sealed.run

Privacy Policy.

Sealed is operated by Lispresso AI · Last updated August 24, 2026

01

What we collect

  • Account: your email address (sign-in, receipts).
  • Usage ledger: per-run metadata — skill, timestamp, amount, status — so your receipts and disputes work.
  • Payments: handled by Stripe; we receive confirmation events, never your card number.
  • Run inputs/outputs: processed only to execute the run and discarded on teardown from Sealed's hosted runtime — we do not retain them after the run, train on them, or share them with publishers.
02

What we never do

  • Train models on your inputs, outputs, or any publisher's skill body, or opt your run content into model-provider training.
  • Sell personal data.
  • Show a publisher what you ran through their skill.
03

Processors

Named subprocessors and what they touch: Stripe (payments), Anthropic or another disclosed model API provider (run execution), Resend or another disclosed email provider (sign-in links, receipts, support replies), and infrastructure hosts for the website, API, storage, and sandbox runtime. We limit each processor to the role needed to operate the marketplace.

04

Retention & deletion

Run inputs and outputs: not retained by Sealed after teardown of the hosted run. Connected sandbox state (catalog execution: "modeB") is destroyed with the sandbox session; Hosted run content is discarded after the response path completes. Ledger and receipts: retained for accounting, tax, abuse-prevention, dispute, and security obligations. Account deletion: email support; eligible unused cash balance can be requested back under the refund policy.

05

Site telemetry

We use first-party, fixed-code telemetry to understand whether the public site and marketplace are working. Static pages send only an allowlisted event code, such as a page view or marketplace click. App pages may also include a public skill id and whether the browser is signed in.

Telemetry does not include emails, support messages, URLs, referrers, search terms, buyer inputs, model outputs, API keys, wallet secrets, or skill bodies. We do not use third-party analytics scripts on these pages.

Failed runs. When a run fails we record that it failed: the skill, a fixed error code from a closed list, the time, and the run’s receipt id. That record is how we find out our own service is broken, so it is always kept. Whether it also records that the run was yours is your choice — it is on by default so we can tell you what happened and follow up, and one switch in your account turns it off. Turning it off does not hide the failure from us; it removes your name from it. Either way the failed run stays on your own usage ledger, where it is your proof that a failed run was not charged.

06

Problem reports

When you — or an AI agent acting for you — report a problem, through the website, the sealed report command, or the report_problem tool, we receive two things: what you wrote, and a fixed list of machine details (which client and version, your Node and operating-system name, which Sealed host you were pointed at, the error code, the run’s receipt id).

A report cannot carry your run inputs, the model’s output, your file contents, file paths, or stack traces. There is no field for them; anything else sent is discarded before the report is stored, and anything shaped like a password or API key is masked. If you paste a secret into the description by accident, we mask it — but rotate it anyway. Reports are read by us to fix what you hit, and are never shown to a publisher or to another buyer.

07

Your rights & contact

Access/export/deletion requests and regional privacy questions can be sent to privacy@sealed.run. We use the request metadata needed to verify and respond to the request.