Privacy
This site is a set of static pages. There are no accounts, no forms, no cookies set by us, and no third-party analytics or advertising scripts. The pages request nothing from any other domain.
What we log
Like nearly every website, our host (Cloudflare) records standard request metadata when you fetch a page: the path requested, the time, your browser's user-agent string, the referring page if your browser sends one, and network information such as IP address. We use an aggregate access log to understand which datasets are being read and by what kind of client — for example, to tell search-engine crawlers and AI assistants apart from people. We do not build profiles of individual visitors, and we have no way to identify you from these logs.
Outbound links
Some pages carry clearly marked outbound links to retailers or services (labelled as such, and marked sponsored where a commission could ever apply). Those links may pass through a local /out/ redirect first so that the click is counted in our own logs before your browser continues to the destination. What the destination site does is governed by its own privacy policy, not this one.
If a sponsored or advertising placement is ever added to a page, it will be visually distinct from the data, will never alter the data, and any third-party network involved will be named here.
The MCP server at /mcp
The same published data is available to AI assistants through a connector at https://referencesource.org/mcp. It works the same way the pages do, and it is worth being explicit about what that means for anyone whose assistant calls it:
- No account, no sign-in, no API key. The endpoint is anonymous and read-only. There is nothing to log in to and no credential to store, so we hold no user identity of any kind.
- It only reads our own published records. The four tools list datasets, search them, fetch one record, and check a claimed value against a record. None of them writes, deletes or changes anything, and none of them fetches an arbitrary URL on a caller's behalf.
- What is sent to us is the query itself. A search term or a claimed value travels in the request, and — like any request to any page — Cloudflare's standard request metadata is recorded. Send nothing personal: the tools answer questions about regulations and published figures, so a query never needs to contain anyone's details.
- Nothing is retained beyond the access log. We store no conversation, no chat transcript and no per-user history. The server keeps no state between calls at all — each request is answered on its own and forgotten.
- We do not sell or share this data, and no third party receives it. The aggregate access log is used only to see which datasets machines read.
The data itself
Every fact published here is drawn from the public sources cited on its own page. Records are about regulations, standards, and published figures — never about people.
Questions
The site publishes no tracking pixel, fingerprinting script, or email capture. If something on a page looks like it contradicts this note, that is a bug — the method page describes how the site is built and checked.