Legal
Privacy Policy
Effective 2 October 2026.
AgentTrust (“we”) operates getagenttrust.com: the website, the REST API under /api/v1, and the MCP servers at /api/mcp and /api/mcp/public. This policy describes what data those services process, why, and for how long. Questions go to dlrhkdaud5592@naver.com.
Trust checks
A trust check (the check_agent_trust MCP tool, or the check page) takes one input: the endpoint URL to look up. We compare it with agents already stored in AgentTrust and return what we have observed. We never contact that URL during a check.
To understand how the service is used, we record a usage event for each completed check:
- when it happened, whether it came over MCP or the web page, and whether the URL matched a known agent;
- for a match: which agent, and the trust decision we returned;
- for no match: the URL's hostname (only when it is a public domain name) and a keyed hash of the URL with its query string and fragment removed;
- the first product token of the client's User-Agent header (for example
node); - a caller identifier: a keyed hash of the caller's IP address that changes every 30 days, so callers can be counted but not followed across periods.
We do not store the raw IP address, the full URL, query strings, request bodies, or any other header. Usage events are deleted after 90 days.
Rate limiting
Anonymous trust checks are rate-limited per IP address. To do that we store, for each one-minute window, a request count keyed by a hash of the IP address made with a secret key that changes every day. These records are only needed during their own minute and are deleted once they are more than a day old; deletion runs in the background, so one can occasionally remain somewhat longer. A separate service-wide count per minute, which contains no personal data, is kept for 90 days.
Accounts and API keys
- Signing up requires an email address and a password. Sign-in is handled by our authentication provider, Supabase, and a session cookie keeps you signed in. We use no advertising or analytics cookies.
- API keys are shown once when created and stored only as a keyed hash. We count requests per key to enforce rate limits.
- We keep a log of account actions, such as creating keys or registering agents, for security.
Agents and monitoring
- When you register an agent we store what you provide: its name, description, endpoint URL, version and capabilities, and, if you supply one, the credential needed to call its endpoint. Credentials are encrypted (AES-256-GCM) and used only to send health checks.
- A public agent's profile (never its credential) is shown on the website and returned by the API and MCP tools, together with its health history, reliability score and trust decision.
- We send health-check requests to monitored agents' endpoints, and ownership verification fetches a verification file from the endpoint's site.
- We also list MCP servers published in the official MCP Registry, using their public registry metadata, and monitor their public endpoints the same way.
MCP clients and AI assistants
Our MCP tools receive only the arguments a client sends with each call, such as an endpoint URL or an agent slug. We do not receive, request or store conversation content, chat history, memory or files from AI assistants that use our tools.
Your choices
You can ask us to access, correct or delete the data associated with your account or your registered agents by emailing dlrhkdaud5592@naver.com. Usage events and rate-limit records contain no account identifier and are deleted automatically on the schedules above.
Contact, support and security
For privacy questions, product support, or to report a security issue, email dlrhkdaud5592@naver.com. If this policy changes, we will update this page and its effective date.