Three things we owe you, on one page.
Last updated: 2026-09-13. We update this page before any material change.
Security
What runs
wakala is a single Go binary. The page and the page-view log are served by that binary, backed by an embedded SQLite database. There is no separate API service, no background worker fleet, and no third-party data processor in the request path. One browser-side analytics script loads after the page is delivered — see Privacy › Rybbit.
What we log
Every page view records six fields. None of them identify you on their own.
- ip_hash
- SHA-256 of
<salt>|client_ip, where the salt comes from the deploy-timeANON_SALTenvironment variable. - ua_hash
- SHA-256 of
<salt>|user_agent, same salt. - path
- Request path, e.g.
/or/policies. - referer
- The
Refererheader, truncated to 512 characters. - user_agent
- The raw
User-Agentstring, truncated to 512 characters. - accept_language
- The
Accept-Languageheader, truncated to 128 characters.
What we don't log
- Request bodies. We do not record what you submit, click, or type.
- Cookies. We do not set any. We do not read any.
- Local storage, session storage, or fingerprinting signals.
- The raw client IP. Only its salted hash reaches the database.
How the Challenge endpoint differs
The Challenge is our diagnostic sandbox (see /challenge).
When the Challenge is live, /challenge issues an API key for the time-boxed
MCP server and records only the same six fields above. Prompts your agent sends during
the Challenge are processed by the MCP server but are not stored in our database.
Disclosure schedule
If we ever change the logging fields, add a third-party processor, or store new categories of data, this page is updated before any planned change ships, and within a few days of any emergency change. The date at the top is the most recent change.
Privacy
What we collect
From this site: the six page-view fields listed under Security › What we log. Nothing else. No name, no email, no account, no behavioral profiles.
What it's used for
Counting visits, surfacing referrers in -report, and answering the
question "is anyone reading this?". It is not fed to a marketing automation platform,
not joined to a customer database, and not sold.
Rybbit
A single third-party analytics script loads at the bottom of each page
(hosted at analysis.mrashad.com). Rybbit is cookieless and does not
set identifiers in your browser. For details on what Rybbit collects, see
rybbit.com/privacy.
Data retention
Page views stay in the operator's local SQLite database until the operator deletes
the file. There is no automatic rotation or export. If the database is wiped, the
log goes with it. Rotating ANON_SALT (the deploy-time secret used to
hash IPs and user agents) makes every prior record unlinkable to any new one — even
while the file remains on disk.
Your rights
Email info@wakala.dev to ask what we hold that can be tied back to you, or to request its removal. The only such data is the salted IP and UA hashes from your visits.
Terms
The service
This site is a marketing site for wakala. It is provided as-is.
There is no service-level agreement, no uptime promise, and no warranty that any
feature described here will ship on any particular schedule.
The Challenge
When the Challenge is live, it is a time-limited, unguarded run of the MCP server intended to let you observe your agent's behavior without workflow rules. It is provided as-is, and we may revoke access at any time during the Challenge window. Keys issued for the Challenge expire when the window closes.
Acceptable use
- Use the site and the Challenge for the purpose they were built for.
- Don't use them to probe, attack, or otherwise abuse us or anyone else.
- Don't use the Challenge to generate load that interferes with other visitors.
Governing law
These terms are governed by the laws of the operator's jurisdiction. If you need a specific jurisdiction named on this page, contact info@wakala.dev and we'll fill it in.