entreprenoid The agentic layer for your website.

Privacy

entreprenoid works on your server and records requests, not people. Here is exactly what that means, in the words the product itself is held to.

What we never collect

Request or response bodies, authorization headers, cookies, arbitrary request headers, arbitrary query parameters, URL fragments, form values, console output, email addresses, names, user identifiers. Not by default, not by option.

What we keep about a request

Which page was asked for, when, by what kind of client, and how it was answered. Query strings are dropped, and a conservative redactor runs over the path itself because a path can carry a secret. On the visitor's IP address:

The address is RETAINED on the stored request and is deleted with it, on the site's own retention schedule -- except for a browser we classify as a person, whose address is discarded as soon as its network type has been recorded, normally as the request is stored. It is also used at the ingest boundary for coarse country, rate limiting and crawler verification, and a separate 24-hour hold exists for that purpose. It is also matched, on our own servers, against public network data to record what kind of network it belongs to; no third-party service is consulted. Each request additionally carries a site-scoped, daily-rotating HMAC pseudonym and a two-letter country code, which are what the aggregates group on.

A request from a browser we classify as a person is kept as its own record for seven days, then folded into hourly counts that keep no address, user-agent, visitor pseudonym or full path, and the record deleted -- unless an AI assistant referred that visit, or the record predates referral tracking, in which case it is kept for the site's retention window. The counts are deleted on the same schedule.

What is counted, not stored

A request is stored when a known AI client makes it (every such request, whatever it asked for), when it asks for markdown, when it fetches a discovery file such as /llms.txt, or when it is served an HTML page. Everything else -- scripts, form posts, redirects, missing pages, assets, and the site's own admin and scheduled traffic -- is counted by reason and not stored.

A request addressed to a server's bare public IP address, rather than to the site by name, is counted by reason and not stored, whichever client made it: visitors ask for a site by its name, and scanners walking a server ask for the machine.

A request addressed to a local name such as localhost, at a site whose traffic otherwise arrives under its own domain, is counted by reason and not stored, whichever client made it: it was made to the server directly, not to the site. A site whose server never sees its own name, behind a proxy that does not pass it on, keeps these requests.

What entreprenoid does not do

Every field, listed

The complete list of what is sent, generated from the same definitions the collector uses so the two cannot disagree: every collected field →