Product
Privacy
Operator contact: michael@magentlab.com. magent is not a separately filed controller entity. Jurisdiction: United States.
What magent stores
Paid requests persist a ledger row on request_events: method, path without query,
status, outcome, latency, error code, and whether the request was paid. That table does not
store IP addresses, PAYMENT-SIGNATURE, nonce, HTML paywalls, or plaintext query
or body.
Encrypted copies of GET query strings, POST {items}, and JSON responses live in
ops_request_payloads
for the allowlisted Magent Console
(ops.magentlab.com). Console access is GitHub-allowlisted; views of Traffic open
are audited. Calculator inputs are treated as PHI-adjacent and are not printed in application
logs or SSH helpers.
Accounts in the console list wallets via payer_hmac (HMAC of the lowercase
address). Ciphertext stays encrypted. SSH settlement lookup prints method, route, status,
amount, and tx hash — never payer or payloads.
Retention
Payment ledger rows on request_events and payment_attempts (path without query, amount, tx) are kept for operations and dispute review. Encrypted console payloads in ops_request_payloads are deleted after 14 days (override OPS_PAYLOAD_RETENTION_DAYS). Email the operator to request earlier deletion of console payload rows for a request_id.
Processors
- Fly.io (application hosting)
- PostgreSQL (payment ledger and code catalog)
- Coinbase Developer Platform (x402 verify and settle)
- GitHub OAuth (allowlisted Magent Console only)
What magent does not store
- Client IP on the payment ledger
PAYMENT-SIGNATUREor EIP-3009 nonce- HTML paywall bodies
Public marketing and docs pages do not set a session cookie. The console at
ops.magentlab.com
uses a session cookie after GitHub login.