Three things we owe you, on one page.

Last updated: 2026-09-13. We update this page before any material change.

Security

What runs

wakala is a single Go binary. The page and the page-view log are served by that binary, backed by an embedded SQLite database. There is no separate API service, no background worker fleet, and no third-party data processor in the request path. One browser-side analytics script loads after the page is delivered — see Privacy › Rybbit.

What we log

Every page view records six fields. None of them identify you on their own.

ip_hash
SHA-256 of <salt>|client_ip, where the salt comes from the deploy-time ANON_SALT environment variable.
ua_hash
SHA-256 of <salt>|user_agent, same salt.
path
Request path, e.g. / or /policies.
referer
The Referer header, truncated to 512 characters.
user_agent
The raw User-Agent string, truncated to 512 characters.
accept_language
The Accept-Language header, truncated to 128 characters.

What we don't log

How the Challenge endpoint differs

The Challenge is our diagnostic sandbox (see /challenge). When the Challenge is live, /challenge issues an API key for the time-boxed MCP server and records only the same six fields above. Prompts your agent sends during the Challenge are processed by the MCP server but are not stored in our database.

Disclosure schedule

If we ever change the logging fields, add a third-party processor, or store new categories of data, this page is updated before any planned change ships, and within a few days of any emergency change. The date at the top is the most recent change.

Privacy

What we collect

From this site: the six page-view fields listed under Security › What we log. Nothing else. No name, no email, no account, no behavioral profiles.

What it's used for

Counting visits, surfacing referrers in -report, and answering the question "is anyone reading this?". It is not fed to a marketing automation platform, not joined to a customer database, and not sold.

Rybbit

A single third-party analytics script loads at the bottom of each page (hosted at analysis.mrashad.com). Rybbit is cookieless and does not set identifiers in your browser. For details on what Rybbit collects, see rybbit.com/privacy.

Data retention

Page views stay in the operator's local SQLite database until the operator deletes the file. There is no automatic rotation or export. If the database is wiped, the log goes with it. Rotating ANON_SALT (the deploy-time secret used to hash IPs and user agents) makes every prior record unlinkable to any new one — even while the file remains on disk.

Your rights

Email info@wakala.dev to ask what we hold that can be tied back to you, or to request its removal. The only such data is the salted IP and UA hashes from your visits.

Terms

The service

This site is a marketing site for wakala. It is provided as-is. There is no service-level agreement, no uptime promise, and no warranty that any feature described here will ship on any particular schedule.

The Challenge

When the Challenge is live, it is a time-limited, unguarded run of the MCP server intended to let you observe your agent's behavior without workflow rules. It is provided as-is, and we may revoke access at any time during the Challenge window. Keys issued for the Challenge expire when the window closes.

Acceptable use

Governing law

These terms are governed by the laws of the operator's jurisdiction. If you need a specific jurisdiction named on this page, contact info@wakala.dev and we'll fill it in.