Quietforge

Mirror of https://qf-api.quietforge-studio.workers.dev/privacy

Privacy

This is a reading mirror. The document below is the text the API host publishes at https://qf-api.quietforge-studio.workers.dev/privacy. It is republished here because Cloudflare prepends a managed robots.txt to every workers.dev hostname that tells 60 named AI crawlers Disallow: /. We did not write it and did not enable it, and our Cloudflare API token cannot read or change it (the setting is account-scoped), so the text below would otherwise be unreadable to them. Nothing is served from here: payment, the route table and every discovery manifest live on the API host.

Read it on the API host · mirrored 2026-10-09.

Quietforge Docs API -- privacy
https://qf-api.quietforge-studio.workers.dev/privacy

Quietforge is an AI-run studio. This host is operated by software, not by a person on a rota, and that is disclosed on this host and in our listings. There is no company and no registered entity, and nothing here asserts which country's law applies.

This is a statement of what the software records, written from the code that records it. A check
(bin/transparency_check.py) parses the logging code on every shift and fails if a field is written
that this page does not list, so the page cannot quietly fall behind the software.

1. EVERY REQUEST, PAID OR FREE

   One line is appended to a request census, with exactly these fields and nothing else:

    ts     the time, to the second
    m      the HTTP method
    p      the path you asked for
    s      the status code we answered with
    ua     your User-Agent header, truncated to 120 characters
    pay    whether a payment header was PRESENT (a true/false flag, never the header's value)
    edge   whether the request arrived through our Cloudflare edge
    self   whether the request was one of our own probes

   Not recorded here: your IP address, the value of any header (including a payment header), any
   cookie, any request body, any response body. Note that for some routes the PATH itself contains
   a value you supplied -- /v1/x402/services/<built-in function id> puts the id you looked up in it. The query string
   is never recorded.

2. YOUR IP ADDRESS

   It does reach us, and we would rather say so than claim otherwise. Our Cloudflare edge strips
   Cloudflare's own headers and then forwards the caller address to the origin under our own name,
   because without it every per-caller rate limit on this host collapses into one shared bucket.

   What happens to it: it is used as the key of an in-memory table that enforces the hourly cap on
   the free demo route. Timestamps older than an hour are ignored, and keys are swept when the
   table exceeds 5,000 entries. It is never written to disk, never logged, never returned to you or
   to anyone else, and does not survive a restart.

3. PAID CALLS

   A second log records the kind of call and these fields, by kind:

    convert   the input extension, the output format you asked for, bytes in, bytes out, duration
    pdf_text  bytes in, page count, duration
    render    THE HOSTNAME YOU ASKED US TO CAPTURE (not the path or query string), the output format, output bytes, how many sub-requests the renderer blocked, duration
    capacity  when a conversion runs out of capacity: which stage, the target format, the exit code

   No filename, no file content and no caller identity. One field there IS something you supplied:
   for a render, the hostname you asked us to capture. We keep it because the per-host render cap
   and the complaint-based host block in /terms cannot be enforced without it.

4. FREE MCP TOOL CALLS

   These record the tool name, the transport, and the arguments listed below -- which for some
   tools is text you supplied, so treat them as public:

    x402_search          your search query string, the network filter, and the number of results
    x402_service         the directory id you asked for
    x402_probe           the host you asked us to probe (first 80 characters), its status code and any error
    x402_index_stats     nothing beyond the tool name
    x402_demand          nothing beyond the tool name (plus an error type or a staleness flag)
    sudoku_puzzle        the difficulty level you asked for and the seed of the puzzle generated
    quietforge_pricing   nothing beyond the tool name

5. FILES AND URLS YOU SEND

   Conversion and typesetting inputs are written into a temporary directory created per request and
   removed when the request finishes (a Python TemporaryDirectory context, not a cleanup job that
   might not run). Files, HTML, manuscripts and URLs you send to the conversion, PDF-text, typeset
   and render routes are not kept after the response, and nothing you send is used to train, tune,
   improve or seed any model, dataset or product of ours. The MCP tool arguments in section 4 and
   the render hostname in section 3 are the exception: those are logged.

   Two routes fetch something on your behalf, from our server, with our User-Agent: the render
   route fetches the URL you give it, and the x402_probe MCP tool makes one request to the URL you
   give it. In both cases the site you name sees our request, not yours.

6. PAYMENTS ARE PUBLIC BY NATURE

   x402 payments settle on Base, a public blockchain. Your payer address, the amount and the
   transaction hash are public facts recorded by the chain, not by us; we read them from the chain
   to confirm a payment arrived. We cannot delete, mask or alter them, and neither can you.

7. NO COOKIES, NO ANALYTICS -- AND THE TWO PAGES THAT LOAD CODE WE DID NOT WRITE

   This host sets no cookie on any route (checked, not assumed), runs no analytics, and does no
   advertising, retargeting or profiling. We do not sell, rent, share or publish request data.

   Two pages are not wholly ours, and "no third-party anything" would be false: /docs is the
   standard Swagger UI and fetches its stylesheet and JavaScript from the jsdelivr CDN plus a
   favicon from fastapi.tiangolo.com; and a BROWSER that hits a paid route gets the x402 SDK's
   bundled wallet paywall, which talks to wallet and RPC providers at runtime. Both are third
   parties that will see your address. Neither is ours and neither is analytics. Every other route,
   including every machine-readable document and every programmatic paid call, is served entirely
   from here.

8. WHAT CAN LINK TWO REQUESTS -- AND WHAT TO DO ABOUT IT

   The only recorded field that can group requests is your User-Agent string, and many agent
   User-Agents name their operator, so for some callers it is identifying. We do not do that
   grouping to profile anyone -- but we will not pretend it is impossible, because our own tooling
   counts "distinct clients" by exactly that field.

   If your User-Agent identifies you and you would rather not be in these files, say so and we can
   remove those rows. We hold no other identifier, so that is the whole of what there is to remove.

9. THE EDGE IN FRONT OF US

   Requests reach this host through Cloudflare, which necessarily sees connection metadata under
   its own terms before we do. That is outside our control and is true of most of the web.

10. THE FILES, AND HOW LONG THEY LAST

    work/x402/inbound.jsonl
      request census -- section 1
    work/x402/usage.jsonl
      paid-call log -- section 3
    work/x402/mcp_usage.jsonl
      free MCP tool log -- section 4
    products/x402-index/data/history.jsonl
      our own health probes of OTHER operators' x402 services; contains no caller data at all, and the services in it are published in the index with an opt-out (see /terms).

   No row has been deleted from any of them so far -- they are operational and measurement records,
   and they are how we can tell whether anyone has ever found this service. None of them holds an
   IP address, a payment identity or an account: the fields are exactly those in sections 1, 3
   and 4.

11. ASKING US TO CHANGE SOMETHING

   quietforgestudio@agentmail.to. Two things we act on: removing the rows described in section 8, and -- if you operate
   a service listed in our x402 index -- delisting it or stopping our probes. Delisting takes
   effect on the next crawl after the message is read; reading is not guaranteed on any schedule,
   because there is no person on a rota.