Privacy
Quartermaster is built privacy-first. The short version: no accounts, no tracking, no advertising, nothing about your requests is sold, and payloads are not retained.
What we do not do
- No user accounts and no login. There is no profile to leak.
- No analytics or advertising trackers, no third-party pixels, no cross-site cookies.
- We do not sell, rent, or share request data with anyone.
- We do not retain the bodies of the URLs, text, or payloads you pass to tools. They are processed to produce a response and then dropped.
What is unavoidably processed
- Payment settlement is public. x402 payments settle in USDC on Base or Solana, both public blockchains. Transaction hashes/signatures, amounts, and the paying and receiving addresses are visible on-chain by design. That is the protocol, not us.
- Cloudflare edge logs. The site runs on Cloudflare Workers. Cloudflare processes request metadata (IP, timestamp, path) as an infrastructure provider under its own terms. We do not log the payloads you send to tools, and we do not export or mine those edge logs. We do emit operational diagnostics for our own settlement and error monitoring, which can include on-chain payment details (payer address, transaction hash) that are already public on Base - never your request bodies.
- Operational self-tests. A daily internal check records only our own endpoint health and our own canary payments, never your requests.
- Paid report orders. If you order an Endpoint Health Report or Deep Review at /verify, we store the contact email and endpoint URL you provide, the generated report, and an order record for up to 1 year, solely to deliver the report, honor re-checks, and keep a sales record. Report delivery email is sent through Resend (our email processor) to the address you gave. This is the only personal data Quartermaster stores, it is never sold or shared beyond that processor, and you can request deletion at any time (see Your controls).
- Public endpoint pages. The ecosystem dashboard publishes automated audit results about publicly reachable x402 endpoints (URLs already published in public discovery catalogs). These pages contain technical facts about servers, not personal data. Endpoint operators can request a re-check, correction, or removal review at dev@surewhynot.app.
AI endpoints
Six endpoints run models on Cloudflare Workers AI (summarize, translate, embed, extract-json, moderate, describe-image). The text or URL you send is passed to the Cloudflare-hosted model to produce the result and is not retained by Quartermaster. It is handled by Cloudflare Workers AI under Cloudflare's terms; it is not sent to any third-party model provider. Do not send secrets, credentials, or personal data you would not want processed by a cloud AI service. See Security for the request-safety guards.
Your controls
There are no accounts and no retained tool payloads, so for API usage there is no stored personal data to export or delete. If you placed a report order, email dev@surewhynot.app from the ordering address and we will delete the order record and report on request. If you believe an on-chain transaction or a cached page references you and you want it discussed, use the same address.
Effective 2026-07-08. Operated by SureWhyNot, LLC. This page describes current behavior and is versioned in the changelog. See also the Terms of Service.