# Privacy Policy

Established and last updated: August 13, 2026

AI-Agent News & Advisory Portal / Agent-Readiness Directory (the "Service") is operated by chinng_inta as an individual. This policy explains how information is handled across the Service's website, public Markdown, REST API, Remote MCP, and Agent-Readiness Directory.

## 1. Information processed

When you access the Service or use its API or MCP endpoint, the Service may process:

- Access time, requested path, HTTP method, status code, and response size
- User-Agent, request ID, and Cloudflare Ray ID
- API or MCP operation, requested article ID, and category
- The name and version in MCP client-provided `clientInfo`
- An identifier generated with HMAC from an IP address and User-Agent or from an MCP client ID
- Text submitted through the anonymous feedback form

The Service's own analytics database does not store raw IP addresses, Bearer tokens, or search terms. MCP client IDs are HMAC-transformed before storage, and raw values are not stored. An HMAC-transformed identifier is not necessarily anonymous information under applicable law.

## 2. Purposes

Information is processed to:

- Provide the Service, REST API, and Remote MCP
- Secure the Service, detect and prevent abuse, and enforce rate limits
- Investigate failures, aggregate usage, and improve the Service
- Create and publish aggregates such as popular-page rankings that do not directly identify individuals
- Review anonymous feedback and reports
- Respond to lawful requests from public authorities or obligations under law

An access event indicates that content was retrieved; it does not indicate that an AI system quoted or used the content in a final answer.

## 3. Cookies and analytics

The Service does not use first-party cookies for advertising or behavioral tracking. Cloudflare may set cookies and process IP addresses or other network information as necessary for communications security, load balancing, and protection against unauthorized access.

Analytics are used to understand usage of articles, discovery resources, APIs, and MCP. Some aggregate results may be published as popular-page rankings.

## 4. External services

The Service uses the following providers. Their respective policies apply to their handling of information:

- [Cloudflare](https://www.cloudflare.com/privacypolicy/): TLS termination, CDN, reverse proxy, security, and communications protection
- [Google Forms](https://policies.google.com/privacy): operation of the anonymous feedback form and processing and storage of submissions

Provider infrastructure may be located outside Japan, and network information or other data may be processed outside Japan.

## 5. Anonymous feedback form

You can submit feedback or reports through the following Google form:

- [Anonymous feedback form](https://docs.google.com/forms/d/e/1FAIpQLSe6XXYFrQgqnqkOjSubgWA9LhJZPUG5XhS1ErJ-v_-xHJ8Tuw/viewform?fbzx=8771331953562657645)

The form does not automatically collect names or email addresses. Do not enter passwords, API keys, access tokens, addresses, telephone numbers, or other personal or confidential information. Because contact information is not collected, individual replies cannot be provided.

## 6. Disclosure and processors

The operator does not provide personally identifiable personal data to third parties except when required or permitted by law, including where necessary to protect life, physical safety, or property. Cloudflare, Google, and other providers may process data on the operator's behalf only as necessary to provide the Service and within the stated purposes.

## 7. Retention

The Service's own analytics events are generally deleted 90 days after they are recorded. Anonymous feedback submissions are retained for review and operationally necessary periods, then deleted when no longer needed. Data may be retained longer for security incidents, disputes, or legal obligations.

## 8. Security

The Service applies safeguards appropriate to the information processed, including TLS, access controls, authentication for administrative APIs, separation of secrets, HMAC transformation of identifiers, and retention limits.

## 9. Access, correction, and deletion

Where the Service holds personal data that identifies a specific individual, requests for access, correction, restriction, or deletion will be handled in accordance with applicable law to the extent that identity can be verified and the relevant data can be identified.

Because analytics are not stored in association with names or email addresses, it may not be possible to identify records corresponding to a particular user. The anonymous feedback form is not a channel for individual responses.

## 10. Changes to this policy

This policy may be revised in response to changes in the Service, external providers, or applicable law. Material changes will be announced on this page and take effect when the revised policy is posted.

Related document: [Terms of Use](/en-us/terms.md)

This English translation is provided for convenience. If it conflicts with the [Japanese version](/privacy.md?lang=ja), the Japanese version prevails.
