What is recorded about a caller, what is not, and how long any of it lasts.
This service does not write client IP addresses to its own logs or storage. The demand counters record the path called, the response status, a two-letter country and the name of the network the call came from (for example a cloud provider), both supplied by the network layer, and a User-Agent string truncated to 120 characters.
When a request looks like a purchase attempt, the site that referred it is also recorded, reduced to its origin and path: query strings and fragments are discarded before anything is stored. Only the time, path and outcome of these records are published at /stats; the rest is seen by the operator alone.
Cloudflare, which hosts the service, keeps its own request logs as our processor, and those may include the connecting address. They are used only to operate and debug the service.
There are no cookies, no analytics scripts, no third-party trackers and no advertising identifiers, because there is no browser session to attach them to.
POST /credits/trial derives your evaluation token from your client address using a keyed hash. The address is used to compute the token and is then discarded: what is stored is a hash of the resulting token and a balance. The address itself is never written to storage, and the stored value cannot be reversed back to it.
IPv6 addresses are collapsed to their /48 prefix before use, so the value involved is less specific than the address you connected from.
Request bodies are processed to produce the response and are not retained, except where retention is the product you asked for:
Vault stores only ciphertext that you encrypted before sending. Encryption keys and plaintext are never transmitted to this service and therefore cannot be read by it, disclosed by it, or produced by it in response to any demand. An item stored with a time to live is deleted when it expires, whether or not the namespace is used again; an item without one is kept until you delete it.
Once-key stores an action key, a hash of your payload and any result you record, until its time to live expires (24 hours by default), when it is deleted whether or not the namespace is used again.
Meeting memory stores the transcripts you import, in a namespace you control, until you delete them. DELETE removes the row and its search index entry. Transcripts usually contain personal information about the people who spoke. For that content you are the party responsible for it and this service processes it on your instructions; see the acceptable use policy for what that requires of you. /meetings/summarize sends the relevant transcript excerpts to an AI model hosted by Cloudflare Workers AI, and its answer is labelled ai_generated.
Credit balances store a hash of the token and the amounts. The token itself is never stored, which is why a lost token cannot be recovered.
/reach/report keeps the URLs you submit and their scan results for 90 days, readable by anyone holding the report's link, then deletes them. An order placed by card is held unpaid for up to 24 hours awaiting Stripe's confirmation, with no scan started; if payment is never completed it is deleted automatically and nothing is charged.
/x402/verify keeps a shared history of each endpoint URL it is asked to check, together with what that endpoint published in its payment challenge (price, chain, asset, receiving address), so that later checks can detect a change. This history is kept indefinitely and is not linked to whoever asked.
The service runs on Cloudflare Workers, Durable Objects and Workers AI; Cloudflare processes traffic and stores the data described above on our behalf, and may do so outside Canada, including in the United States. Payment settlement is performed by a third-party x402 facilitator and by the Base network, which is a public blockchain.
A card payment for the $69 reachability report is processed by Stripe, which receives the card number and billing details directly on its own hosted page; this service receives only a checkout session id and whether it was paid, and never the card number.
Payments are public by nature. A settled payment is permanently visible on-chain, including the paying address and amount. That is a property of the payment rail you chose, not something this service can undo.
The paying address in each payment is checked against a sanctions list before the payment is accepted, and again when funds arrive. The check is a read of Chainalysis's public on-chain sanctions oracle through a Base network node; only the address is sent, and nothing about the check is stored unless the address is listed.
Because no account and no identity is collected, most requests about personal data cannot be matched to a person here. Data you stored under a namespace or token you control can be deleted by you at any time using the documented endpoints. For anything else, write to support@agentic-endpoints.com or https://agentic-endpoints.com/about#contact.