{"schema":"bay-run.data-policy.v1","service":"bay-run","build":{"source_sha":"067d3be66e76897ce7a21b1598e37c96b454262c","image_digest":"sha256:0d419d6de42b7a247336d3d07e8cffcf2895840fb7811cfd5584096efafb8d9f","binding_status":"complete","generated_at":"2026-10-02T18:07:10Z"},"effective_date":"2026-08-13","training":{"customer_inputs_used_for_training":false,"cross_tenant_examples_used_for_ranking":false,"opt_in_required_for_future_cross_tenant_learning":true},"human_authorization":{"principle":"The human owner defines data, provider, region, retention, environment, and spending boundaries before delegating execution to an agent.","owner_only_authority":["control of the private OAuth client identity and any confidential-client secret","operator-attested enrollment for billing, durable-profile, private-evaluation, memory, and deletion credentials","use and revocation of purpose-specific owner-management credentials","spending-policy changes","one-use approvals above the configured threshold"],"owner_authorization_model":{"oauth_identity":"Public demo OAuth issues a fresh ephemeral token-scoped session principal per token and cannot administer developer credentials or owner-managed private state. A confidential client authenticated with its client secret establishes a durable identified principal, but still does not prove that a human approved owner-management authority.","owner_scope_enrollment":"The current build requires explicit platform-operator attestation before issuing billing:write, task_profile:owner_write, evaluation:owner_write, memory:read, memory:write, or data:delete against the OWNER key space. The free-launch session and identified memory tiers below are separate, reserved key spaces and do not grant any owner-management scope.","ordinary_agent_boundary":"Ordinary execution credentials cannot create, read, or execute a raw-retaining task profile; cannot retain a labeled private evaluation; cannot access owner-delegated durable memory; and cannot delete private state, approve spend, or change account policy. Any valid demo bearer may use its own token-scoped session memory, while registration or a bay_live_ key upgrades to the bounded durable identified tier. Both are isolated from every owner key space.","demo_memory":{"available":true,"price_usd":"0.00","retention":"EPHEMERAL","retention_semantics":"EPHEMERAL_BY_CONSTRUCTION for session memory","retention_detail":"A zero-secret bearer maps to a principal derived from its token jti/hash and expiry. Every session entry has a TTL capped by the token's remaining life (normally 86400 seconds), so expiry makes the principal unreachable. Session memory is ephemeral scratch context, not a system of record.","eligibility":"Every valid demo bearer, including the zero-secret demo grant. The token itself is the stable identity for its 24-hour lifetime.","isolation":"Demo entries are stored under a reserved principal prefix that no developer or operator principal can produce, and every read and write is scoped by that principal in the query itself. One demo principal cannot read, search, export, overwrite or delete another demo principal's entries, nor any owner-delegated entry. This boundary is fail-closed and covered by tests.","caps":{"max_rows_per_principal":50,"max_value_bytes":4096,"default_ttl_seconds":86400,"max_ttl_seconds":86400},"deletion":"DELETE /v1/memory (REST) or the `forget` MCP tool removes demo entries immediately; expiry removes them automatically regardless.","upgrade_path":"Register free with client_secret_post or use a durable bay_live_ key for 1000 rows and bounded 2592000-second identified memory. Owner-managed memory with separate purpose-specific scopes still requires operator-attested enrollment."},"durable_memory":{"available":true,"eligibility":["registered OAuth client_secret_post principal","durable bay_live_ key"],"retention":"bounded durable, default and maximum 30 days","caps":{"max_rows_per_principal":1000,"max_value_bytes":8192,"default_ttl_seconds":2592000,"max_ttl_seconds":2592000}},"delegation_limit":"Profile-bound delegation is not yet offered; an owner-scoped profile credential must not be placed in a general-purpose agent harness."},"agent_authority":"Issue only task-required scopes; autonomous prepaid execution uses a separate billing:spend + inference:invoke key that cannot carry billing:write or data:delete.","sensitive_developer_scopes":{"billing:write":{"scope":"billing:write","description":"Owner-authorized permission to manage checkout, spending policy, and approvals.","credential_role":"owner_billing_management","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"not_for_general_agent_harnesses","data_effect":"billing_and_spending_policy_management"},"data:delete":{"scope":"data:delete","description":"Owner-authorized permission to redact retained private product state.","credential_role":"owner_data_deletion","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"not_for_general_agent_harnesses","data_effect":"principal_scoped_private_data_redaction"},"memory:read":{"scope":"memory:read","description":"Owner-authorized permission to read or inject principal-scoped durable memory.","credential_role":"owner_delegated_memory_reader","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_memory_disclosure_to_the_assigned_agent"},"memory:write":{"scope":"memory:write","description":"Owner-authorized permission to create or modify principal-scoped durable memory.","credential_role":"owner_delegated_memory_writer","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_memory_retention_or_modification"},"evaluation:owner_write":{"scope":"evaluation:owner_write","description":"Owner-authorized permission to retain labeled private evaluation data.","credential_role":"owner_private_evaluation","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_labeled_evaluation_retention"},"task_profile:owner_write":{"scope":"task_profile:owner_write","description":"Owner-authorized permission to create or update raw-retaining durable task profiles.","credential_role":"owner_task_profile","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"raw_task_profile_retention"}},"payment_authorization_modes":{"stripe_prepaid":"Bay Run enforces the authenticated owner's per-call, hourly, daily, monthly, provider, task-kind, environment, and approval policy.","tokenless_x402":"The wallet signature authorizes one exact payment only. Bay Run enforces the quoted price, idempotency, and non-durable task-data boundary, but does not claim an account-level hourly, daily, or monthly policy for a tokenless payer.","tokenless_x402_owner_responsibility":"The wallet owner or agent harness must enforce wallet-level cumulative limits and approval rules before signing. Use an authenticated account route when Bay Run-side durable policy is required."},"recommended_default":"Minimize input, exclude credentials, disallow external APIs, require the actual processing region, and use none or execution_metadata retention unless the owner explicitly requests durable private state.","regulated_data":"No regulatory certification or universal suitability is claimed. The owner must confirm that this published contract satisfies any legal, contractual, or sector requirements before sending restricted data."},"task_suitability":{"decision_type":"task_specific_not_universal","use_when":["the owner permits processing in us-central1","the declared retention mode is acceptable","the selected route's provider, model license, and external-API evidence satisfy the task policy","the agent holds only the scopes and spending authority needed for the assigned task"],"do_not_use_when":["the input contains credentials or secrets","the task requires an unsupported region, certification, data-processing agreement, or regulatory control","the owner has not authorized the declared retention, provider, payment, or approval policy","the free quote reports a policy conflict or lacks evidence required by the owner"],"agent_review_sequence":["request a free task quote with explicit data and spending constraints","check can_execute_immediately and every constraint_failure","inspect recommended_route processing_region, external_api, provider, model_license, and their evidence fields","confirm data_handling_policy and quote expiration with the human owner's rules","execute only inside the quoted ceiling and verify the returned receipt"],"human_explanation_fields":["processing region and whether task data reaches an external inference API","whether customer inputs are used for training or cross-tenant learning","raw-input, output, profile, evaluation, and log retention","agent credential scopes, spending limits, and owner-only approval controls","receipt guarantees and explicit limitations"]},"task_execution":{"processing_region":"us-central1","external_inference_apis":false,"input_storage":"canonical SHA-256 only; raw task input is not stored in the task ledger","output_storage":{"none":"no raw output in the task ledger","execution_metadata":"hashes, route, latency, cost, status, and receipt only","task_profile":"raw output may be retained with the explicitly saved private profile; creation requires a billing-eligible developer credential with task_profile:owner_write"},"quote_examples":"quotes retain only an examples digest","quote_specification":"the bounded quote specification is redacted after quote expiry; IDs, hashes, route, price, and receipt evidence remain","saved_profile_examples":"retained only after explicit save_profile with a bounded TTL, then redacted by the task-retention sweep","feedback_corrections":"Accepted only for an active saved task profile through the required owner-scoped credential; public demo, static, and OAuth bearers cannot submit feedback or corrections. Payloads are redacted when that profile retention expires.","pin_feedback":{"authorization":"Only an authenticated developer principal holding the execution-scoped credential that created a committed Pin execution may submit accepted, corrected, or rejected feedback for that exact execution. A public demo, static, or OAuth bearer without that execution credential cannot submit feedback or corrections. An operator-attested evaluation:owner_write credential remains an alternate owner-scoped authority; Pin ownership and execution ownership are stored separately, and cross-tenant writes are rejected. Cross-Pin export or route changes remain owner-scoped evaluation:owner_write operations.","receipt_binding":"The service resolves an unexpired principal-scoped Pin run and verifies its Ed25519 receipt; caller-supplied Pin IDs and hashes are ignored.","hash_only_default":"Feedback stores receipt metadata and hashes by default. A private held-out row is appended only when the owner resubmits the exact receipt-bound input with a corrected or rejected label/ranking.","retention":"30 days, then correction and input payloads are redacted","training":false,"cross_tenant_learning":false,"route_change":"none; evaluation and promotion remain separate propose-only operations"},"pin_run_replays":{"retention_seconds":86400,"retention":"24 hours","stored":"A durable same-key Pin replay stores the complete Pin API response, which may echo caller-provided input; it is principal-scoped and not used for training.","after_expiry":"The response is never replayed. The same idempotency key can be reclaimed for a new request, and bounded cleanup removes the expired response payload.","physical_cleanup":"A bounded service-owned cleanup function removes expired rows; runtime table privileges do not include DELETE."},"expiry_sweep":{"maximum_interval_seconds":900,"maximum_rows_per_category_per_sweep":1000}},"other_product_state":{"memory":{"authorization":"Owner-managed memory reads, injection, writes, imports, exports, TTL updates, and deletes require a purpose-specific developer credential issued after operator-attested human-owner enrollment. The free-launch session and identified demo memory tiers are the explicit reserved-key-space exception and remain principal-scoped.","tenant_boundary":"Tenant-scoped reads, writes, imports, exports, searches, TTL updates, and deletes carry the authenticated private principal predicate. Bounded service-wide expiry maintenance is the explicit exception: it invokes only the expiry predicate and does not expose tenant data. Database row-level security is not claimed.","retention":"Manual entries use the owner-selected TTL; omitting TTL means no expiry. Automatic result memory is opt-in and expires by default after 2592000 seconds; it cannot create an indefinite entry.","expiry_maintenance":{"scope":"bounded service-wide maintenance over rows already eligible for expiry","tenant_predicate_exception":true,"maximum_rows_per_sweep":1000,"physical_deletion":"Best-effort and bounded by sweep/delete batch limits; live-row removal does not guarantee immediate physical removal from backups or infrastructure logs, and immutable accounting or receipt evidence may remain."},"receipts":"Ordinary entry/page receipt hashes are caller-held response-time digests; context-pack receipts are signed. Ordinary memory receipts are not a durable authenticated ledger.","semantic_storage":"Semantic opt-in stores the bounded raw JSON value plus a model/revision-bound embedding.","prompt_injection_boundary":"Injected memory is labeled as untrusted user data and separated from the system guard; it is context, never executable policy or tool instructions.","secret_filter_limit":"Credential-like patterns are rejected, but this is not a general DLP, PII, PHI, financial-data, or legal-data classifier. Owners must minimize and classify data before sending it.","controls":["principal-scoped bounded reads and writes","TTL and importance controls","literal and bounded semantic search","bounded export and HMAC-authenticated portable context packs","namespace or key deletion","private no-store MCP and REST responses"],"training":"Customer memory is not used for model training or cross-tenant ranking."},"private_evaluations":{"ephemeral_default":"omit namespace to avoid durable evaluation storage","explicit_persistence":"supplying a namespace retains the principal-scoped labeled dataset and scorecard until the bounded expires_in/default expiry and requires an operator-attested evaluation:owner_write credential","delete":"DELETE https://run.huggingbay.xyz/v1/eval/namespaces/{namespace}","after_expiry":"dataset, scorecard, and task hint are redacted; digests, candidate/winner, version, and timing evidence remain"},"bakeoffs":{"purpose":"optional labeled lab that scores at least two resident models from one detected task family","retained":"public=true bakeoffs that pass the strong-proof gate retain the task description, labeled examples, candidate ids, scorecard, winner, optional challenger id, signed receipt, public choice, and creation time","challenger_admission":"only the quarantine-admitted GCS mirror catalog is consulted; task inputs are never sent to Hugging Face. A compatible mirrored challenger may load on demand inside the bounded challenger timeout","quota":"the ordinary replay-aware 15/day bake-off cap and separate 2/day challenger cap both apply","author_claim":"an unauthenticated claim succeeds only when the winning public model's root README.md at the Hub-resolved revision contains the exact public bake-off claim string; the repository id, org, revision, and claim time are retained","public_default":false,"public_opt_in":"set public=true on POST /v1/bakeoff; publication still requires the complete strong-proof gate","public_retention":"only public=true bakeoffs that pass the strong-proof gate follow the configured durable backing store and operator policy; no deletion promise is made","private_behavior":"public=false is request-lifetime only: the record is not written to durable storage, the HTTP response is private, no-store, and no unauthenticated index or detail read exists","used_for_training":false},"usage_ledger":{"scope":"current authenticated principal; durable bay_live_ keys are supported","retained":"UTC-day task kind counts, input/output/total token counts, estimated Bay Run cost, and fixed latency histogram counts under a one-way principal hash","not_retained":"raw key, bearer token, task input, output, model prompt, IP, or user-agent","write_path":"existing in-memory funnel/metering counters batch-flushed about every 60 seconds and on graceful shutdown; no per-request database write","savings_limit":"Illustrative vs GPT/Claude embedding+completion list prices; excludes cache and batch discounts, long-context premiums, tools, volume terms, tokenizer differences, and task/quality equivalence. Not billing evidence.","viewer":"https://run.huggingbay.xyz/usage"},"durable_free_keys":{"secret_storage":"the bay_live_ secret is returned once; only a keyed digest and bounded prefix are stored","daily_task_quota":500,"revocation":"DELETE /v1/keys/free/{key_id} authenticated with the same key","email_required":false},"jobs":"bounded principal-scoped inputs/results until the published job TTL","job_callbacks":{"private_retention_seconds":86400,"egress":{"terminal_content":["completed.result","failed.error"],"destination":"caller_provided_callback_url","recipient_processing_retention":"controlled_by_recipient","bay_run_retention_applies_to_recipient":false},"after_expiry":"terminal callback URL, signed payload body, signature, and error detail are redacted; event identity, payload digest, status, attempts, HTTP status, and timestamps remain as delivery evidence"},"payments":{"retained":"billing and settlement evidence for replay prevention and accounting","raw_task_payload_in_payment_ledger":false,"self_service_deletion":false,"fixed_expiry_promised":false,"suitability_limit":"Do not use a payment rail when the owner's policy requires deletion of all transaction evidence or a fixed accounting-retention deadline."},"legacy_stripe_response_payloads":{"retention_seconds":86400,"allowed_range_seconds":[3600,604800],"after_expiry":"response body and transport headers are redacted; payment, idempotency, credit, and receipt evidence remains"},"catalog_request_contacts":{"retention_days":30,"after_expiry":"the private contact field is redacted; public request, status, dedupe, refusal, and moderation evidence remains"},"specialist_demand":"keyed task/example correlation digests and bounded counts only; raw task text, examples, contacts, and arbitrary caller metadata are not retained","service_logs":{"content":"request metadata and sanitized error classes/codes; Cloud Run request metadata can include source IP, user-agent, and URL. Credentials, task request bodies, memory values, and raw database errors are not intentionally logged. Use the POST body form of /v1/memory/search, including semantic=true when needed, because the deprecated GET search aliases can place search text in infrastructure URL logs","default_log_bucket_retention_days":30},"response_cache":{"scope":"tenant-bound free deterministic responses only","tiers":{"l1":"process-local memory","l2":"optional Cloud SQL PostgreSQL; fail-open and not a readiness dependency"},"durable_l2_configured":true,"durable_l2_enabled":true,"maximum_ttl_seconds":60.0,"revision_binding":"cache addresses include the deployed source revision","physical_expiry_cleanup":"best-effort background deletion runs at least once per configured TTL; expired rows are never reusable","stored":"opaque tenant/request digests plus the serialized deterministic response and bounded safe headers; the cache has no raw request, bearer-token, raw-principal, memory, task-ledger, or payment columns","durable_output_limit":"credential-shaped responses bypass L2, but this filter is not general DLP; callers must still minimize data and exclude secrets","bypasses":["paid and billing paths","task and memory paths","shared identities","dynamic routing","nondeterministic generation","requests carrying Cache-Control: no-store"],"caller_opt_out":"send Cache-Control: no-store to bypass both cache tiers"},"task_learning":{"default":"disabled and propose-only","scope":"explicitly saved, owner-scoped task profiles only","automatic_signals":["usable_success","fallback","retry_replay","timeout","provider_failure"],"semantic_outcomes":"accepted, corrected, and rejected outcomes enter learning only through explicit feedback; a technically successful execution is never inferred to be semantically accepted","retained":"bounded profile/execution identifiers, route digests and safe route metadata, and small operational evidence; no task input, output, correction payload, bearer token, or cross-tenant example is stored in the learning-event table","maximum_events_per_profile":256,"retention":"events expire with the saved profile and are removed by profile redaction or the bounded expiry sweep","route_changes":"the default only proposes reevaluation or a route change; automatic apply requires an owner-selected apply policy and a fallback route that re-passes price, provider, region, and data-policy constraints","owner_control":"PUT https://run.huggingbay.xyz/v1/task/profiles/{profile_id}/learning"},"model_artifacts":"open model artifacts may be fetched from Hugging Face or the Hugging Bay mirror; task inputs are not sent during artifact fetches"},"security":{"transport":"HTTPS/TLS","at_rest":"Google Cloud managed encryption for Cloud SQL and object storage","tenant_isolation":"authenticated principal predicates on tenant-scoped task and memory operations; bounded expiry maintenance is an explicit service-wide exception; database RLS is not claimed","secret_management":"Google Secret Manager/runtime environment; credentials are not inserted into model inputs","host_header_validation":{"enabled":true,"policy":"canonical public host plus explicitly configured Cloud Run and local operational hosts"},"forwarded_header_policy":"Uvicorn proxy-header rewriting is disabled. Application rate-limit attribution uses forwarded addresses only when the direct peer matches an operator-configured trusted proxy CIDR.","maximum_default_request_body_bytes":2097152,"maximum_chat_completions_request_body_bytes":4194304,"maximum_chat_completions_input_chars_per_message":500000,"development_and_production_policies":"separate spending-policy environments","deletion_controls":"memory, saved task profiles, and private evaluation namespaces support explicit principal-scoped redaction; expired raw content is redacted while receipt, digest, route, and accounting evidence remains. Physical deletion is best-effort and bounded; self-service deletion does not claim immediate removal from provider backups or immutable accounting logs.","certifications_claimed":[],"security_assurance_limit":"Published controls describe the current implementation; they are not a substitute for a customer-specific security review or data-processing agreement."},"subprocessors":[{"name":"Google Cloud","purpose":"runtime, database, logging, and object storage"},{"name":"Stripe","purpose":"optional card checkout and prepaid-credit accounting"},{"name":"Coinbase Developer Platform","purpose":"optional x402 verification and settlement facilitator"},{"name":"Hugging Face","purpose":"open model artifact source when a mirrored artifact is unavailable"}],"receipt_assurance":{"current_schema":"bay-run.execution-receipt.v2","integrity":"Legacy/task receipts may use HMAC-SHA256 authentication with a key identifier and an undisclosed tenant-context binding; this is a MAC, not a proof. Public Ed25519 result receipts publish a verification key and bind served Hugging Bay weight hashes.","verification_model":"Public Ed25519 result proofs are independently signature-verifiable from the receipt and published key; legacy/task MACs remain Server-verifiable authenticated evidence only, not a public-key signature and not a proof.","bound_claims":["execution identity and result timestamp","quoted and actual price","served provider and model plus fallback evidence","quoted restrictions and data policy","actual latency and quality evidence","input and output digests"],"current_state_not_receipt_bound":["later credit, dispute, revocation, or lifecycle state"],"legacy":"Legacy receipts may be HMAC-authenticated, but that is a MAC, not a proof; unbound claims are returned as null with explicit limitations.","does_not_prove":["answer truth","task quality beyond the bound evidence","model-weight identity when the receipt lacks its manifest binding","cryptographic attestation of the execution environment","legal, contractual, regulatory, or universal safety suitability"]},"security_contact":"https://run.huggingbay.xyz/.well-known/security.txt","data_rights":{"saved_task_profile_delete":"DELETE https://run.huggingbay.xyz/v1/task/profiles/{profile_id}","private_evaluation_delete":"DELETE https://run.huggingbay.xyz/v1/eval/namespaces/{namespace}","memory_delete":"DELETE https://run.huggingbay.xyz/v1/memory","operator_request_contact":"Use security@huggingbay.xyz when self-service redaction is unavailable. Minimize personal data and coordinate a secure transfer method before sending sensitive records or exploit material."}}