AttestPage · Docs · Pricing · OpenAPI · llms.txt

Privacy

Last updated: 2026-10-10

This page lists what AttestPage keeps about calls to https://vehcdj664efetfrsolne5umanq.srv.us and for how long.

Access log

For each request we log the time, method, path, status, duration, payment rail and its network, price, a coarse user-agent class (for example "ai_agent", "browser" or "crawler"), the name of a known AI agent where the user agent gives one (for example "gptbot"), the referrer's host name, a caller id, and a yes/no mark ("own") that says whether the request came from our own test and check scripts, so we can leave them out of our usage figures. The caller id is a keyed hash of your IP address under a random key held in memory only and replaced every UTC day, so it cannot be traced back to an address or linked across days. We do not log request bodies, query strings, target URLs, IP addresses or full user-agent strings. Log files are deleted after 14 days.

Rate limits

To apply per-address rate limits and trial limits, we hold a keyed hash of your IP address in memory only. The key is random and replaced every UTC day. It is never written to disk.

Payments

Attestations

For POST /v1/attest we keep a sequence number, the time, a SHA-256 of your idempotency key and the paying address if you sent a key, the SHA-256 you sent, the SHA-256 of your note, and the signed receipt (which includes the paying address). We keep these so that a retry gets the same receipt. The note text itself is never stored. These records are kept with no set end date.

Pages we fetch

Pages fetched for you are not stored. We keep only what goes into the receipt you receive. That receipt records the IP address of the site we fetched (never yours), its TLS certificate details and a few of its response headers. robots.txt files are cached in memory for up to one hour.

Sharing

Payments go through an x402 facilitator and are recorded on a public blockchain, as all such payments are. When a verify/citations call cites a page with a DOI, that DOI (only the DOI) is sent to Crossref (api.crossref.org) to read its public metadata. We do not sell or share the data above with anyone else.

Contact

no contact address is set on this server; the robots.txt opt-out works without one.