Public reading
Public content and small queries do not require an account. The service receives ordinary request metadata needed to return and protect the service.
API keys are accepted only in supported authorization headers. They must not be included in URLs or stored by this site in long-lived browser storage.
Minimal usage events
When metering is enabled, records are limited to operational fields such as client category, request ID, tool, latency, outcome, result status, source count, dataset version, freshness result and cost units.
The default design does not log authorization values, full request bodies, research text or precise route details.
API keys
The database stores a one-way hash and a minimal identifier, not the plaintext key. A newly created key is shown once.
Retention and deletion
Log retention is configuration-controlled. The active duration and deletion procedure must be confirmed in operations documentation before production launch.