api.strale.io

https://api.strale.io/x402/privacy-policy-analyze

Shares a payout wallet with 268 other endpoints — its adoption is attributed from that shared wallet's traffic, not earned exclusively.

Analyze a company's privacy policy. Extracts data collected, purposes, third parties, user rights, GDPR/CCPA compliance signals.

62
reliability

Reliability & health

Uptime and response time from our own unpaid probes, plus the reliability score built from them.

Uptime

100.0% avg
0% 50% 100% Jul 22Aug 1Aug 10Aug 20

Response time

p50 27ms · p95 59ms
0ms 200ms 400ms Jul 22Aug 1Aug 10Aug 20
Data table
Reliability history per time bucket over the last 30 days (daily).
Bucket Uptime Probes Response time
7/22/2026, 12:00:00 AM 100% 1 27ms
7/23/2026, 12:00:00 AM 100% 1 369ms
7/24/2026, 12:00:00 AM 100% 1 27ms
7/25/2026, 12:00:00 AM 100% 1 27ms
7/26/2026, 12:00:00 AM 100% 1 28ms
7/27/2026, 12:00:00 AM 100% 1 29ms
7/28/2026, 12:00:00 AM 100% 1 28ms
7/29/2026, 12:00:00 AM 100% 1 27ms
7/30/2026, 12:00:00 AM 100% 1 29ms
7/31/2026, 12:00:00 AM 100% 1 24ms
8/1/2026, 12:00:00 AM 100% 1 26ms
8/2/2026, 12:00:00 AM 100% 1 30ms
8/3/2026, 12:00:00 AM 100% 1 28ms
8/4/2026, 12:00:00 AM 100% 1 25ms
8/5/2026, 12:00:00 AM 100% 1 25ms
8/6/2026, 12:00:00 AM 100% 1 28ms
8/7/2026, 12:00:00 AM 100% 1 25ms
8/8/2026, 12:00:00 AM 100% 1 27ms
8/9/2026, 12:00:00 AM 100% 1 27ms
8/10/2026, 12:00:00 AM 100% 1 29ms
8/11/2026, 12:00:00 AM 100% 1 28ms
8/12/2026, 12:00:00 AM 100% 1 25ms
8/13/2026, 12:00:00 AM 100% 1 25ms
8/14/2026, 12:00:00 AM 100% 1 27ms
8/15/2026, 12:00:00 AM 100% 1 25ms
8/16/2026, 12:00:00 AM 100% 1 27ms
8/17/2026, 12:00:00 AM 100% 1 26ms
8/18/2026, 12:00:00 AM 100% 2 32ms
8/19/2026, 12:00:00 AM 100% 20 28ms
8/20/2026, 12:00:00 AM 100% 19 30ms
62
Composite reliability — the weighted average of the dimensions below, on a 0–100 scale.
Availability
100

How often it was reachable when we probed it (weight 35%).

Latency
100

How quickly it answers when it is up — fast scores high (weight 20%).

Security
100

Whether it serves over working TLS / https (weight 15%).

Transparency
61

Whether the operator disclosed what it does — description, schema, identity (weight 15%).

Activity
1

Observed on-chain payments to this endpoint's wallet — transactions, volume, and distinct paying wallets over the last month (weight 15%; not yet measured when we have not seen its wallet settle).

Confidence 100% — how much probe evidence backs this score. A thin history is flagged, not hidden.

See the scoring methodology for exactly how each number is computed.

Payment

Currencies
USDC
Networks
base
Facilitator
unknown
SDK
unknown

Operator

Company
inferred — unknown
Jurisdiction
Registrar
Domain registered
Hosting network
RLWY-HIKARI-01
Hosting country

Operator context is derived from public RDAP/TLS records and unverified. Company and country are only available for endpoints that publish them (an OV/EV TLS certificate or a non-redacted domain record); most endpoints are CDN-fronted and disclose neither.

On-chain activity (base)

2,337
payments (30d)
161.87
USD volume (30d)
15
paying wallets (30d)

Payments per day

last payment 8/20/2026
0 100 200 Jul 22Aug 6Aug 13Aug 20
Data table
Settled payments per day.
Day Payments Volume (USD) Paying wallets
7/22/2026 139 11.67 5
7/23/2026 76 6.23 3
7/24/2026 195 13.53 1
8/1/2026 151 9.32 3
8/2/2026 35 1.91 1
8/4/2026 5 0.43 3
8/5/2026 3 0.43 3
8/6/2026 73 4.3 1
8/7/2026 162 7.35 2
8/8/2026 40 3.01 1
8/9/2026 146 13.32 1
8/10/2026 131 13.05 1
8/11/2026 62 5.21 1
8/12/2026 106 8 2
8/13/2026 97 4.86 2
8/14/2026 40 2.14 2
8/15/2026 124 6 1
8/16/2026 56 3.12 1
8/17/2026 186 17.59 1
8/18/2026 190 11.85 2
8/19/2026 195 9.42 1
8/20/2026 125 9.12 1

This payout wallet is shared: figures cover all 269 endpoints paid at it, since payments cannot be attributed to one of them. Only payments settled on chains and facilitators we index.

Linked by wallet — likely same operator

On-chain agent identity and the x402 endpoint that shares its settlement wallet.

Response schema
{
  "example": {
    "ccpa_compliant_signals": [
      "Dedicated CCPA section in Privacy Center",
      "Categories of Personal Information Collected disclosed",
      "Sensitive personal information categories identified",
      "Sale/Share of personal information addressed explicitly",
      "California Privacy Rights Metrics provided",
      "Data retention periods mentioned as CCPA-related topic"
    ],
    "children_data": null,
    "company_name": "Stripe",
    "cookie_usage": "Stripe uses cookies for fraud detection, payment method storage (Link feature), and potentially advertising. Advanced fraud signals are used but distinguished from ad tracking. Stripe.js is employed. Merchants and Link users have specific obligations regarding cookie technology disclosures.",
    "data_collected": [
      "Personal data from Business Users",
      "End Customer personal data (cardholders)",
      "Representative contact information (beneficial owners, shareholders, officers, directors)",
      "Precise location data (context-dependent)",
      "Identity verification data",
      "Transaction history",
      "Authentication and authorization data",
      "Phone verification information",
      "Call recordings (in some instances)",
      "Payment method details",
      "Financial account information (via Financial Connections)"
    ],
    "dpo_contact": null,
    "gdpr_compliant_signals": [
      "Dual role as data controller and processor clearly articulated",
      "Data Processing Agreements (DPAs) available for Business Users",
      "Data Transfer Addendum provided",
      "Multiple legal basis identification",
      "Specific guidance for Business Users as controllers under GDPR",
      "EU-U.S. Data Privacy Framework certification",
      "Standard Contractual Clauses implemented",
      "Sub-processors list published",
      "Privacy by Design implementation mentioned",
      "Clear distinction between user categories",
      "Ireland-based main establishment (Stripe Technology Company Limited) for GDPR compliance",
      "Support for Global Privacy Control (GPC)",
      "Jurisdictional nuances acknowledged (EEA, Switzerland, UK, APAC)"
    ],
    "international_transfers": [
      "EU-U.S. Data Privacy Framework (DPF) certified",
      "Standard Contractual Clauses (SCCs)",
      "UK Addendum (for UK data transfers)",
      "Cross-border: Americas vs. Non-Americas entities (Stripe LLC vs. STC/SPEL)",
      "Global storage of authentication and authorization data",
      "India: localized data storage options mentioned"
    ],
    "last_updated": null,
    "legal_basis": [
      "Contract performance (service delivery)",
      "Legitimate interest",
      "Legal obligation",
      "Consent (implied for some contexts)"
    ],
    "missing_elements": [
      "Specific data retention periods (policy states 'not specified' or deferred to details)",
      "DPO contact information (policy asks 'Does Stripe have a DPO?' but answer not provided in excerpt)",
      "Detailed sub-processors list (only referenced, not detailed)",
      "Specific legal basis matching per data type",
      "Automated decision-making and profiling disclosures",
      "Right to lodge complaint with supervisory authority (only mentioned for India)",
      "Specific cookie names and purposes",
      "Last updated/effective date of the policy",
      "Biometric data handling",
      "Details on when data is NOT retained after deletion requests",
      "Specific retention timelines (e.g., '30 days', '7 years')",
      "Explicit children's data policy/age restrictions"
    ],
    "purposes": [
      "Service delivery and payment processing",
      "Fraud prevention and security",
      "Artificial intelligence model training",
      "Transaction authentication",
      "Identity verification",
      "Co-marketing of End User Services",
      "Product improvement",
      "Regulatory compliance",
      "Legal obligation fulfillment"
    ],
    "retention_periods": [
      "not specified"
    ],
    "source_url": "https://stripe.com/privacy-center/legal",
    "third_parties": [
      "Sub-processors (list available but not detailed in excerpt)",
      "BNPL providers",
      "Crypto wallet services",
      "Third-party fraud prevention and security providers",
      "Third-party identity verification providers",
      "Advertising partners (for ad targeting)"
    ],
    "user_rights": [
      "Access to personal data",
      "Deletion/right to be forgotten",
      "Rectification/correction",
      "Data portability",
      "Objection to processing",
      "Right to exercise data protection rights",
      "Right to honor Global Privacy Control (GPC) signals",
      "Right to opt-out of tracking and advanced fraud signals",
      "Right to lodge complaints (India-specific: mentioned)"
    ]
  },
  "properties": {
    "data_collected": {
      "type": "array"
    },
    "gdpr_compliant_signals": {
      "type": "array"
    },
    "missing_elements": {
      "type": "array"
    },
    "purposes": {
      "type": "array"
    },
    "user_rights": {
      "type": "array"
    }
  },
  "type": "object"
}