{"schema":"bay-run.data-policy.v1","service":"bay-run","effective_date":"2026-08-13","training":{"customer_inputs_used_for_training":false,"cross_tenant_examples_used_for_ranking":false,"opt_in_required_for_future_cross_tenant_learning":true},"task_execution":{"processing_region":"us-central1","external_inference_apis":false,"input_storage":"canonical SHA-256 only; raw task input is not stored in the task ledger","output_storage":{"none":"no raw output in the task ledger","execution_metadata":"hashes, route, latency, cost, status, and receipt only","task_profile":"raw output may be retained with the explicitly saved private profile"},"quote_examples":"quotes retain only an examples digest","saved_profile_examples":"retained only after explicit save_profile with a bounded TTL"},"other_product_state":{"memory":"explicit principal-scoped writes with TTL/delete/export controls","jobs":"bounded principal-scoped inputs/results until the published job TTL","payments":"billing and settlement evidence is retained for replay prevention and accounting","service_logs":"request metadata and error codes; credentials and task request bodies are not intentionally logged","model_artifacts":"open model artifacts may be fetched from Hugging Face or the Hugging Bay mirror; task inputs are not sent during artifact fetches"},"security":{"transport":"HTTPS/TLS","at_rest":"Google Cloud managed encryption for Cloud SQL and object storage","tenant_isolation":"authenticated principal predicates on every task-store query; database RLS is not claimed","secret_management":"Google Secret Manager/runtime environment; credentials are not inserted into model inputs","development_and_production_policies":"separate spending-policy environments"},"subprocessors":[{"name":"Google Cloud","purpose":"runtime, database, logging, and object storage"},{"name":"Stripe","purpose":"optional card checkout and prepaid-credit accounting"},{"name":"Coinbase Developer Platform","purpose":"optional x402 verification and settlement facilitator"},{"name":"Hugging Face","purpose":"open model artifact source when a mirrored artifact is unavailable"}],"receipt_limitations":"Receipts authenticate bounded stored execution, routing, hashes, and amount evidence. They do not prove answer truth, quality, model-weight identity at serve time, or a cryptographically attested execution environment.","security_contact":"https://run.huggingbay.xyz/.well-known/security.txt"}