agentlookups.ai / privacy

Privacy

This page covers every agentlookups.ai service: Plumbline, CounterScript, GroundTruth, GreenLight, Overassessed and GroundRules. What you look up can be private (a drug name, a home address), so these services are built to handle as little about you as they can. Each rule below holds for all six services. Where one service does less, or something extra, the table at the end says so.

The short version

Lookups

When you or your AI agent run a lookup (a license number, a business name, a drug, an address), the query goes to our server, which answers it from public records it already holds. The server does not save the query. The web server logs that a lookup happened (the time, your network address, your browser's identification string and the path, such as /v1/check) so we can spot anyone overloading the services, but its log format leaves out the words you searched. The table lists the lookup paths this covers for each service.

Two services pass a lookup onward, to the US Census Bureau's public geocoder, which works out where a location is. When you type an address into GroundTruth, our server sends the address. When you ask GroundRules what law applies at a place, or search it with an address, our server sends the address or the map coordinates you gave. The Census Bureau handles those requests under its own policies, which we do not control.

Page visits

Where a service logs page visits, the log holds what most web servers record: the page address, your network (IP) address, the time, your browser's identification string, and the page that linked you there, when your browser sends one. A page address can itself say what you looked at: a CounterScript drug page names the drug, and a Plumbline record page names the contractor. We use these logs to keep the sites running, fix problems and deal with abuse, and for nothing else.

When something breaks

If a service fails in the middle of a request, the web server writes a technical error line. That line includes the web address you requested, and a lookup's web address can hold the words you searched. Apart from GreenLight's state-code lookups, this is the only way the words of a lookup can reach a log. We use these lines only to fix faults and stop overload, and they are deleted after 14 days with the other logs.

Rate limiting

To keep the services up, the web server counts recent requests per network address in memory. The counts protect against overload and are not written to disk. A request turned away this way is recorded in the lookup log by its path only, like any other lookup; no error line is written for it.

What we keep on purpose

How long we keep things

Usage statistics

Each service except GroundRules keeps a daily tally so we can see what gets used and what breaks: how many requests each part of the service answered, what kind of client sent them (a browser, an AI agent such as ChatGPT or Claude, or a search-engine crawler), which state a lookup asked about, whether it found a match, the website that linked the visitor (its domain only, such as chatgpt.com), the rough shape of a search (a license number, or a name of two words), errors and response times. A tally holds counts and nothing else: no network addresses, no search words, no browser identification strings, no page addresses and no time finer than the day.

Once a week we email ourselves a report built from those tallies and the 14-day logs, including the busiest network addresses so we can spot overload. An AI service helps write the report from the tallies; the network addresses are added afterwards and never sent to it. GroundRules keeps no tally yet, and its logs are not part of this report.

Your choices

You can ask what we hold about you, or ask us to delete it, at support@agentlookups.ai. That includes removing your email address from a Plumbline error report or from the GreenLight signup file.

Service by service

ServicePage visits logged?Search words never logged atSpecific to this service
PlumblineYes, 14 days/search/, /v1, /mcpRecord-error reports (see above); email removable on request.
CounterScriptYes, 14 days/search/, /v1, /mcpA drug page's address names the drug, so visiting one leaves that name in the page log.
GroundTruthYes, 14 days/v1, /mcpTyped addresses go to the Census Bureau geocoder. "Use my location" is worked out by your browser, only after you allow it; only the coordinates reach us. Address lookups are sent with a no-store header.
GreenLightYes, 14 days/v1, /mcpA state lookup's address names the state (such as /v1/state/UT), so the state code is in the lookup log. Alert signups and the do-not-email list (see above).
OverassessedYes, 14 days, path only: no address reaches the page logEverything: pages, /v1, /mcpResult pages are sent no-store and noindex. Owner names from Maryland's roll never reach our systems.
GroundRulesYes, 14 days, except the search page and law pages, which are not logged at allNot logged at all, not even the path: the search page (/), /section/, /law/, /browse/, /v1, /mcpAddresses and map coordinates go to the Census Bureau geocoder: every location lookup, and any search you give an address. The server keeps recent typed addresses in memory for up to 15 minutes to answer repeats faster, and never writes them to disk. No daily usage tally.

Who runs this

All six services are run by TopHat Monkey Software LLC. Questions: support@agentlookups.ai. This page describes how the services are set up today, checked against their code and server configuration. If it ever drifts from what they do, that is a bug; please tell us.

Last updated: September 28, 2026