Public reading

Public content and small queries do not require an account. The service receives ordinary request metadata needed to return and protect the service.

API keys are accepted only in supported authorization headers. They must not be included in URLs or stored by this site in long-lived browser storage.

Minimal usage events

When metering is enabled, records are limited to operational fields such as client category, request ID, tool, latency, outcome, result status, source count, dataset version, freshness result and cost units.

The default design does not log authorization values, full request bodies, research text or precise route details.

API keys

The database stores a one-way hash and a minimal identifier, not the plaintext key. A newly created key is shown once.

Retention and deletion

Log retention is configuration-controlled. The active duration and deletion procedure must be confirmed in operations documentation before production launch.