Privacy

Post Oak Labs operates ainumbers.co and the MCP endpoint mcp.ainumbers.co. This policy covers both. Effective date:

In short

Scope

Two exceptions to "nothing leaves your tab", both triggered only by you: verifying a receipt at ledger.ainumbers.co, and timestamping an artifact you explicitly choose to anchor at anchor.ainumbers.co. Only the artifact you submit for anchoring is transmitted.

The website

Tool pages execute deterministic calculations locally in your browser. We set no cookies and use no client-side storage for identity or tracking. Your inputs and results stay in memory in your tab; there is no account to hold them against. The only network requests a page can make are the explicit actions above (verification, anchoring, and the MCP playground you aim at our endpoint yourself).

The MCP server (mcp.ainumbers.co)

The endpoint is public: no account, no API key, no sign-in. We receive no identity for you at all, including when you call it through an AI agent such as Muse.

For each tool call the server computes your result in memory and keeps no inputs and no outputs. To operate the service it records small structural metadata, and nothing more:

Our infrastructure provider (Cloudflare) processes standard request data transiently to deliver the service, under provider-default retention windows. Once a week, a scheduled job runs internal self-checks over demo fixtures and passes the receipts through our message queue; these contain no user content. Renewal checks for artifacts you have explicitly anchored are processed and then discarded, with no durable storage.

What we never do

We do not sell data, use it for advertising, build profiles about people, infer sensitive characteristics, or use it to train models. Operational metadata is used only to run, secure, and improve the service.

Retention and deletion

We hold no account data and nothing that identifies you, so there is generally nothing to delete. If you believe we hold data connected to you, write to us and we will delete what we can and confirm what was held.

Security

All traffic is encrypted in transit (TLS). The site enforces layered Content Security Policies; the endpoint is rate-limited and sends restrictive security headers. We publish a vulnerability-disclosure program with safe harbor on our security page. Secrets are never logged.

Contact and changes

General: contact@ainumbers.co · Security: security@postoaklabs.com

We will post any change to this policy on this page with a new effective date.