Privacy Policy
Last updated: July 2026
Payaion is a file transfer service with paid downloads settled in USDC. You sign in with a wallet, so we never ask for your name, your ID or your bank details. This policy explains the data we do process, why we process it, who we share it with, and how long we keep it. It covers the Payaion website, the dashboard, the Aion HTTP API and our MCP servers.
Who is responsible
Payaion is a service of DEFDONE sp. z o.o., Floriana Stablewskiego 43/4, 60-213 Poznań, Poland (KRS 0000933095, NIP 7792532726, REGON 520521883), which is the controller of your personal data (“we”). For any privacy question or request, write to contact@payaion.com. We do not have a statutory Data Protection Officer; that address reaches the people who can act on your request.
What we process, and on what basis
| Data | Why | Legal basis |
|---|---|---|
| Wallet address and the signature you sign at login | Identify your account, authorise uploads, route payouts | Contract |
| Email or social login used for an embedded wallet | Handled by our wallet provider (Reown) to create your wallet. We receive and store only the resulting address, not your email | Contract |
| File contents you upload | Stored on Walrus so your recipient or buyer can download them | Contract |
| Upload metadata: file name, size, type, checksum, expiry, download counters, optional password hash | Serve the download, enforce plan limits, expire files on time | Contract |
| API key records: key hash and prefix, label, scopes, optional IP allowlist, last-used timestamp | Authenticate your agents, let you revoke access, trace abuse | Contract, legitimate interest (security) |
| Payment records: payer address, amount, currency, chain, transaction hash, subscription period, purchased listing | Unlock what you paid for, prevent replayed payments, keep our books | Contract, legal obligation (accounting) |
| Listing title, description and tags you write | Show your listing on the public marketplace | Contract |
| IP address, user agent and request logs from our servers | Rate limiting, abuse and fraud prevention, debugging outages | Legitimate interest |
| Emails and abuse reports you send us | Answer you, investigate reported listings | Legitimate interest, legal obligation |
| Usage analytics | Understand which pages and features get used. Google Analytics runs only if you accept cookies; Vercel Web Analytics counts page views without cookies or identifiers | Consent (Google), legitimate interest (cookieless) |
A wallet address is pseudonymous but it can be linked back to a person, so we treat it as personal data throughout this policy.
What we never do
- We do not sell, rent or trade your data, and we run no ad networks.
- We do not build cross-site profiles and do not use your files to train models.
- We do not inspect the contents of your files, except where a report or a legal obligation forces us to look at a specific upload.
- We do not hold your private keys, cannot move your funds, and cannot sign anything on your behalf.
- We ask for no identity documents and run no KYC checks.
Who processes data for us
We use service providers for hosting and databases (mainly in the EU), wallet connection, rate limiting, and — only if you accept cookies — analytics. Some of them may process data in the United States; those transfers rely on the European Commission's standard contractual clauses or the EU–US Data Privacy Framework. A current list of processors is available on request at contact@payaion.com.
File storage on Walrus and payments on Base are public networks, not processors we can bind by contract — see the next section.
Data that is public and cannot be deleted
- Payments. Every subscription and purchase is a transaction on Base. The addresses, amounts and timestamps are public and permanent. Neither you nor we can edit or erase them.
- Files. Uploads are stored as blobs on Walrus, a public storage network. Anyone who learns a blob identifier can fetch the bytes. When a file expires or you delete it, we remove our record and stop paying to keep it stored, but we cannot guarantee that every copy on that network disappears immediately.
- Marketplace listings. Titles, descriptions, prices and the seller address are public by design.
The practical rule: encrypt anything sensitive before you upload it, and do not put data on Payaion that you could not tolerate becoming public.
How long we keep things
- Files. Anonymous transfers expire after 12 or 24 hours. Basic accounts keep files for 30 days. Pro files live while the subscription is active plus a 14-day grace window after it lapses.
- Purchased downloads. A buyer keeps access for 30 days from the purchase, even if the seller's own retention is shorter.
- Upload metadata. Removed by our daily cleanup job after the file expires.
- Payment records. Kept as long as tax and accounting law requires us to keep them, which in Poland is five years from the end of the accounting year.
- API keys. Kept until you revoke them; revoked records are retained briefly so we can audit what a compromised key did.
- Server logs. Short-lived, retained by our hosting providers for a limited operational window and not used to build profiles.
- Sessions. A signed-in session expires after 8 hours.
Security
Traffic runs over TLS. API keys are stored only as hashes, so a database leak does not expose usable keys and we cannot show you a key again after creation. Download links are signed and time-limited. Database access is restricted per row. No service is unbreakable; if a breach ever affects your data we will notify the supervisory authority and, where required, you.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to a particular use, or export it in a portable format. Where we rely on consent — analytics cookies — you can withdraw it at any time from the Cookie Policy page. Write to contact@payaion.com and we will answer within one month.
Two honest limits. We identify accounts by wallet address, so to act on a request we need you to prove control of that address, normally by signing in. And as explained above, we cannot erase what is already on a public blockchain or on Walrus.
If you think we handled your data badly, you can complain to your local data protection authority — in Poland, the President of the Personal Data Protection Office (UODO).
Automated decisions
We do not profile you and make no automated decisions with legal effect. Some enforcement is automatic and rule-based: rate limits, plan limits, and suspension of storage access after an abuse report. Those decisions are reviewable by a human — email us and we will look at your case.
Children
Payaion is not intended for children. Do not use the service or create an account if you are under 16.
Marketplace reports and account review
Anyone can report a listing. If a report suggests abuse we may review the account and temporarily restrict uploads, downloads and marketplace features while we investigate. What that means for your account is set out in the Terms — Marketplace listing policy.
Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we use your data, we will say so in the product before it takes effect.
Contact
contact@payaion.com — privacy requests, abuse reports and anything else about this page.