# Privacy

> entreprenoid works on your server and records requests, not people. Here is exactly what that
> means, in the words the product itself is held to.

## What we never collect

Request or response bodies, authorization headers, cookies, arbitrary request headers, arbitrary
query parameters, URL fragments, form values, console output, email addresses, names, user
identifiers. Not by default, not by option.

## What we keep about a request

Which page was asked for, when, by what kind of client, and how it was answered. Query strings are
dropped, and a conservative redactor runs over the path itself because a path can carry a secret.
On the visitor's IP address:

*The address is RETAINED on the stored request and is deleted with it, on the site's own retention
schedule -- except for a browser we classify as a person, whose address is discarded as soon as
its network type has been recorded, normally as the request is stored. It is also used at the
ingest boundary for coarse country, rate limiting and crawler verification, and a separate 24-hour
hold exists for that purpose. It is also matched, on our own servers, against public network data
to record what kind of network it belongs to; no third-party service is consulted. Each request
additionally carries a site-scoped, daily-rotating HMAC pseudonym and a two-letter country code,
which are what the aggregates group on.*

*A request from a browser we classify as a person is kept as its own record for seven days, then
folded into hourly counts that keep no address, user-agent, visitor pseudonym or full path, and
the record deleted -- unless an AI assistant referred that visit, or the record predates referral
tracking, in which case it is kept for the site's retention window. The counts are deleted on the
same schedule.*

## What is counted, not stored

*A request is stored when a known AI client makes it (every such request, whatever it asked for),
when it asks for markdown, when it fetches a discovery file such as /llms.txt, or when it is
served an HTML page. Everything else -- scripts, form posts, redirects, missing pages, assets, and
the site's own admin and scheduled traffic -- is counted by reason and not stored.*

*A request addressed to a server's bare public IP address, rather than to the site by name, is
counted by reason and not stored, whichever client made it: visitors ask for a site by its name,
and scanners walking a server ask for the machine.*

*A request addressed to a local name such as localhost, at a site whose traffic otherwise arrives
under its own domain, is counted by reason and not stored, whichever client made it: it was made
to the server directly, not to the site. A site whose server never sees its own name, behind a
proxy that does not pass it on, keeps these requests.*

## What entreprenoid does not do

- **It does not identify people.** No cross-site tracking, no identity graph, no session replay,
  no keystroke or form capture.
- **It does not block or challenge anyone.** It labels traffic; it never enforces.
- **It does not serve different content by identity.** AI agents and people get the same words.
- **It does not publish anything you have not allowed**, and everything it publishes can be
  withdrawn.

## Every field, listed

The complete list of what is sent, generated from the same definitions the collector uses so the
two cannot disagree: [every collected field](https://entreprenoid.com/collected-fields.md).

---

entreprenoid is a Fifth Mind LLC product. Private beta.
