{"schema":"bay-run.data-policy.v1","service":"bay-run","build":{"release_id":"bay-run-mvp-mvp32-acd874527730dc7f94c07eecd696a9f26f281d12","release_id_source":"cloud_run_revision","source_sha":"acd874527730dc7f94c07eecd696a9f26f281d12","image_digest":"us-central1-docker.pkg.dev/barneyserver/hugging-bay-workers/bay-run@sha256:fb33127a500c5feb547645731b4bf45df293a36a32fb2f8b718564ab88a4288c","binding_status":"complete","generated_at":"2026-08-15T03:31:20Z"},"effective_date":"2026-08-13","training":{"customer_inputs_used_for_training":false,"cross_tenant_examples_used_for_ranking":false,"opt_in_required_for_future_cross_tenant_learning":true},"human_authorization":{"principle":"The human owner defines data, provider, region, retention, environment, and spending boundaries before delegating execution to an agent.","owner_only_authority":["control of the private OAuth client identity and any confidential-client secret","operator-attested enrollment for billing, durable-profile, private-evaluation, memory, and deletion credentials","use and revocation of purpose-specific owner-management credentials","spending-policy changes","one-use approvals above the configured threshold"],"owner_authorization_model":{"oauth_identity":"Public demo OAuth issues a fresh ephemeral private principal per token and cannot administer developer credentials or durable private state. A confidential client authenticated with its client secret establishes a durable private principal, but still does not prove that a human approved owner-management authority.","owner_scope_enrollment":"The current build requires explicit platform-operator attestation before issuing billing:write, task_profile:owner_write, evaluation:owner_write, memory:read, memory:write, or data:delete.","ordinary_agent_boundary":"Ordinary execution credentials cannot create, read, or execute a raw-retaining task profile; cannot retain a labeled private evaluation; cannot access durable memory; and cannot delete private state, approve spend, or change account policy.","delegation_limit":"Profile-bound delegation is not yet offered; an owner-scoped profile credential must not be placed in a general-purpose agent harness."},"agent_authority":"Issue only task-required scopes; autonomous prepaid execution uses a separate billing:spend + inference:invoke key that cannot carry billing:write or data:delete.","sensitive_developer_scopes":{"billing:write":{"scope":"billing:write","description":"Owner-authorized permission to manage checkout, spending policy, and approvals.","credential_role":"owner_billing_management","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"not_for_general_agent_harnesses","data_effect":"billing_and_spending_policy_management"},"data:delete":{"scope":"data:delete","description":"Owner-authorized permission to redact retained private product state.","credential_role":"owner_data_deletion","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"not_for_general_agent_harnesses","data_effect":"principal_scoped_private_data_redaction"},"memory:read":{"scope":"memory:read","description":"Owner-authorized permission to read or inject principal-scoped durable memory.","credential_role":"owner_delegated_memory_reader","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_memory_disclosure_to_the_assigned_agent"},"memory:write":{"scope":"memory:write","description":"Owner-authorized permission to create or modify principal-scoped durable memory.","credential_role":"owner_delegated_memory_writer","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_memory_retention_or_modification"},"evaluation:owner_write":{"scope":"evaluation:owner_write","description":"Owner-authorized permission to retain labeled private evaluation data.","credential_role":"owner_private_evaluation","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"private_labeled_evaluation_retention"},"task_profile:owner_write":{"scope":"task_profile:owner_write","description":"Owner-authorized permission to create or update raw-retaining durable task profiles.","credential_role":"owner_task_profile","owner_issued":true,"default_grant":false,"demo_grant":false,"agent_grant":"explicit_owner_authorization","data_effect":"raw_task_profile_retention"}},"payment_authorization_modes":{"stripe_prepaid":"Bay Run enforces the authenticated owner's per-call, hourly, daily, monthly, provider, task-kind, environment, and approval policy.","tokenless_x402":"The wallet signature authorizes one exact payment only. Bay Run enforces the quoted price, idempotency, and non-durable task-data boundary, but does not claim an account-level hourly, daily, or monthly policy for a tokenless payer.","tokenless_x402_owner_responsibility":"The wallet owner or agent harness must enforce wallet-level cumulative limits and approval rules before signing. Use an authenticated account route when Bay Run-side durable policy is required."},"recommended_default":"Minimize input, exclude credentials, disallow external APIs, require the actual processing region, and use none or execution_metadata retention unless the owner explicitly requests durable private state.","regulated_data":"No regulatory certification or universal suitability is claimed. The owner must confirm that this published contract satisfies any legal, contractual, or sector requirements before sending restricted data."},"task_suitability":{"decision_type":"task_specific_not_universal","use_when":["the owner permits processing in us-central1","the declared retention mode is acceptable","the selected route's provider, model license, and external-API evidence satisfy the task policy","the agent holds only the scopes and spending authority needed for the assigned task"],"do_not_use_when":["the input contains credentials or secrets","the task requires an unsupported region, certification, data-processing agreement, or regulatory control","the owner has not authorized the declared retention, provider, payment, or approval policy","the free quote reports a policy conflict or lacks evidence required by the owner"],"agent_review_sequence":["request a free task quote with explicit data and spending constraints","check can_execute_immediately and every constraint_failure","inspect recommended_route processing_region, external_api, provider, model_license, and their evidence fields","confirm data_handling_policy and quote expiration with the human owner's rules","execute only inside the quoted ceiling and verify the returned receipt"],"human_explanation_fields":["processing region and whether task data reaches an external inference API","whether customer inputs are used for training or cross-tenant learning","raw-input, output, profile, evaluation, and log retention","agent credential scopes, spending limits, and owner-only approval controls","receipt guarantees and explicit limitations"]},"task_execution":{"processing_region":"us-central1","external_inference_apis":false,"input_storage":"canonical SHA-256 only; raw task input is not stored in the task ledger","output_storage":{"none":"no raw output in the task ledger","execution_metadata":"hashes, route, latency, cost, status, and receipt only","task_profile":"raw output may be retained with the explicitly saved private profile; creation requires a billing-eligible developer credential with task_profile:owner_write"},"quote_examples":"quotes retain only an examples digest","quote_specification":"the bounded quote specification is redacted after quote expiry; IDs, hashes, route, price, and receipt evidence remain","saved_profile_examples":"retained only after explicit save_profile with a bounded TTL, then redacted by the task-retention sweep","feedback_corrections":"accepted only for an active saved task profile and redacted when that profile retention expires","expiry_sweep":{"maximum_interval_seconds":900,"maximum_rows_per_category_per_sweep":1000}},"other_product_state":{"memory":{"authorization":"Every read, injection, write, import, export, TTL update, or delete requires a purpose-specific developer credential issued after operator-attested human-owner enrollment.","tenant_boundary":"Tenant-scoped reads, writes, imports, exports, searches, TTL updates, and deletes carry the authenticated private principal predicate. Bounded service-wide expiry maintenance is the explicit exception: it invokes only the expiry predicate and does not expose tenant data. Database row-level security is not claimed.","retention":"Manual entries use the owner-selected TTL; omitting TTL means no expiry. Automatic result memory is opt-in and expires by default after 2592000 seconds; it cannot create an indefinite entry.","expiry_maintenance":{"scope":"bounded service-wide maintenance over rows already eligible for expiry","tenant_predicate_exception":true,"maximum_rows_per_sweep":1000,"physical_deletion":"Best-effort and bounded by sweep/delete batch limits; live-row removal does not guarantee immediate physical removal from backups or infrastructure logs, and immutable accounting or receipt evidence may remain."},"receipts":"Ordinary entry/page receipt hashes are caller-held response-time digests; context-pack receipts are signed. Ordinary memory receipts are not a durable authenticated ledger.","semantic_storage":"Semantic opt-in stores the bounded raw JSON value plus a model/revision-bound embedding.","prompt_injection_boundary":"Injected memory is labeled as untrusted user data and separated from the system guard; it is context, never executable policy or tool instructions.","secret_filter_limit":"Credential-like patterns are rejected, but this is not a general DLP, PII, PHI, financial-data, or legal-data classifier. Owners must minimize and classify data before sending it.","controls":["principal-scoped bounded reads and writes","TTL and importance controls","literal and bounded semantic search","bounded export and HMAC-authenticated portable context packs","namespace or key deletion","private no-store MCP and REST responses"],"training":"Customer memory is not used for model training or cross-tenant ranking."},"private_evaluations":{"ephemeral_default":"omit namespace to avoid durable evaluation storage","explicit_persistence":"supplying a namespace retains the principal-scoped labeled dataset and scorecard until the bounded expires_in/default expiry and requires an operator-attested evaluation:owner_write credential","delete":"DELETE https://run.huggingbay.xyz/v1/eval/namespaces/{namespace}","after_expiry":"dataset, scorecard, and task hint are redacted; digests, candidate/winner, version, and timing evidence remain"},"jobs":"bounded principal-scoped inputs/results until the published job TTL","job_callbacks":{"private_retention_seconds":86400,"egress":{"terminal_content":["completed.result","failed.error"],"destination":"caller_provided_callback_url","recipient_processing_retention":"controlled_by_recipient","bay_run_retention_applies_to_recipient":false},"after_expiry":"terminal callback URL, signed payload body, signature, and error detail are redacted; event identity, payload digest, status, attempts, HTTP status, and timestamps remain as delivery evidence"},"payments":{"retained":"billing and settlement evidence for replay prevention and accounting","raw_task_payload_in_payment_ledger":false,"self_service_deletion":false,"fixed_expiry_promised":false,"suitability_limit":"Do not use a payment rail when the owner's policy requires deletion of all transaction evidence or a fixed accounting-retention deadline."},"legacy_stripe_response_payloads":{"retention_seconds":86400,"allowed_range_seconds":[3600,604800],"after_expiry":"response body and transport headers are redacted; payment, idempotency, credit, and receipt evidence remains"},"catalog_request_contacts":{"retention_days":30,"after_expiry":"the private contact field is redacted; public request, status, dedupe, refusal, and moderation evidence remains"},"specialist_demand":"keyed task/example correlation digests and bounded counts only; raw task text, examples, contacts, and arbitrary caller metadata are not retained","service_logs":{"content":"request metadata and sanitized error classes/codes; Cloud Run request metadata can include source IP, user-agent, and URL. Credentials, task request bodies, memory values, and raw database errors are not intentionally logged. Use the POST body form of /v1/memory/search, including semantic=true when needed, because the deprecated GET search aliases can place search text in infrastructure URL logs","default_log_bucket_retention_days":30},"response_cache":"process-local, tenant-bound, free deterministic responses only, with a maximum 60-second TTL; paid, task, memory, and shared identities bypass it","model_artifacts":"open model artifacts may be fetched from Hugging Face or the Hugging Bay mirror; task inputs are not sent during artifact fetches"},"security":{"transport":"HTTPS/TLS","at_rest":"Google Cloud managed encryption for Cloud SQL and object storage","tenant_isolation":"authenticated principal predicates on tenant-scoped task and memory operations; bounded expiry maintenance is an explicit service-wide exception; database RLS is not claimed","secret_management":"Google Secret Manager/runtime environment; credentials are not inserted into model inputs","host_header_validation":{"enabled":true,"policy":"canonical public host plus explicitly configured Cloud Run and local operational hosts"},"forwarded_header_policy":"Uvicorn proxy-header rewriting is disabled. Application rate-limit attribution uses forwarded addresses only when the direct peer matches an operator-configured trusted proxy CIDR.","maximum_default_request_body_bytes":2097152,"development_and_production_policies":"separate spending-policy environments","deletion_controls":"memory, saved task profiles, and private evaluation namespaces support explicit principal-scoped redaction; expired raw content is redacted while receipt, digest, route, and accounting evidence remains. Physical deletion is best-effort and bounded; self-service deletion does not claim immediate removal from provider backups or immutable accounting logs.","certifications_claimed":[],"security_assurance_limit":"Published controls describe the current implementation; they are not a substitute for a customer-specific security review or data-processing agreement."},"subprocessors":[{"name":"Google Cloud","purpose":"runtime, database, logging, and object storage"},{"name":"Stripe","purpose":"optional card checkout and prepaid-credit accounting"},{"name":"Coinbase Developer Platform","purpose":"optional x402 verification and settlement facilitator"},{"name":"Hugging Face","purpose":"open model artifact source when a mirrored artifact is unavailable"}],"receipt_assurance":{"current_schema":"bay-run.execution-receipt.v2","integrity":"Detached HMAC-SHA256 authentication with a key identifier and an undisclosed tenant-context binding; verification also checks immutable stored execution and receipt facts.","verification_model":"Server-verifiable authenticated evidence, not a public-key signature or an independently verifiable hardware attestation.","bound_claims":["execution identity and result timestamp","quoted and actual price","served provider and model plus fallback evidence","quoted restrictions and data policy","actual latency and quality evidence","input and output digests"],"current_state_not_receipt_bound":["later credit, dispute, revocation, or lifecycle state"],"legacy":"Legacy receipts are not HMAC authenticated; unbound claims are returned as null with explicit limitations.","does_not_prove":["answer truth","task quality beyond the bound evidence","model-weight identity at serve time","cryptographic attestation of the execution environment","legal, contractual, regulatory, or universal safety suitability"]},"security_contact":"https://run.huggingbay.xyz/.well-known/security.txt","data_rights":{"saved_task_profile_delete":"DELETE https://run.huggingbay.xyz/v1/task/profiles/{profile_id}","private_evaluation_delete":"DELETE https://run.huggingbay.xyz/v1/eval/namespaces/{namespace}","memory_delete":"DELETE https://run.huggingbay.xyz/v1/memory","operator_request_contact":"Use security@huggingbay.xyz when self-service redaction is unavailable. Minimize personal data and coordinate a secure transfer method before sending sensitive records or exploit material."}}