Privacy Policy
Short version: we don't have accounts, we don't use cookies or trackers, and we don't collect personal data beyond what a normal web server log briefly sees in passing.
1. No accounts, no cookies
There is no sign-up or login anywhere on this site or API. We do not set tracking cookies, browser fingerprinting scripts, or third-party ad/analytics pixels.
2. What we do collect
A first-party, best-effort analytics module counts aggregate events only, bucketed by day: page views by path, referrer hostname only (never the full referring URL or its query string), free-tool lookups by tool name, unpaid-402 challenges by route, successful paid settlements by route, and MCP tool-call names. No raw IP addresses, no cookies, no per-visitor identifiers, and no way to reconstruct an individual visitor's session from what's stored. These aggregates are readable only via an admin endpoint gated by a private token that is unset by default (the endpoint 404s until an operator deliberately turns it on).
Standard web-server/hosting-platform request logs (e.g. Render's own infrastructure logs) may briefly retain IP addresses and request metadata per our hosting provider's own logging practices — this is normal for any web server and is not something draconic21 separately stores or analyzes.
3. Payments
API calls (x402/USDC on Base): payment is a direct on-chain crypto transaction between your wallet and ours, processed through a payment facilitator. We receive a wallet address and a settlement confirmation — never a private key, seed phrase, card number, or bank detail. We do not require or collect your name, email, or any other identifying information to make a paid API call.
Digital downloads (Gumroad): checkout, payment, and any buyer account are handled entirely by Gumroad. We receive whatever Gumroad's own seller dashboard shows (typically an email and purchase record) — see Gumroad's privacy policy for what Gumroad itself collects and how it's handled.
4. What we never store
No passwords (there are none to store), no wallet private keys or seed phrases, no card numbers, no government ID numbers, and no more personal data than a purchase or a page visit inherently requires.
5. Data from the API's own subject matter
The names, wallet addresses, and filings data returned by sanctions_screen, sanctions_delta, and the SEC EDGAR routes are public government records (see /sources) fetched live on your request — they are not personal data about you, the caller; they're the subject of your query, already public before you asked.
6. Children
This API and these downloads are intended for business/developer/compliance use, not children, and are not directed at anyone under 13.
7. Changes
This policy may change as the project evolves; the effective date at the top reflects the latest revision. Material changes will be reflected in the changelog.
8. Contact
No dedicated support inbox is published yet for this project. Live operational status: /status. See also Terms of Service.