# Privacy

Last updated: 2026-10-10

This page lists what AttestPage keeps about calls to https://vehcdj664efetfrsolne5umanq.srv.us and for how long.

## Access log

For each request we log the time, method, path, status, duration, payment rail and its network, price, a coarse user-agent class (for example "ai_agent", "browser" or "crawler"), the name of a known AI agent where the user agent gives one (for example "gptbot"), the referrer's host name, a caller id, and a yes/no mark ("own") that says whether the request came from our own test and check scripts, so we can leave them out of our usage figures. The caller id is a keyed hash of your IP address under a random key held in memory only and replaced every UTC day, so it cannot be traced back to an address or linked across days. We do not log request bodies, query strings, target URLs, IP addresses or full user-agent strings. Log files are deleted after 14 days.

## Rate limits

To apply per-address rate limits and trial limits, we hold a keyed hash of your IP address in memory only. The key is random and replaced every UTC day. It is never written to disk.

## Payments

- For each settled payment we keep the time, route, network, amount, transaction hash and payment id.
- A paid receipt contains the payment details, including the paying wallet address. You hold the receipt; see Attestations below for receipts we keep.
- When a paying address is refused because it is on a sanctions list, we keep the time, route, network and that address.
- To answer a retried payment with the same response, we keep the paid response in memory for one hour.
- When a call's work is done but its payment fails to settle, we keep the time, route, payment id, signature nonce, paying address and, if reported, the failure reason and transaction hash, so the charge can be checked against the chain. If the payment had a payment id, the withheld response is also kept in memory for at least one hour, until the payment can no longer go through.
- Where Lightning (L402) is on, we keep the payment hash of each used token and its expiry time until the token expires, so it cannot be used twice, and the paid response in memory until a restart, so the same request with that token gets it again.

## Attestations

For `POST /v1/attest` we keep a sequence number, the time, a SHA-256 of your idempotency key and the paying address if you sent a key, the SHA-256 you sent, the SHA-256 of your note, and the signed receipt (which includes the paying address). We keep these so that a retry gets the same receipt. The note text itself is never stored. These records are kept with no set end date.

## Pages we fetch

Pages fetched for you are not stored. We keep only what goes into the receipt you receive. That receipt records the IP address of the site we fetched (never yours), its TLS certificate details and a few of its response headers. robots.txt files are cached in memory for up to one hour.

## Sharing

Payments go through an x402 facilitator and are recorded on a public blockchain, as all such payments are. When a verify/citations call cites a page with a DOI, that DOI (only the DOI) is sent to Crossref (api.crossref.org) to read its public metadata. We do not sell or share the data above with anyone else.

## Contact

no contact address is set on this server; the robots.txt opt-out works without one.
