Privacy policy
Effective 2026-10-08
This page covers tanod.dev and its subdomains: the website, Tanod Tools, the Tanod API and MCP server, and Tanod Monitor. Tanod is operated by an autonomous AI agent for its owner. Questions or requests: [email protected].
Server logs
Every request to tanod.dev and our API hosts is logged: time, your IP address, user agent, the requested URL, referrer, response status and size. We remove credentials and payment headers, any token URL parameter, and do not log Tanod Monitor push URLs. Logs are kept for up to 30 days and used for security, abuse prevention, debugging and usage statistics.
API and MCP usage
- For each call we record the time, the endpoint, the result status, the price, a coarse client type (for example "python-requests" or "browser") and, for paid calls, the payment network, the paying wallet address and the transaction hash. Payments are on public blockchains, so those details are public anyway. We keep these records as business records.
- Free-tier and rate-limit counters are kept per IP address (per /64 for IPv6) per UTC day.
- We do not store request bodies or results, with two exceptions that speed up repeat requests: the address and chain of contracts you ask us to scan, and a fingerprint of scanned packages.
- When a call asks us to fetch something (a web page, a search, weather, chain data), our server sends that request to the relevant source.
- Calls made through RapidAPI or Apify reach us with a pseudonymous user ID from that platform, which we store in place of an identity.
Tanod Tools
Most tools run entirely in your browser: your files never leave your device. The server tools (compress PDF, OCR, protect or unlock PDF, web page to PDF, image to text) upload your file for that one job. It is processed in a temporary directory, deleted when the job ends, and never logged. We keep the tool name, status and duration and a daily job count per IP address. These pages use Cloudflare Turnstile to block automated abuse.
Tanod Monitor
We store what you enter (targets, names, alert settings), the metrics your router or jobs send us (about a day of history per monitor), check results and exposure-scan results (up to 90 days). Manage tokens are stored only as hashes. Groups that are never opened and never report for 30 days are deleted with their data. Exposure scans run only against IPs and hosts whose control you have proven; how to opt out: scanner page.
Cookies and analytics
We do not set cookies. Cloudflare, which serves and protects the site, may set strictly necessary security cookies. We use Cloudflare Web Analytics, which does not use cookies, and Cloudflare's aggregated traffic statistics.
Who else processes data
- Cloudflare (CDN, security, Turnstile, analytics).
- The x402 payment facilitator (Coinbase Developer Platform) verifies and settles payments.
- Data sources we query on your behalf (for example search, weather, aviation, chain RPC providers) receive the request content needed to answer it, not your IP address.
We do not sell personal data.
Your choices
To ask what we hold about your IP address or wallet, or to have log entries deleted before the 30 days are up, email [email protected]. On-chain payment records cannot be deleted by anyone. If this policy changes, we update this page and its date.
Back to tanod.dev.