. |
| Aggregated or de-identified data, including model-training corpora | May be retained indefinitely. |
5. Your rights and choices
Depending on where you live, you may have some or all of the rights described below. We will not discriminate against you for exercising any of them. To exercise a right, contact support@d6n.ai. We may need to verify your identity before fulfilling the request, and we will respond within the period required by applicable law (typically within 30–45 days).
5.1 Access, correction, portability
You may request a copy of the personal information we hold about you, correct inaccurate information, and request a portable copy in a commonly used, machine-readable format.
5.2 Deletion
You may request deletion of your personal information. We will honor the request except where retention is required to: complete open orders; comply with tax, accounting, or financial-services obligations; resolve support requests or chargebacks; prevent fraud or abuse; or meet other legal requirements.
5.3 Opt-out and limit-of-use
You may opt out of non-transactional communications via the unsubscribe link in any marketing message or by contacting support@d6n.ai. We do not engage in cross-context behavioral advertising or in “sales” or “sharing” of personal information as defined by California, Delaware, Virginia, Colorado, or Connecticut law; you nonetheless have the right to confirm that.
5.4 Withdraw consent
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect prior lawful processing.
5.5 Right to appeal
If we deny a privacy request, you may appeal by replying to our response. If unsatisfied, you may contact your local data-protection authority (for EEA / UK residents) or, for U.S. state residents, your state attorney general (for example, the Delaware Department of Justice).
5.6 Delaware residents
Under the Delaware Personal Data Privacy Act (DPDPA), you have the rights described above, including the right to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We honor Global Privacy Control (GPC) signals as a valid opt-out where the DPDPA requires.
5.7 California residents
Under the California Consumer Privacy Act, as amended by the CPRA, you have the rights to know, delete, correct, opt out of the sale or sharing of personal information (we do not sell or share), limit use and disclosure of sensitive personal information, and to non-discrimination. Categories collected in the last twelve months include: identifiers (email, account identifiers), commercial information (orders, payment-method tokens), internet or network activity (telemetry, MCP-tool traces), geolocation (approximate, from IP), professional or business information (for seller accounts), and inferences derived from the above (for example, fraud risk). We have not sold or shared personal information for cross-context behavioral advertising in the last twelve months. You may designate an authorized agent.
5.8 EEA / UK residents (GDPR)
You have the additional rights to restrict processing, object to processing based on legitimate interests, and lodge a complaint with your local supervisory authority. Our lawful bases are described in Section 2.1.
5.9 Virginia, Colorado, Connecticut, and other U.S. state residents
You have rights substantially similar to those described above, including access, correction, deletion, portability, and the right to opt out of targeted advertising, sales, and certain profiling. Contact support@d6n.ai to exercise them.
6. Security
We employ administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS) and at rest where appropriate, least-privilege access controls, audit logging, secret management for credentials, rate-limiting and anomaly detection, and regular review of our security posture. No system is fully secure; we cannot guarantee absolute protection.
6.1 Breach notification
If we determine that a breach of security has resulted in unauthorized access to personal information that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law, generally within seventy-two (72) hours of becoming aware of the breach.
7. International data transfers
D6N’s primary infrastructure is in the United States. Your information may be transferred to, processed, and stored in the United States and in other countries where our service providers operate. Some of these countries may not have the same data-protection laws as your country. Where required by applicable law, we rely on appropriate transfer mechanisms (such as the European Commission’s Standard Contractual Clauses and the UK Addendum) and supplementary measures to protect personal information transferred out of the EEA or UK.
8. Children
The Service is not directed to and is not intended for children under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will delete it and terminate any associated account.
9. Third-party links and integrations
The Service may link to or integrate with third-party websites, services, models, agent runtimes, and channel managers that we do not control. We are not responsible for the privacy practices of those third parties. Review their privacy policies before engaging with them.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Updates take effect when posted; we will update the “Last updated” date above and, for material changes, give at least thirty (30) days’ notice via the Service or by email where required by law. Your continued use of the Service after a change becomes effective constitutes acceptance.
11. Contact us
For questions, to exercise your privacy rights, or to submit a data-protection request: