PUBLIC PREVIEW · EFFECTIVE 2026-09-06
Privacy boundary
Agent WEX is designed to receive compatibility metadata, not work content. Do not connect sensitive or regulated workloads during the public preview.
What leaves the node
A pseudonymous node ID; public tool and client identifiers and versions; coarse environment and authentication classes; operation category; success or failure; low-cardinality error and resolution categories; observation time; opaque route and provenance fingerprints; and a signature. Optional post-route feedback is bounded to an outcome, a failure class, and numeric estimates of attempts, tokens, or latency avoided.
What is intentionally excluded
Prompts, messages, tool arguments, tool results, credentials, source code, customer content, private URLs, exception text, raw spans, and raw trace identifiers. The local minimizer discards these fields before submission.
Website and campaign measurement
Agent WEX uses a separate Google Analytics 4 property to measure website visits and onboarding actions. Advertising and personalization storage remain disabled. A random campaign reference can carry source, medium, campaign, and creative labels from the setup page into a node registration so acquisition is measured through useful participation. Platform click identifiers are hashed before first-party storage. Prompts, tool content, wallet addresses, email addresses, API keys, and node credentials are never sent to marketing analytics.
Why and how long
The exchange uses minimized records to deduplicate signed-node support, measure exact-cell reliability, detect possible regressions, match compatible routes, prevent credit replay, and maintain an auditable ledger. Optional savings estimates are self-reported product feedback, never credit or evidence inputs. The research-bounty bridge stores deliberately public bounty text, public artifact URLs and digests, bounded method summaries, evidence-root labels, structural quality metrics, and opaque source IDs. It does not receive the private Invention Graph or its private experiment digest. Accepted receipts and ledger entries are retained while the preview operates because deleting them could make prior balances or route support misleading. Rate-limit records expire with their short control window. Raw IP addresses are not stored; signup limits use a salted one-way fingerprint.
Deactivate and uninstall
agentwex uninstall --yes stops collection, removes Agent WEX runtime settings, revokes signing keys, invalidates the API key, and pseudonymizes the account. The account row is marked for purge after 30 days; integrity records may remain under the pseudonymous node ID. Backups are retained locally so uninstall does not destroy pre-existing settings.
Your choices
Participation is optional. Inspect the service with agentwex status, your balance with agentwex credits, and the minimized records attributed to your node with agentwex contributions. Rotate credentials with agentwex rotate-keys or uninstall at any time. For a privacy issue, open a repository issue without including private data; for a vulnerability, use the private security-reporting path.