Privacy Policy
Effective Date: August 30, 2026
GexLog is operated by an individual doing business as GexLog, located in the State of Minnesota, United States (the "Operator", "we", "us", or "our"). This Privacy Policy describes what information we collect when you use gexlog.com, its subdomains including the API at agent.gexlog.com, and the WebMCP tools on our pages (together, the "Service"), how we use that information, and the choices you have.
The Service is intended for and directed to users in the United States. We do not offer the Service to, or target, residents of the European Economic Area, the United Kingdom, or Switzerland, and we do not intend to subject ourselves to the GDPR or the UK GDPR. If you access the Service from outside the United States, you do so on your own initiative.
1. Information We Collect
A. Technical data collected automatically
When you access the Service, our hosting provider, our content delivery network, and our analytics provider automatically record technical data, including:
- IP address
- Browser type, version, and user agent string
- Device type and screen size
- Pages requested, referring page, and the date and time of each request
- Interaction data captured by Microsoft Clarity (see Section 3), such as clicks, scrolling, mouse movement, and session recordings
B. Information you provide through the contact form
If you use our contact form, we collect the name, email address, and message you enter. We use this information solely to respond to you.
C. Operator login sessions and security records
There is no public account registration. Login is available only to a small number of authorized accounts used to operate the site. When a login attempt fails, we record the IP address, the username entered, and the time of the attempt in order to detect and block brute-force attacks. Short-lived IP-based rate-limiting records are also kept for certain endpoints.
D. Agent API payment and access records
When you pay for an API request using the x402 protocol with USDC, or access a paid route with a partner key, we record the following in a transaction log: timestamp, route requested, query parameters, IP address, your payment wallet address, the amount and network, the blockchain transaction identifier, and, for partner-key requests, the partner name assigned to the key. We use this record to verify and settle payments, prevent duplicate settlement (replay protection), enforce rate limits, and maintain accounting records. Requests to free API routes are not written to this log, although they appear in ordinary server logs like any other request.
Blockchain transactions are inherently public and permanent. We do not control the public ledger and cannot delete on-chain records.
2. Cookies, Do Not Track, and Similar Technologies
Session cookie (first party). Our server sets a session cookie that contains a random identifier and no personal information. It is strictly necessary to maintain a browsing session and to authenticate authorized operator accounts, and it expires when you close your browser.
Third-party cookies and scripts. Microsoft Clarity sets cookies and uses similar technologies to recognize returning visitors and record sessions. Google reCAPTCHA Enterprise, used on the contact page, may set cookies and collects device and interaction data. Details are in Section 3. You can block or delete cookies through your browser settings; blocking third-party scripts will disable session recording and may prevent the contact form from working.
Do Not Track. Some browsers transmit "Do Not Track" (DNT) signals. There is no industry-standard response to DNT signals. This site does not currently respond to DNT signals, and it does not track visitors across third-party websites over time. Third-party services embedded on this site (Microsoft Clarity and Google reCAPTCHA) may collect information as described below and may respond to such signals under their own policies. Because we do not sell personal information or share it for targeted advertising, opt-out preference signals such as Global Privacy Control do not change how we process your data.
Advertising. We do not use Google AdSense or any third-party advertising network. Sponsored placements on the site are served from our own server and set no cookies.
3. Service Providers
We rely on the following third parties to operate the Service. Each processes data under its own privacy policy.
Microsoft Clarity (analytics and session replay)
We partner with Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve our services. Website usage data is captured using first- and third-party cookies and other tracking technologies to determine the popularity of pages and online activity. We also use this information for site optimization and for fraud and security purposes. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
Google reCAPTCHA Enterprise (contact form protection)
We use Google reCAPTCHA Enterprise to protect our contact form from abuse. reCAPTCHA collects hardware and software information, such as device and application data, and interaction data, and sends it to Google for analysis. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Google Fonts
We use Google Fonts to display text. Your browser requests font files from Google's servers, and Google may receive your IP address and browser information in the process. See the Google Privacy Policy.
Web3Forms (contact form delivery)
When you submit our contact form, your name, email address, and message are transmitted to our form-processing provider, Web3Forms (api.web3forms.com), which forwards the submission to us by email. See the Web3Forms privacy policy for its handling of submission data.
NameHero (hosting) and Bunny.net (content delivery network)
Our site is hosted on shared hosting provided by NameHero and served through the Bunny.net content delivery network. These providers automatically process technical data, including your IP address, browser type, and request logs, to deliver and secure the site and to protect against abuse and denial-of-service attacks. Retention of these logs is governed by those providers' policies. See the NameHero and Bunny.net privacy policies.
x402 payment facilitators
API payments are verified and settled through third-party x402 facilitators, including the Coinbase Developer Platform facilitator and Circle. When you pay, your signed payment authorization, which includes your wallet address, is transmitted to the facilitator for verification and on-chain settlement. See the Coinbase and Circle privacy policies.
AI providers
Market narratives, summaries, and video scripts are generated with the assistance of AI models from Anthropic and Google (Gemini). These models receive pre-computed market data only. We do not send visitor data to AI providers.
4. How We Use Information
- To deliver, operate, secure, and improve the Service
- To respond to messages you send through the contact form
- To verify and settle API payments, prevent duplicate settlement, and enforce rate limits
- To detect, investigate, and prevent abuse, fraud, and unauthorized access
- To keep accounting and tax records
- To comply with legal obligations
5. How We Share Information
We share information only with the service providers listed in Section 3, to the extent needed for them to perform their functions, and where required by law or legal process, or to protect the rights, property, or safety of the Operator or others. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Affiliate links. The Service contains affiliate links, currently to TradingView and Option Alpha. When you click one, the partner learns that you arrived from GexLog through a referral identifier in the link. We do not send the partner any personal information about you. The partner's own privacy policy governs what it collects on its site.
6. Data Retention
- Contact form messages: retained in our email for as long as needed to respond and for our records.
- Failed login records: approximately 30 days; records of attempts that trigger our anti-abuse rules are retained for approximately 365 days.
- Rate-limiting records: from one minute up to 24 hours, depending on the endpoint.
- API transaction log: retained as part of our accounting records and not automatically deleted.
- Hosting, CDN, analytics, and reCAPTCHA data: retained according to the respective provider's policy.
7. Your Choices and Requests
Because of the limited personal data we hold and the size of this operation, we do not meet the thresholds that would make us a "business" under the California Consumer Privacy Act or a covered controller under the Minnesota Consumer Data Privacy Act or similar state laws. As a courtesy, regardless of where you live, you may use our Contact Form to ask what personal data we hold about you or to request that we delete it, and we will make reasonable efforts to honor your request. Please note that in most cases we cannot identify you from technical data such as an IP address, that we cannot alter on-chain blockchain records, and that data held by the third-party providers in Section 3 must be requested from them directly.
8. Children's Privacy
This site is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us and we will delete it. Separately, our Terms of Service require users to be at least 18 years old.
9. Security
The Service is served over HTTPS. Security records, payment logs, and configuration are stored outside the public web root with restricted access, and administrative accounts are protected by two-factor authentication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when the current version took effect. Changes are effective when posted on this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us at: Contact Form