Privacy Policy
Draft — last updated 8 August 2026
This is a working draft, written directly from the decisions in our own build docs. It has not had a legal review pass yet — see /05-REPORT-DISCLOSURE-POLICY.md §10. Don't treat it as final; in particular the GDPR lawful-basis language needs a lawyer's sign-off.
What we collect
- The target URL or hostname you submit for validation
- A hashed (not raw) form of your source IP, for rate-limit and abuse checks
- Your email, only if you verify origin ownership, dispute a finding, or request a private run
What we scrub before we ever store anything
Every probe transcript is scrubbed at ingest — before storage, not after — removing authorization headers, cookies, API keys, and other credential-shaped values. We never store a raw, unscrubbed transcript.
How long we keep it
- Public report findings: while public, deleted on request
- Full scrubbed transcript: 30 days, then deleted
- Redacted/unlisted reports: 12 months, then deleted
- Probe/abuse logs: 90 days
- Aggregate, de-identified statistics: indefinite
Cookies
We use Plausible for analytics, which doesn't use cookies or track you across sites. That's why this site doesn't show a cookie banner.
Your rights
You can request deletion of a report's evidence at any time — no account required — or email abuse@createmcps.com for anything else, including a data access request.
Contact
abuse@createmcps.com. A formal Data Processing Agreement is available on request.