Effective 24 August 2026
Privacy Policy
This policy describes the minimum data processed by the Accord Trace public evidence service operated by Accord Trace project.
1. Evidence content
When you submit raw content, Accord Trace processes it in memory to calculate a SHA-256 digest and does not intentionally store the raw content. You may submit a client-computed hash instead so the service never receives the underlying content.
2. Public proof records
Proof IDs, evidence hashes, service timestamps, issuer data, attestations and metadata supplied with a proof are stored as public verification records. Do not place secrets, confidential information or unnecessary personal data in metadata.
3. Usage security data
For rate limiting and aggregate metrics, the service derives a salted one-way client identifier from connection data such as IP address and user agent. Raw IP addresses are not intentionally stored in the application database. Usage events include event type, status code, referral host and time.
4. Retention
Proof records are intended to be immutable and retained for verification. Usage events are deleted after 90 days. Rate-limit counters are deleted after approximately 24 hours. Infrastructure providers may maintain shorter operational or security logs under their own policies.
5. Analytics
Accord Trace uses first-party, cookie-free aggregate metrics for Agent Card discovery, MCP discovery, proof creation, retrieval, verification and errors. It does not use advertising pixels, browser fingerprinting or cross-site behavioural tracking.
6. Sharing
Public proof metadata can be retrieved by anyone with the proof ID. Service providers may process data only to host, secure and operate Accord Trace. We do not sell personal information.
7. Security
We use payload limits, bound SQL parameters, rate limiting, non-secret opaque identifiers and cryptographic service attestations. No system is risk-free; submit hashes rather than raw sensitive content.
8. Your choices
You control whether to submit content or a hash and what public metadata to attach. Immutable proof records cannot be edited through the public API. Contact us about unlawful or accidentally disclosed metadata; removal requests may conflict with evidence integrity and applicable obligations.
9. Contact
Privacy and security questions may be sent to replace-before-launch@example.invalid. Production launch is blocked until the operator identity and contact are configured.