media processing for agents, by VidDay

This gateway settles real USDC on base mainnet; section 2 describes what the public blockchain exposes.

ffpipe Privacy Policy

Last updated: 2026-08-13. This policy covers ffpipe, the machine-payable media-processing API operated by VidDay Media Inc. ("VidDay", "we", "us") of 772 St. Joseph Street, Winnipeg, Manitoba, R2H 3A7, Canada. It is the ffpipe-specific companion to the VidDay Privacy Policy, which governs the vidday.com sites and services; where you use both, each policy governs the service it names. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

ffpipe is deliberately different from most online services: there are no accounts, no registration and no profiles. We do not ask who you are, and in most cases we could not identify you if we tried. What follows describes the little we do collect, why, and what happens to it.

1. What we collect

When you (or software acting for you) call the API, we collect:

  • Payment information: the wallet address that signs each payment, the amounts, and the on-chain settlement transaction references. We never see or hold your private keys.
  • Technical information: the IP address a request came from, request timestamps, job parameters (dimensions, presets, source URLs you supply), job identifiers, and error messages.
  • Your media, transiently: the source file you point us at or upload, and the converted result. We process media solely to perform the job you paid for and to investigate suspected abuse. We do not sell it, mine it, or use it to train models.

We do not collect names, email addresses, phone numbers or payment-card details — the service has nowhere to put them. If you email us (for example an abuse report), we collect what you send.

2. The blockchain is public — and permanent

Payments are made in USDC on a public blockchain. This has privacy consequences no policy can change, so be aware of them:

  • Every payment you make to ffpipe is publicly visible, forever, on the blockchain: your wallet address, our address, the amount and the time. Anyone can view it with a block explorer.
  • We do not control the blockchain and cannot delete, amend or hide anything recorded on it. Deletion rights under privacy law cannot apply to a decentralized public ledger.
  • Wallet addresses are pseudonymous, not anonymous. If you link your wallet to your identity elsewhere, your ffpipe payment history is linkable too. If that matters to you, use a wallet dedicated to this service.
  • Payment verification and settlement are performed by a third-party facilitator (Coinbase Developer Platform), which processes the payment authorization your wallet signs — including your wallet address — under its own privacy policy and legal obligations (including sanctions screening).

3. Why we collect it

We use the information above only to: run the job you paid for; deliver the result to whoever holds the job's access token; operate, secure and rate-limit the service (abuse prevention, per-payer limits, settlement-failure containment); investigate suspected abuse or fraud; comply with legal obligations, including mandatory reporting of child sexual abuse and exploitation material; and produce internal, aggregate operational statistics (counts and revenue totals that identify no one). We do not use it for marketing, we do not build profiles, and we do not sell personal information.

4. Disclosure

We disclose information only: to our third-party service providers (network and edge services, computing, storage, and payment facilitation — including the Coinbase Developer Platform, whose facilitator processes every x402 payment), each only what its role requires; where required by law, including reports under the Act respecting the mandatory reporting of Internet child sexual abuse and exploitation material by persons who provide an Internet service to Cybertip.ca and law enforcement, and preservation of related records for the statutory period; and where you direct or consent to it. Result and status URLs are disclosed to whoever presents the job's access token — guard your tokens.

5. International transfers

ffpipe runs on third-party infrastructure located in Canada and the United States, and on a globally distributed edge network. Information stored or processed outside your country of residence is subject to the laws of the country where it is held, and may be accessible to that country's authorities under those laws. Our contracts with these providers include confidentiality and data-protection safeguards, and our practices remain governed by this policy wherever the data sits.

6. Retention — short by design

  • Source media: deleted at every job's terminal state, with a 7-day automated backstop. Never kept longer than 7 days.
  • Results: guaranteed available for 24 hours after completion; deleted no later than 7 days after completion.
  • Job metadata (wallet address, IP, parameters, timestamps, errors): kept up to 30 days for operations, billing forensics and abuse investigation, then expires.
  • Abuse-control records (rate counters, settlement strikes, retry vouchers): expire automatically within 48 hours to 30 days of creation.
  • Exception: records subject to a legal hold — including statutory preservation for a mandatory report — are kept for the period the law requires, then destroyed.
  • The blockchain: as section 2 explains, on-chain payment records are permanent and outside our control.

7. Safeguards

We protect the information we hold with technical measures (encryption in transit everywhere; encrypted storage; scoped, revocable credentials between every component; HMAC-gated access tokens; secrets management), administrative measures (least-privilege access, documented abuse and legal-hold procedures) and the structural safeguard of simply holding very little for very long. No security is absolute; we design so that what a breach could expose is small and short-lived.

8. Children

ffpipe is a developer- and machine-facing service, not directed at minors, and processing media that sexually victimizes children is prohibited, reported and permanently banned wherever we detect it (see the Terms of Service).

9. Your rights: access, correction, withdrawal

You may ask what personal information we hold about you, ask us to correct it, or withdraw consent to further collection (which, for a pay-per-use service, simply means ceasing to use it — nothing about past on-chain payments can be withdrawn). One honest caveat: because the service is pseudonymous, we usually cannot link data to a person — so for any request concerning a wallet's records, we require proof you control that wallet (signing a message we specify with the wallet's key), which is the same proof the protocol itself uses. Requests are answered within a reasonable time and at no cost, subject to the legal exceptions PIPEDA provides (for example where records are part of an investigation or legal hold, or where data has already been irreversibly deleted on schedule).

10. Contact and complaints

VidDay Privacy Officer — Mailing address: 772 St. Joseph Street, Winnipeg MB, R2H 3A7 Canada. Email: support@vidday.com (privacy matters) or abuse@vidday.com (service abuse and takedowns — include the job id).

We investigate all complaints about our handling of personal information and will tell you the outcome; justified complaints lead to corrective measures. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).

11. Changes

We may update this policy; the current version is always at /privacy, and the "last updated" date above changes with it. Material changes take effect when posted. Continued use of the service after a change means you accept it.