Privacy · syfert.com

Privacy

What this site keeps

Effective 10 September 2026

This site is run by one person: Graham W. Syfert, a Jacksonville, Florida attorney. There is no company behind it, no analytics department, no data broker. What follows is a plain description of what this machine actually records.

The short version. The website keeps ordinary web-server logs for fourteen days, and those logs contain search terms. The MCP connector does not log your research at all. Nothing here is sold, and nothing is shared with anyone but me.

What the web server records

Every request to syfert.com is written to an Apache access log: your IP address, the date and time, the URL you asked for including its query string, the page that referred you, and your browser's user-agent string. Search on this site happens through the URL, so your search terms are in that log — a search arrives as ?q=... and is stored exactly as you typed it. The logs rotate daily and the fifteenth day's copy is deleted, so nothing survives past fourteen days. I read them for traffic, breakage and scraping, not for people.

Cookies, storage, and analytics

There is no advertising network, no retargeting pixel, and no third-party tracker other than the two named above.

Diagnostic logs

Two internal logs can capture query text: a slow-query log, which records the URL and the SQL of any database query that takes more than three seconds, and a search-fallback log. They exist so I can find the queries that break things. Website searches can land in them. Queries that arrive through the MCP are redacted from them.

The error-report button

The ? control in the top bar sends me a report about a page. It stores what you typed, the page you were on, your IP address, your browser string, and the basic browser diagnostics the panel shows you before you send, in a database kept outside the web root, and mails a copy to me. Those reports are not deleted on a schedule. Ask and I will delete yours.

Brief Check

A brief you paste or upload is read inside a sandbox, checked, and thrown away the moment the request finishes. It is not logged and not stored. One narrow exception, unchanged from the site terms: if the checker breaks in a way I cannot reproduce, I may hold a copy for up to thirty days to find out why. That is an emergency power, not a filing cabinet.

The MCP research connector

When your AI calls mcp.syfert.com, this server logs the tool name, how long the call took, whether it succeeded or failed, your subscriber handle, and your IP address. The content of your research — your queries, the citations you check, the documents you read — is not logged by the MCP, and it is redacted from the search backend's diagnostic logs. Those operational records are kept for about twelve weeks and then deleted. A running account of a lawyer's research is a dangerous thing for anyone to hold, so this machine does not hold one.

Signing up for MCP access

Activation stores the email address you type, the IP address you typed it from, and the browser details your browser volunteers, so that I know whose token is whose and can stop abuse. Your address is kept as long as your token is live. It is used to send you your access URL and, rarely, to tell you something about the service. It is not added to a marketing list, because there is no marketing list.

Signing in with Google or Microsoft

You can sign in to Syfert Legal Research with a Google account or a Microsoft account instead of an emailed link. When you do, the provider sends this site three things and nothing more: your email address, your name, and a numeric account identifier (Google may also send a profile-picture URL, which is discarded). That is the whole of the openid, email and profile scopes the sign-in requests. The site does not ask for, and cannot reach, your mail, contacts, calendar, files, or anything else in that account.

The email address and name are used for one purpose: to identify your account so that the same person is recognised on the website, in the MCP connector, and on the billing page. They are stored in an account record on this server together with the profile you fill in (firm, states of practice, and an optional bar number), and the sign-in creates a session cookie named syf_session on syfert.com. The provider's tokens are used once to complete the sign-in and are not stored.

Google and Microsoft account data is not shared with anyone, not sold, not used for advertising, and not used to train anything. It is kept until you delete your account, which you can do from your account page or by emailing [email protected]; deletion removes the account record, the profile, and any sessions within seven days. Billing records held by Stripe are kept as long as the law requires. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Blocking and geography

Requests from outside the countries this site serves are refused, and the refusal is recorded with the country code and the IP address. The scraper detector records events only — a user-agent fingerprint or a network range that triggered a block, never a path, never a query, never an individual reader's browsing.

What I do not do

I do not sell anything here, share it with partners, or build advertising profiles. Nobody sees any of it but me, except where a court leaves me no choice — and by the time anyone asks, most of it no longer exists.

Deleting your data, and questions

Email [email protected] and say what you want removed — your MCP token and email address, an error report, whatever it is. I will remove it and tell you it is done. Server logs age out on their own inside fourteen days.

Children

This is a research tool for lawyers and people handling their own cases. It is not directed at children under 13 and I do not knowingly collect anything from them.

Changes

If this policy changes in a way that matters, the effective date at the top changes with it, and MCP subscribers get an email about it.