DATA HANDLING / TECHNICAL DISCLOSURE

Evidence without prompts.

Loading operator disclosure…

Inputs

A rights request contains a resource URL, purpose and optional usage context. Do not include credentials or personal information. Query strings and fragments are rejected. Application telemetry records decision class, tier, timing, fetch count and payment conversion, not customer prompts or provider API keys.

Reports and declarations

Prepared reports temporarily live in isolated payment-intent storage. Paid reports and eligible RSL declaration snapshots use private storage. The configured report-retention default is 30 days; financial journals are kept separately according to the operator’s reviewed retention and accounting policy. Cache obeys no-store/private and bounded freshness. A no-store response is not retained as a raw RSL snapshot.

Payments and access

Wallet addresses and transaction hashes can be public on the blockchain. Payment records use a pseudonymous payer identifier for aggregate statistics, but the secure reconciliation journal retains the fields needed to verify a transaction. Pseudonymization is not anonymity. Operator access uses Cloudflare Access plus an application credential.

Processors and optional integrations

The deployment uses Cloudflare services and the configured payment facilitator. Optional Tavily and Firecrawl diagnostic probes use their APIs only after an authenticated operator explicitly authorizes a potentially billable request. Their results are not treated as licensing authority. Hosting region, international-transfer arrangements and processor contracts must be reviewed by the operator; this release does not promise EU-only processing.

Requests and incidents

Use the published privacy contact for access, retention or deletion requests and the support contact for incidents. Never send wallet secrets. The operator must finalize the applicable legal basis, retention schedule and rights procedures before paid launch.