Privacy and authorization boundary

The boundary is part of the product.

Agents can search Not Human Search without an account or payment. A caller can attest that its principal currently wants a controlled next step and record that interest without contacting a provider. Creating a provider-funded ticket and asking NHS to continue to the provider are separate actions with separate versioned attestations.

NO RAW QUERY SALES · NO AGENT IDENTITY SALES · NO PAID ORGANIC RANK

What free discovery records

The exchange uses a query-free discovery receipt. Search text is classified in memory into no more than three controlled topics, then discarded from this receipt.

Query-free search receipt

Stored

  • Surface: web, REST, or MCP.
  • Controlled topics and explicit category.
  • Boolean capability filters, result count, page, and page size.
  • Returned site IDs, domain snapshots, scores, and organic positions.
  • Any paid offer shown: its ID, offer version, name, action type, disclosed bounty/currency, charge event, and organic-result binding.
  • The offer’s exact commercial-terms contract version and SHA-256, invalid/duplicate credit rule, provider response expectation, first-activation period-anchor rule, and Merchant-of-Record acknowledgement.
  • Whether the request was a marked deployment smoke test.
30-day eligibility · hourly physical deletion

Not in the discovery receipt

Excluded by schema

  • Raw search text or a hash/fingerprint of it.
  • Name, email, contact data, or principal identity.
  • Claimed agent identity or an agent-to-principal mapping.
  • IP address, IP hash, user agent, or referral trail.
  • A provider payment flag that could change organic score or order.
Never sold as row-level data

Record interest without contacting a provider

This wording is the complete contract represented by nhs-action-interest-v1. It records one controlled next step for aggregate Stage 1 demand; it is not a provider request, action ticket, verified outcome, or commercial event.

What the receipt stores

  • The opaque action-interest and query-free search-receipt IDs.
  • One exact domain already present in that organic result set.
  • One action: quote, trial, demo, booking, application, signup, or purchase.
  • REST or MCP surface, confirmation boolean, version label, and timestamps.
  • The receipt becomes ineligible for replay and reporting when its source search receipt reaches 30 days; the next successful boot or hourly cleanup then deletes the row.

What recording interest does not do

  • It does not contact or identify the caller to the provider.
  • It does not create an action ticket, redirect, charge, lead, activation, or conversion.
  • It does not change organic membership, order, readiness score, or provider eligibility.
  • It does not accept a raw query, prompt, note, contact detail, budget, region, or agent/principal identity.
  • The recording call creates no persisted IP/user-agent, page-view, MCP-request, intent-event, or API-key quota row.
  • It cannot count toward NHS commercial proof.

What a provider action ticket records

A ticket exists only for an active provider-funded offer attached to a site already present in the referenced organic result set. Creation returns a raw bearer token and the NHS handoff endpoint—not the provider action URL—and charges neither party.

Controlled ticket fields

  • Opaque provider-claim, provider-offer, and search-receipt IDs.
  • One topic already present on that receipt.
  • Optional region, USD budget band, urgency, and allowlisted requirement flags.
  • The authorization boolean and immutable consent-version label.
  • Immutable offer, price, bounty, action URL, billing, offer-version, exact commercial-terms contract/hash, credit-rule, response-expectation, terms-anchor, and provider Merchant-of-Record acknowledgement snapshots.

What NHS does not transmit in the ticket

  • No name, email, phone number, or other direct contact field.
  • No raw prompt, notes, free-form requirements, or uploaded content.
  • No claimed agent identity or principal identity.
  • No card, bank, or provider-account credentials.
  • No provider action URL is returned until the caller separately makes the handoff-time attestation below.
  • The provider may collect information on its own site under its own terms after the attributed action URL is followed.

At 30 days, NHS read paths stop returning the ticket’s controlled intent fields and search-receipt link. NHS schedules their physical redaction on the next successful boot or hourly cleanup; downtime or cleanup failure can delay that redaction without extending resolver availability. It retains the ticket consent attestation, immutable commercial snapshot, opaque IDs, handoff receipt, and signed outcome/accounting records as commercial and audit history; the schema does not promise automatic deletion of those retained records.

Operational and commercial records

Abuse and reliability telemetry

Separate operational logs for ordinary discovery can contain a truncated IP hash, user agent, route, status, duration, and allowlisted MCP arguments. Ticket preparation, observed handoff, optional controlled-intent resolution, and action-interest recording bypass page-view and request-line identity telemetry; the privacy-bypassed MCP actions also skip MCP request and paid-usage telemetry. Page, MCP, and intent-event logs become eligible for boot or hourly deletion after 30 days; priority-throughput usage events after 35 days. Downtime or cleanup failure can delay physical deletion. New discovery analytics do not write raw query text.

Provider and accounting records

Provider accounts retain an email, DNS claim state, key hashes, offer terms, exact non-secret evidence references, append-only admin actions, budget entries, and signed outcome receipts. Callback secrets are returned to the provider and stored only as hashes.

DNS ownership freshness

The provider must keep its TXT value published. During initial verification and automatic rechecks, NHS compares DNS answers in memory and does not retain the raw answers or challenge token; it stores only the SHA-256 token hash, check timestamps, and failure count. Paid-action eligibility stops after 3 consecutive failed checks or when the last successful check reaches 7 days old. Claim revocation pauses offers and revokes callback keys and outstanding action authorization.

Verified commercial evidence

A provider-key-authenticated pilot-company or exact-terms acceptance is stored as one append-only event, but does not become proof by itself. Separately, the owner records an externally deduplicated keyed company digest—rather than the raw legal or billing identity in the pilot-company table—and a non-secret identity evidence reference. Funding, exact-terms, renewal, and reversal evidence are separate owner-verified append-only events with exact source references, effective times, offer version, and commercial-terms version/hash. Reversals append a new event; they do not rewrite history.

Retention

Provider acceptance events, keyed company mappings, owner-verified commercial events, reversals, handoff receipts, budget/accounting links, and signed outcomes are retained as commercial and audit records. The exchange schema and pilot runbook do not specify an automatic deletion interval for them.

Demand reports

Owner-only Stage 1 reports count meaningful searches, result selections, and action-interest receipts without exposing row-level searches or interests. Any segmented topic or action bucket is suppressed until at least 20 persisted, non-synthetic receipts qualify. Because NHS deliberately does not retain agent identity in these receipts, every threshold counts receipts—not distinct people, principals, or agents.

Who charges whom

Pilot terms require the provider to remain Merchant of Record for its product or service; NHS does not independently verify that status. NHS does not charge the principal for a ticket. NHS records a provider-funded debit or capped CPA receivable only on the disclosed provider-reported event. An authenticated invalid or duplicate report can credit an existing charge after ticket expiry or authorization revocation, but cannot create a new charge or positive outcome.

Controls that stay with each party

Agents and principals

Search or use the canonical organic link without recording interest, decline provider-funded actions, withhold either required versioned attestation, or decline the separate optional controlled-intent disclosure without blocking handoff.

Providers

Pause an offer, rotate a callback key, or revoke a domain claim. Emergency operator action can invalidate outstanding authorization.

NHS operator

Can pause inventory and preserve append-only evidence, but cannot sell organic rank, readiness score, raw queries, or agent identities.

Access, deletion, or correction

Email the address below with the provider domain and request type. NHS will verify authority before changing a provider account. Commercial, security, and accounting records may be retained where needed to preserve signed receipts, resolve disputes, or meet legal obligations.

hello@nothumansearch.ai