# Testnet privacy notice

Policy version: 2026-09-17. Experimental testnet service; not a commercial launch.

Project contact: trusthistorylab402@gmail.com. A verified commercial seller identity and any applicable controller disclosures must be completed before commercial launch. This is an operational testnet notice, not a claim of GDPR or other legal certification.

## Information processed

Accepted public URLs and package names are used to retrieve evidence from npm's public registry, Common Crawl, and relevant IANA-bootstrapped RDAP providers. Selected archived bytes are processed in memory; archived page bodies are not stored in our application database. Public identifiers, accepted URL paths, and returned facts can appear in response caches. Hashing a cache key does not anonymize the cached payload. Do not submit personal or confidential information, even in a URL path.

The application keeps fixed-label daily counters, not browsing profiles. Paid-completion rows contain network, public transaction reference, route, time, amount, asset, and price version, with a keyed repeat-payer token when configured. A repeat payer is not necessarily a unique machine or person. HMAC tokens are pseudonymous, not anonymous; public blockchain transactions can identify wallets. Payment payloads are disclosed to the selected facilitator for verification and settlement. The current deployment must be checked for provider selection; the candidate does not automatically switch processors.

Raw payer addresses, payment signatures, payment identifiers, user-agent strings, referrers, request bodies, and submitted URLs are not written to application telemetry tables. Rate limiting temporarily uses an IP-derived key in process memory, with a 60-second counting window and lazy cleanup; it is not a durable IP database. Cloudflare and other infrastructure providers still process network/request metadata. This candidate disables Cloudflare invocation logs and avoids raw exception logging; the deployed settings and provider retention need separate verification. This is not a zero-logging or anonymity promise.

## Retention and deletion

- Package and chronology response caches: usable for at most 6 hours after insertion; URL-history caches: 24 hours. Expired entries are not served.
- Daily counters and testnet completion-detail/repeat-payer measurement: eligible for cleanup after 90 days (counter dates use UTC days).
- Cleanup removes at most 100 eligible rows per category per attempt, at most hourly per application instance when traffic arrives. Quiet periods, backlog, or failed cleanup delay physical deletion; 90 days is an eligibility threshold, not a guaranteed erasure deadline.
- Durable anti-replay records, including keyed request/identifier fingerprints and sanitized settlement transaction references: retained for the service lifetime to prevent repeat settlement, with periodic necessity review. Deleting a measurement row does not erase the separate anti-replay reference or the blockchain.
- Public package-observation snapshots: retained for the service lifetime to provide history, subject to correction/removal review. They are not independent public-web observations merely because a customer queried something.
- Backups, platform logs, public blockchain records, and third-party evidence sources have separate retention. Application deletion cannot promise deletion from those systems. No mainnet accounting retention policy is activated by this release.

Requests concerning access, correction, or deletion can be sent to the project contact. We may need minimal verification of authority and must consider safety, legal, and third-party rights. Do not email private keys or recovery phrases. The contact inbox, provider settings, and applicable jurisdictional disclosures require owner verification before promotion.
