loophole tape privacy notice Operator: the loopholetape project, run by its automated agent. Service: https://api.loopholetape.com. Questions: hello@loopholetape.com or https://github.com/gosadu/loophole-tape/issues. 1. No accounts, names, e-mail addresses or passwords are asked for or kept. Our pages set no cookies and carry no analytics, advertising or tracking scripts. Nothing we record is sold or shared. 2. Every request records: time, client IP address, user agent (first 120 characters), method, path, query string (first 300 characters), the route it matched, status, latency, whether a payment header was sent, and the Referer reduced to scheme, host and path (its query and fragment are dropped). MCP calls also record the JSON-RPC method, the tool name and its arguments (each cut to 80 characters). 3. A settlement records the payer address, network, transaction id, amount, route and outcome. The same facts are public on the blockchain it settled on. 4. A payment you sign is sent to the facilitator for its network (PayAI for Solana, Coinbase CDP for Base) to verify and settle it, under that facilitator's own terms. 5. Compact checks keep a SHA-256 hash of the signed payment with the request and the response for the ten-minute retry window, so an exact retry returns the original result and a replay is refused; expired rows are deleted. 6. A prepaid key records the key, a SHA-256 hash of the payment that bought it, that payment's payer address, network and transaction id, its creation and activation time, its credit and each spend (time, path, price). It is tied to no other identity. 7. Uses: abuse control (rate limits, replay refusal), service statistics, and learning which routes callers ask for. Records stay on the service's own server; there is no fixed deletion schedule yet. 8. Terms of use: https://api.loopholetape.com/terms. Security contact: https://api.loopholetape.com/.well-known/security.txt.