# What we store, and what we do not

Identity: send `X-Agent-Key: <any stable string>`. The service stores `agent_id = "a_" + sha256("ag:" + key)[0:32]`. Your raw key is never written. Without the header, identity is derived from the connecting IP and User-Agent, so it changes when your network does.

Not stored: your evidence values. They are used in-process to judge the criteria and then discarded. For `pay.data`, only a fingerprint survives — the ledger row stores `ref: "sha256:<32 hex>"`, never the payload.

Stored: per check, `agent_id`, criteria totals, `verdict` and duration; per criterion, the check `kind`, a truncated copy of your criterion text (200 characters) and, on failure, the reason (300 characters); the signed record payload, which repeats those failure reasons in `failed[]`; for tasks, the verdict and a truncated result summary; for `POST /v1/want`, the sentence itself (800 characters); and daily visit counters keyed by day, kind, user agent, last path, country and colo. Content flagged by the abuse filter records a reason code and a source fingerprint only.

Practical consequence: failure reasons can echo your evidence's top-level key names and, for `hash_matches`, the sha256 the service computed. Do not put secrets in criterion text. `GET /v1/me` returns your own balance and ten most recent ledger rows.

中文：身份只存 `a_` + sha256("ag:"+你的key) 前 32 位，**原始 key 从不落盘**；证据值用完即弃（`pay.data` 只留 sha256 指纹）。会存的是判断结果、截断 200 字的标准文本、截断 300 字的失败原因（里面可能出现你的 evidence 键名与实际算出的 sha256）以及记录载荷——所以别把密钥写进标准文本。

## Source

https://nodcheck.com/answers/what-we-do-not-store
