← AgentToll
Privacy
Last updated 15 September 2026
AgentToll has no accounts, no API keys and no sessions, so there is very
little about you for us to hold in the first place. This page describes exactly what exists.
What we do not collect
- No sign-ups, names, emails or passwords — there is no account system.
- No cookies, no analytics, no advertising or tracking scripts. The site loads no third-party code.
- No private keys. Payment authorizations are signed in your own wallet or agent.
- No per-caller state. The watch endpoints work from a cursor you send back, so we do not store where you left off.
What does exist
- Server logs. Completed and interrupted API requests record their time,
request ID, route template, HTTP outcome, duration, data-source counters and payment
failure stage/reason. Recognized client names and numeric versions may be retained as
self-reported diagnostics. Application request logs omit IP addresses, raw user-agent
text, query strings, requested wallet/name values and payment authorization payloads.
After successful facilitator verification or settlement, logs may include the verified
public paying address and transaction hash to diagnose payment faults. Once settlement is
confirmed, the log also records the amount, asset and payment network selected by the server.
We do not record signatures or private keys.
- Log retention. The application runs on Hetzner. Its Docker log files
rotate by size (three files of up to 10 MB each), so the time retained varies with
traffic. Operational reports may preserve selected diagnostic records while a fault
is investigated. Hosting/network providers can maintain separate operational logs.
- Onchain payments. x402 payments settle on Base, a public blockchain. The
paying address, amount and timestamp are public on the network. Our
/api/stats counter reads those public transfers; verified payer and receipt
identifiers may also appear in the diagnostic logs described above.
- Aggregate usage reports. We can aggregate the retained or exported server
logs to count browser safety-check quotes, payment submissions, failure stages, confirmed
settlements and reports delivered after payment. The aggregate separates known operator
wallets from other public paying addresses and can count an address as returning when it
pays on two or more UTC dates in the supplied log window. Commercial payment and wallet
totals include Base mainnet only; testnet receipts are shown separately. Aggregate output omits wallet
addresses. A wallet count is not a count of people, and an address outside our known operator
list is not necessarily an organic customer. Because logs rotate by size, these reports cover
only the records supplied to them.
- In-memory caches and rate limits. Data responses are cached for a
route-specific period; immutable historical snapshots can remain cached for six hours.
Cache keys describe requested data, not the paying identity. Per-IP counters enforce
one-minute request limits; they are separate from application request logs. Watch
cursors stay with the caller.
Third parties
The canonical website and API are hosted on Hetzner; Vercel is retained as a deployment
fallback. Coinbase's CDP x402 facilitator verifies and settles payments and receives their
authorization data. Endpoint data comes from sources including CoinGecko, GeckoTerminal,
DexScreener, Blockscout, alternative.me, GitHub and Base RPC. Those data providers receive our
server's queries, including requested public token/address identifiers where needed.
Your choices
Because we hold no account data, there is no profile to export or delete. If you want a
server log line removed, or have any privacy question, open an issue at
github.com/tevfikefeaydin/agenttoll
with the approximate timestamp and request ID. Issues are public: do not post private keys,
signatures or payment authorization payloads. Public blockchain records cannot be removed
by AgentToll.
AgentToll · agenttoll.base.eth · Terms