Wellknown is an index of publicly published AI agents and MCP servers, operated by Moneyed28 LLC (United States). This notice describes what we collect from the people and agents that use the site, and what we do with metadata about the resources we index. It is written to match what the software actually does; the machine-readable version of the same commitments is served at /api/v1/terms (version 2026-09-05).
We use Google Analytics 4 to count visits and see which pages are read. It is loaded only after you accept analytics in the banner shown on your first visit; until then it runs in a consent-denied mode that sets no analytics cookies. If you accept, Google sets cookies named _ga and _ga_<id> to recognise a returning browser. We enable IP anonymisation and disable advertising signals and ad personalisation, so the data is not used to build advertising profiles. You can withdraw consent at any time by clearing the site's cookies and site data in your browser, which brings the banner back.
Our hosting provider keeps ordinary web-server logs (address, time, path, user agent, response code) for operational and abuse-handling purposes. We do not sell data, we do not run advertising, and we do not share visitor data with anyone beyond the providers named here.
The API, the MCP server, the A2A endpoint and the ARD interface are usable without an account. For those requests we store a salted daily aggregate: the caller's address and user agent are hashed together with a server-side secret into an identifier that cannot be reversed, and we keep counts per day, per surface and per route. Raw addresses are never written to the database. Callers using an API key are counted per key, so the key holder can see their own usage in the dashboard.
Search queries are not stored. We keep only an aggregate count of how many searches arrived per day, in which script the query was written (Latin, Han, Cyrillic and so on), which lexical path answered it, and whether it returned nothing. The text of a query never reaches the database or a log.
Signing in uses GitHub OAuth. We receive and store your GitHub login, numeric id and, where GitHub provides it, your email address. A session cookie is set: HttpOnly, SameSite=Lax, Secure in production, valid for 30 days, containing only your developer id in a signed token. API keys you create are stored as SHA-256 hashes with a short display prefix — the key itself is shown once and cannot be recovered by us. If you set an alert webhook for a record you own, we store that URL and call it when the record's observed status changes. Deleting your account or a key removes the corresponding rows; write to us and we will do it.
Records describe published software, not people. Their declared half is public metadata collected from the sources listed on Sources & freshness — package registries, the official MCP registry, public repositories and documents an operator publishes under /.well-known/. It stays attributed to the source it came from. The observed half is our own measurement: whether an endpoint answered a read-only protocol handshake, how quickly, and when. Where declared metadata happens to contain a personal name, such as a package author, it is published because and where the source published it.
If a record concerns something you control, you can correct it by proving ownership, which lets you edit the record and request removal from the dashboard. You can also keep our crawler away entirely: see about our crawler for the user agent, the robots.txt rules we honour, and how a 403 or 410 response takes a record out. Or write to us and we will hide it.
Observations and the records built from them are kept indefinitely, because a reliability history is the point of the index. Usage and query aggregates are kept as daily rows with no identifiers in them. Sessions expire after 30 days. Analytics retention follows the Google Analytics property setting.
Railway (hosting and the Postgres database, United States), Google Analytics (website statistics, only with consent), GitHub (sign-in), and OpenRouter (the model that writes the journal from a fact sheet computed from our own index; no visitor or caller data is sent to it). Each processes data on our instructions only.
You can ask what we hold about you, ask for it to be corrected or deleted, or object to a use of it. Write to hello@moneyed28.com and we will answer. The same address is the one in our security.txt, and the fastest route for anything about a specific record is a claim.
Last updated 2026-09-05. Changes are versioned together with the terms; material changes will be noted here and in the machine-readable terms document.