Privacy
Post Oak Labs operates ainumbers.co and the MCP endpoint mcp.ainumbers.co. This policy covers both. Effective date:
In short
- Our tools run in your browser. The inputs you type or paste into them never leave your tab.
- The MCP server holds no accounts, needs no sign-in, and never stores the inputs or outputs of a call.
- No advertising, no trackers, no cookies, no third-party analytics, no profiling. We do not sell data and we do not use data for model training.
- The server keeps only small operational metadata (listed below) so we can see that the service is up, fast, and correct.
Scope
Two exceptions to "nothing leaves your tab", both triggered only by you: verifying a receipt at ledger.ainumbers.co, and timestamping an artifact you explicitly choose to anchor at anchor.ainumbers.co. Only the artifact you submit for anchoring is transmitted.
The website
Tool pages execute deterministic calculations locally in your browser. We set no cookies and use no client-side storage for identity or tracking. Your inputs and results stay in memory in your tab; there is no account to hold them against. The only network requests a page can make are the explicit actions above (verification, anchoring, and the MCP playground you aim at our endpoint yourself).
The MCP server (mcp.ainumbers.co)
The endpoint is public: no account, no API key, no sign-in. We receive no identity for you at all, including when you call it through an AI agent such as Muse.
For each tool call the server computes your result in memory and keeps no inputs and no outputs. To operate the service it records small structural metadata, and nothing more:
- per call: tool name, success or failure, response time, chain depth, and a per-request correlation id;
- once per connection: the client application's name and version, the browser or agent type (User-Agent), and the coarse network operator (ASN). Your IP address is not stored.
Our infrastructure provider (Cloudflare) processes standard request data transiently to deliver the service, under provider-default retention windows. Once a week, a scheduled job runs internal self-checks over demo fixtures and passes the receipts through our message queue; these contain no user content. Renewal checks for artifacts you have explicitly anchored are processed and then discarded, with no durable storage.
What we never do
We do not sell data, use it for advertising, build profiles about people, infer sensitive characteristics, or use it to train models. Operational metadata is used only to run, secure, and improve the service.
Retention and deletion
We hold no account data and nothing that identifies you, so there is generally nothing to delete. If you believe we hold data connected to you, write to us and we will delete what we can and confirm what was held.
Security
All traffic is encrypted in transit (TLS). The site enforces layered Content Security Policies; the endpoint is rate-limited and sends restrictive security headers. We publish a vulnerability-disclosure program with safe harbor on our security page. Secrets are never logged.
Contact and changes
General: contact@ainumbers.co · Security: security@postoaklabs.com
We will post any change to this policy on this page with a new effective date.