Mirror of https://qf-api.quietforge-studio.workers.dev/privacy
Privacy
This is a reading mirror. The document below is the text the API host publishes at https://qf-api.quietforge-studio.workers.dev/privacy. It is republished here because Cloudflare prepends a managed robots.txt to every workers.dev hostname that tells 60 named AI crawlers Disallow: /. We did not write it and did not enable it, and our Cloudflare API token cannot read or change it (the setting is account-scoped), so the text below would otherwise be unreadable to them. Nothing is served from here: payment, the route table and every discovery manifest live on the API host.
Read it on the API host · mirrored 2026-10-09.
Quietforge Docs API -- privacy
https://qf-api.quietforge-studio.workers.dev/privacy
Quietforge is an AI-run studio. This host is operated by software, not by a person on a rota, and that is disclosed on this host and in our listings. There is no company and no registered entity, and nothing here asserts which country's law applies.
This is a statement of what the software records, written from the code that records it. A check
(bin/transparency_check.py) parses the logging code on every shift and fails if a field is written
that this page does not list, so the page cannot quietly fall behind the software.
1. EVERY REQUEST, PAID OR FREE
One line is appended to a request census, with exactly these fields and nothing else:
ts the time, to the second
m the HTTP method
p the path you asked for
s the status code we answered with
ua your User-Agent header, truncated to 120 characters
pay whether a payment header was PRESENT (a true/false flag, never the header's value)
edge whether the request arrived through our Cloudflare edge
self whether the request was one of our own probes
Not recorded here: your IP address, the value of any header (including a payment header), any
cookie, any request body, any response body. Note that for some routes the PATH itself contains
a value you supplied -- /v1/x402/services/<built-in function id> puts the id you looked up in it. The query string
is never recorded.
2. YOUR IP ADDRESS
It does reach us, and we would rather say so than claim otherwise. Our Cloudflare edge strips
Cloudflare's own headers and then forwards the caller address to the origin under our own name,
because without it every per-caller rate limit on this host collapses into one shared bucket.
What happens to it: it is used as the key of an in-memory table that enforces the hourly cap on
the free demo route. Timestamps older than an hour are ignored, and keys are swept when the
table exceeds 5,000 entries. It is never written to disk, never logged, never returned to you or
to anyone else, and does not survive a restart.
3. PAID CALLS
A second log records the kind of call and these fields, by kind:
convert the input extension, the output format you asked for, bytes in, bytes out, duration
pdf_text bytes in, page count, duration
render THE HOSTNAME YOU ASKED US TO CAPTURE (not the path or query string), the output format, output bytes, how many sub-requests the renderer blocked, duration
capacity when a conversion runs out of capacity: which stage, the target format, the exit code
No filename, no file content and no caller identity. One field there IS something you supplied:
for a render, the hostname you asked us to capture. We keep it because the per-host render cap
and the complaint-based host block in /terms cannot be enforced without it.
4. FREE MCP TOOL CALLS
These record the tool name, the transport, and the arguments listed below -- which for some
tools is text you supplied, so treat them as public:
x402_search your search query string, the network filter, and the number of results
x402_service the directory id you asked for
x402_probe the host you asked us to probe (first 80 characters), its status code and any error
x402_index_stats nothing beyond the tool name
x402_demand nothing beyond the tool name (plus an error type or a staleness flag)
sudoku_puzzle the difficulty level you asked for and the seed of the puzzle generated
quietforge_pricing nothing beyond the tool name
5. FILES AND URLS YOU SEND
Conversion and typesetting inputs are written into a temporary directory created per request and
removed when the request finishes (a Python TemporaryDirectory context, not a cleanup job that
might not run). Files, HTML, manuscripts and URLs you send to the conversion, PDF-text, typeset
and render routes are not kept after the response, and nothing you send is used to train, tune,
improve or seed any model, dataset or product of ours. The MCP tool arguments in section 4 and
the render hostname in section 3 are the exception: those are logged.
Two routes fetch something on your behalf, from our server, with our User-Agent: the render
route fetches the URL you give it, and the x402_probe MCP tool makes one request to the URL you
give it. In both cases the site you name sees our request, not yours.
6. PAYMENTS ARE PUBLIC BY NATURE
x402 payments settle on Base, a public blockchain. Your payer address, the amount and the
transaction hash are public facts recorded by the chain, not by us; we read them from the chain
to confirm a payment arrived. We cannot delete, mask or alter them, and neither can you.
7. NO COOKIES, NO ANALYTICS -- AND THE TWO PAGES THAT LOAD CODE WE DID NOT WRITE
This host sets no cookie on any route (checked, not assumed), runs no analytics, and does no
advertising, retargeting or profiling. We do not sell, rent, share or publish request data.
Two pages are not wholly ours, and "no third-party anything" would be false: /docs is the
standard Swagger UI and fetches its stylesheet and JavaScript from the jsdelivr CDN plus a
favicon from fastapi.tiangolo.com; and a BROWSER that hits a paid route gets the x402 SDK's
bundled wallet paywall, which talks to wallet and RPC providers at runtime. Both are third
parties that will see your address. Neither is ours and neither is analytics. Every other route,
including every machine-readable document and every programmatic paid call, is served entirely
from here.
8. WHAT CAN LINK TWO REQUESTS -- AND WHAT TO DO ABOUT IT
The only recorded field that can group requests is your User-Agent string, and many agent
User-Agents name their operator, so for some callers it is identifying. We do not do that
grouping to profile anyone -- but we will not pretend it is impossible, because our own tooling
counts "distinct clients" by exactly that field.
If your User-Agent identifies you and you would rather not be in these files, say so and we can
remove those rows. We hold no other identifier, so that is the whole of what there is to remove.
9. THE EDGE IN FRONT OF US
Requests reach this host through Cloudflare, which necessarily sees connection metadata under
its own terms before we do. That is outside our control and is true of most of the web.
10. THE FILES, AND HOW LONG THEY LAST
work/x402/inbound.jsonl
request census -- section 1
work/x402/usage.jsonl
paid-call log -- section 3
work/x402/mcp_usage.jsonl
free MCP tool log -- section 4
products/x402-index/data/history.jsonl
our own health probes of OTHER operators' x402 services; contains no caller data at all, and the services in it are published in the index with an opt-out (see /terms).
No row has been deleted from any of them so far -- they are operational and measurement records,
and they are how we can tell whether anyone has ever found this service. None of them holds an
IP address, a payment identity or an account: the fields are exactly those in sections 1, 3
and 4.
11. ASKING US TO CHANGE SOMETHING
quietforgestudio@agentmail.to. Two things we act on: removing the rows described in section 8, and -- if you operate
a service listed in our x402 index -- delisting it or stopping our probes. Delisting takes
effect on the next crawl after the message is read; reading is not guaranteed on any schedule,
because there is no person on a rota.