What we log, and what we deliberately do not
A licensing gateway sees a lot of traffic. Most of it is none of our business.
We sit in front of your API calls. That is a position of some privilege and it deserves an explicit answer about what we retain.
What we record
For each gateway call: which key, which endpoint you named, the outcome, the reason if refused, the calling IP, and the time.
That is what makes your usage page work, what lets you answer *why did this fail at 3am*, and what lets us enforce plan limits and spot abuse.
What we do not
We do not record your request bodies. We do not proxy your API — your data does not pass through us at all. The verify call tells us a key was used; it does not tell us what it was used for.
That is an architectural property, not a policy one, which is the kind worth having. A policy can change with a board meeting. An architecture cannot hand over what it never held.
We could not disclose your API payloads under subpoena, under pressure, or by mistake, because they have never been on our disks.
Retention
Usage rows can be pruned on a schedule the operator configures. Longer is better for debugging and worse for everything else, and there is no universally right answer — so it is a setting rather than a default we impose.
If you are running this yourself, pick a number and write down why. Ninety days is a defensible default: long enough to investigate a pattern, short enough that a breach exposes a season rather than a history.
IP addresses
We keep the calling IP because IP allowlisting cannot work without it, and because a refusal you cannot trace to a caller is a refusal you cannot debug.
It is worth being clear that this is personal data in most jurisdictions, and it is covered by the same retention setting as the rest of the usage log.
Bot checks
A browser check necessarily looks at request headers and asks the client to run a small script.
It does not fingerprint across sites. It does not persist anything on the visitor's device beyond the life of a single check. It does not build a profile. What it produces is one bit: this looked like a browser, or it did not.
Because it runs on *your* visitors rather than on you, you should mention it in your own privacy notice. We are a processor there; you are the controller.