Effective: August 31, 2026 · Applies to aye.today and api.aye.today
X-Agent-Id header you choose, and a one-way SHA-256 hash of your IP address used only for rate limiting and demand deduplication. We do not store raw IPs. Because IP space is enumerable, this hash reduces casual exposure but is not anonymity or strong de-identification.A successful media-consistency request creates a signed, content-addressed evidence bundle. Its /v1/bundle/{bundle_id} URL is a public bearer URL: no account, payment, or authentication is required to retrieve it, and anyone who obtains the URL may read, copy, or share it. The bundle ID is not an access-control mechanism and should not be treated as a secret-sharing guarantee.
The public bundle includes the exact latitude and longitude submitted, the normalized claimed UTC timestamp, the media SHA-256, asserted facts, itemized checks and observations, source URLs and payload digests, verdict, signature, and timestamp-anchor receipts. Do not submit a location/time combination or media hash that you are unwilling to make publicly retrievable. AYE does not publish or receive the raw media itself.
| Data | TTL |
|---|---|
| Demand-ledger entries and dedupe markers | 90 days |
| Settlement audit rows / replay set | 180 days / 7 days |
| Source-payload attestations (digest + URL) | 90 days |
| Evidence bundles in R2 (including exact location/time and media hash) | No application-level automatic expiry is configured. Retained until operator deletion or a future bucket-retention policy; deletion is not guaranteed while a legal, integrity, or operational hold applies. |
| Evidence bundles in legacy/local KV fallback | 365 days from the latest write or anchor refresh |
| Nightly ledger snapshots | 365 days |
| Research-Lab memory extracts (private repo) | Indefinite, no personal data by design; subject strings are places/conditions, not people |
Settlement rows written before August 31, 2026 may contain a facilitator-verified wallet address and an unverified client payer header in their original form; those legacy rows expire under the 180-day TTL. New rows pseudonymize the verified payer and do not retain the unverified header.
Cloudflare (edge serving and KV/D1/R2 storage), Coinbase Developer Platform (x402 payment verification/settlement facilitation), GitHub (private research memory). We do not sell data and run no advertising trackers.
Because identifiers are pseudonymous and there is no account system, requests must identify the relevant bundle URL or other record. Public copies already retrieved or shared by others may remain outside AYE's control. For questions or requests contact ops@aye.today. We serve EU and other international visitors on a minimal-footprint basis and will honor applicable access/deletion rights where they lawfully attach.
Published here with a new effective date when material.