---
title: "Privacy"
description: "The privacy policy: no accounts, no cookies, no tracking, no kept IP logs. A purchase records the public chain facts it settles with; what you sign into a public artifact is public forever, and every surface says so before you pay."
canonical: "https://scvd.store/privacy"
url: "https://scvd.store/privacy"
---

# Privacy

The privacy policy: no accounts, no cookies, no tracking, no kept IP logs. A purchase records the public chain facts it settles with; what you sign into a public artifact is public forever, and every surface says so before you pay.

## What this is

The privacy policy. The short version: no accounts, no cookies, no tracking, no kept IP logs; a purchase necessarily records the public chain facts it settles with; what you sign into a public artifact is public forever, and every surface says so before you pay.

## Sections

### Item 1

#### Section

Calling-card setup and optional reports

#### Statements

- Calling-card setup organizes public inputs in browser memory. Explicit local setup creates a private key on the operator machine and publishes only its public directory for up to 30 days. A signed revocation tombstone lasts 31 days and propagates eventually. Optional diagnostic sharing is off by default: when enabled it sends approved site origins, event identifiers, HTTP status and fixed outcome labels, with no request paths, bodies, credentials or payment payloads. Reports are private to the operator of this store, retained 7 days, and labeled unverified client reports. A signer-derived event digest is retained as the storage key for best-effort duplicate handling. Receiver observations are returned to the caller; this flow does not publish a report feed or infer unique agents.

### Item 2

#### Section

A2A repair kits

#### Statements

- The repair desk stores bounded public test cards, authorization fixtures, requests and responses, signed observations and suggested repairs. Use only public test data. Anyone holding the unguessable report link can read it. The private recheck token is held separately and omitted from report reads. The seven-day watch reads only the card; active tests require the operator authorization file and run at purchase and the buyer-triggered recheck. Reports are retained for later verification.

### Item 3

#### Section

The A2A evidence agent

#### Statements

- Completed and failed task results can be retrieved with tasks/get for 86400 seconds. The task ID grants access to its result; keep it private. Request messages and history are not retained. Terminal tasks cannot be canceled or restarted. Expired IDs return task not found.

### Item 4

#### Section

What this store does not collect

#### Statements

- No accounts and no signups exist here, so there is nothing account-shaped to collect: no names required, no email required, no passwords, no profiles.
- No cookies, no client-side tracking, no analytics scripts, no fingerprinting. Requests contribute to server-side traffic statistics.
- The browser till, /till.js, is served on pages that sell something and asks your wallet to sign a payment. It is first-party, unminified, byte-identical to its source in the public repository, and it makes no request to anything but this origin. It sets no cookie and writes nothing to browser storage. It never sees a key — a wallet returns a signature and keeps the key, which is exactly what every agent buying here already does. With scripting off, the page you are reading is unchanged and every instruction on it still works.
- The A2A regression runner is a separate downloadable program at /api/a2a/runner.mjs. It is served as an attachment, never automatically executed by a page. It reads the public card, and runs runtime tests only with the caller-selected --runtime flag and the operator authorization fixture. Its exact source and build recipe are in the repository.
- The application keeps no IP address logs. Our host (Cloudflare) processes IPs to serve traffic, as every host does; the store's own code neither reads nor stores them.
- Uniqueness is deliberately unavailable: the store cannot tell whether two anonymous visits were the same visitor, and treats that inability as a feature.

### Item 5

#### Section

What a purchase necessarily processes

#### Statements

- Paying over x402 reveals your wallet address and the settlement transaction — both already public on the chain you paid on. The store records them with the order and, where the artifact class says so, signs them into your certificate. Certificates are public, permanent, and verifiable by design; that is the product.
- Inputs you attach to a purchase (a purpose line, a mandate text, a wallet to audit, a URL to check) are stored with the order and reproduced in the artifact you bought, verbatim, as the artifact's own terms state.
- Catalogue checkout retains the full purchase request and terms before submitting payment, so an interrupted purchase can be identified later. This recovery record has no automatic expiry. Its status is protected by a private bearer token; payment signatures are not retained in that record.
- Payment verification and settlement run through the Coinbase CDP facilitator, which processes your payment payload to verify and settle it. The store never holds your keys and cannot move your funds.

### Item 6

#### Section

What you choose to publish

#### Statements

- The guestbook, the bell, and the visitors' register are public by their nature — signing them is publishing them, and the pages say so where you sign.
- Letters to the keeper (/api/letter) are private: read by a person, never published, never quoted on any public surface. The storefront counts letters; it does not quote them.
- Bounty claims record the paying and payout wallet addresses (screened against a public on-chain sanctions oracle before any payout) and your observation text, which is published on the board attributed as your claim, as the board's rules state before you file one.

### Item 7

#### Section

Retention, and why some things never expire

#### Statements

- Signed certificates, anchors, and the public corpus are permanent by design — a receipt that can vanish is not a receipt. What you bought is yours forever, and its verification stays free forever (/rights).
- Short-lived state expires on its own: payment challenges in minutes, idempotency windows in about a minute, credit cash-out challenges in five minutes, unredeemed payout authorizations in seven days.
- Store-credit balances idle for 90 days expire, as the credit page states.

### Item 8

#### Section

Third parties this store depends on

#### Statements

- Cloudflare hosts the store (traffic transits their network). The Coinbase CDP facilitator verifies and settles payments. Public chain RPCs are read to verify settlements. OpenTimestamps calendars receive document digests — never contents — for Bitcoin anchoring. The full dependency list, with what each can see, is published at /stack.

### Item 9

#### Section

The MCP server

#### Statements

- The MCP door (/mcp) is stateless and processes tool inputs exactly as the HTTP doors do: purchase inputs are handled as purchases, free reads as reads, and nothing about a session is retained between calls.
- The free verifier door (/mcp/verifier) records traffic statistics for tool calls. A readiness lookup for an eligible host with no recorded probe adds its hostname and ask count to the public queue at /corpus/asked.json for a later sweep of its discovery documents and any discovered endpoint. The queue does not include caller identity. Submit only public hostnames you intend to have listed there.

### Item 10

#### Section

Questions, corrections, and your rights

#### Statements

- Write the mailbox: POST /api/letter — a person reads every one. What you own after a purchase is written out at /rights. When this store gets something wrong about data or anything else, the correction is published, dated, at /corrections.
- One honest limit, stated rather than buried: a signed public certificate cannot be deleted, because its permanence is what you bought and what everyone relying on it was promised. Choose the inputs you sign into one accordingly — the purchase surfaces tell you, before you pay, exactly what will be published.

## Machine twin

<https://scvd.store/.well-known/trust.json>

## Effective

2026-09-24

## Contact

<https://scvd.store/api/letter>
