agentlookups.ai / privacy
This page covers every agentlookups.ai service: Plumbline, CounterScript, GroundTruth, GreenLight, Overassessed and GroundRules. What you look up can be private (a drug name, a home address), so these services are built to handle as little about you as they can. Each rule below holds for all six services. Where one service does less, or something extra, the table at the end says so.
When you or your AI agent run a lookup (a license number, a business name, a drug, an address), the query goes to our server, which answers it from public records it already holds. The server does not save the query. The web server logs that a lookup happened (the time, your network address, your browser's identification string and the path, such as /v1/check) so we can spot anyone overloading the services, but its log format leaves out the words you searched. The table lists the lookup paths this covers for each service.
Two services pass a lookup onward, to the US Census Bureau's public geocoder, which works out where a location is. When you type an address into GroundTruth, our server sends the address. When you ask GroundRules what law applies at a place, or search it with an address, our server sends the address or the map coordinates you gave. The Census Bureau handles those requests under its own policies, which we do not control.
Where a service logs page visits, the log holds what most web servers record: the page address, your network (IP) address, the time, your browser's identification string, and the page that linked you there, when your browser sends one. A page address can itself say what you looked at: a CounterScript drug page names the drug, and a Plumbline record page names the contractor. We use these logs to keep the sites running, fix problems and deal with abuse, and for nothing else.
If a service fails in the middle of a request, the web server writes a technical error line. That line includes the web address you requested, and a lookup's web address can hold the words you searched. Apart from GreenLight's state-code lookups, this is the only way the words of a lookup can reach a log. We use these lines only to fix faults and stop overload, and they are deleted after 14 days with the other logs.
To keep the services up, the web server counts recent requests per network address in memory. The counts protect against overload and are not written to disk. A request turned away this way is recorded in the lookup log by its path only, like any other lookup; no error line is written for it.
Each service except GroundRules keeps a daily tally so we can see what gets used and what breaks: how many requests each part of the service answered, what kind of client sent them (a browser, an AI agent such as ChatGPT or Claude, or a search-engine crawler), which state a lookup asked about, whether it found a match, the website that linked the visitor (its domain only, such as chatgpt.com), the rough shape of a search (a license number, or a name of two words), errors and response times. A tally holds counts and nothing else: no network addresses, no search words, no browser identification strings, no page addresses and no time finer than the day.
Once a week we email ourselves a report built from those tallies and the 14-day logs, including the busiest network addresses so we can spot overload. An AI service helps write the report from the tallies; the network addresses are added afterwards and never sent to it. GroundRules keeps no tally yet, and its logs are not part of this report.
You can ask what we hold about you, or ask us to delete it, at support@agentlookups.ai. That includes removing your email address from a Plumbline error report or from the GreenLight signup file.
| Service | Page visits logged? | Search words never logged at | Specific to this service |
|---|---|---|---|
| Plumbline | Yes, 14 days | /search/, /v1, /mcp | Record-error reports (see above); email removable on request. |
| CounterScript | Yes, 14 days | /search/, /v1, /mcp | A drug page's address names the drug, so visiting one leaves that name in the page log. |
| GroundTruth | Yes, 14 days | /v1, /mcp | Typed addresses go to the Census Bureau geocoder. "Use my location" is worked out by your browser, only after you allow it; only the coordinates reach us. Address lookups are sent with a no-store header. |
| GreenLight | Yes, 14 days | /v1, /mcp | A state lookup's address names the state (such as /v1/state/UT), so the state code is in the lookup log. Alert signups and the do-not-email list (see above). |
| Overassessed | Yes, 14 days, path only: no address reaches the page log | Everything: pages, /v1, /mcp | Result pages are sent no-store and noindex. Owner names from Maryland's roll never reach our systems. |
| GroundRules | Yes, 14 days, except the search page and law pages, which are not logged at all | Not logged at all, not even the path: the search page (/), /section/, /law/, /browse/, /v1, /mcp | Addresses and map coordinates go to the Census Bureau geocoder: every location lookup, and any search you give an address. The server keeps recent typed addresses in memory for up to 15 minutes to answer repeats faster, and never writes them to disk. No daily usage tally. |
All six services are run by TopHat Monkey Software LLC. Questions: support@agentlookups.ai. This page describes how the services are set up today, checked against their code and server configuration. If it ever drifts from what they do, that is a bug; please tell us.
Last updated: September 28, 2026