Public access is limited to 100 requests per 24-hour counter window by default. Every request, including discovery, consumes one slot. Responses include X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, and X-RateLimit-Tier; throttled requests return HTTP 429 and Retry-After. Provisioned API keys may have higher limits.
Rate limiting uses a server-secret HMAC of the network identifier; raw IP addresses and API keys are not used as counter keys. Counter identifiers expire after up to 24 hours. Operational telemetry stores only aggregate tool, coarse client family, success/error, latency bucket, and clean HAA source-path counts. It does not store prompts, tool arguments, raw IPs, API keys, full user agents, or error text.
Do not send names, contact details, medical records, symptoms, medication lists, or other personal or sensitive health information in tool arguments. See the Privacy Policy and Terms of Service.