createmcps.com

Privacy Policy

Draft — last updated 8 August 2026

This is a working draft, written directly from the decisions in our own build docs. It has not had a legal review pass yet — see /05-REPORT-DISCLOSURE-POLICY.md §10. Don't treat it as final; in particular the GDPR lawful-basis language needs a lawyer's sign-off.

What we collect

  • The target URL or hostname you submit for validation
  • A hashed (not raw) form of your source IP, for rate-limit and abuse checks
  • Your email, only if you verify origin ownership, dispute a finding, or request a private run

What we scrub before we ever store anything

Every probe transcript is scrubbed at ingest — before storage, not after — removing authorization headers, cookies, API keys, and other credential-shaped values. We never store a raw, unscrubbed transcript.

How long we keep it

  • Public report findings: while public, deleted on request
  • Full scrubbed transcript: 30 days, then deleted
  • Redacted/unlisted reports: 12 months, then deleted
  • Probe/abuse logs: 90 days
  • Aggregate, de-identified statistics: indefinite

Cookies

We use Plausible for analytics, which doesn't use cookies or track you across sites. That's why this site doesn't show a cookie banner.

Your rights

You can request deletion of a report's evidence at any time — no account required — or email abuse@createmcps.com for anything else, including a data access request.

Contact

abuse@createmcps.com. A formal Data Processing Agreement is available on request.