Short version: you can read the whole site without an account, an account holds your email and what you chose to watch, and your source code stays on your machine. The long version is below, because rules require it to be written down.
Anonymous usage statistics through Google Analytics: which pages are opened, roughly where from, which browser. This is aggregated — it says "forty people opened the catalogue today", not who they were.
Standard server logs: address, time, requested page, browser string. They are how we notice that a search engine crawls us or that something returns an error. Logs rotate and are not used for anything else.
Reading the catalogue needs no account and no email. Everything below applies only if you make one.
We store your email address, and — if you signed in with GitHub or Google — the login name they hand us. Nothing else about you comes from them: no repositories, no contacts, no profile.
There is no password to lose: sign-in is GitHub, Google, or a one-time link sent to your email.
Your IP address is not stored against your account. The session row keeps the browser string and nothing else — enough to tell a phone from a work machine, not enough to identify anyone.
We also store what you did here: the servers you watch, where you want alerts delivered, your policy, your API keys. Keys are stored hashed — we can show you the last four characters and nothing more.
Delete the account and all of it goes with it. Write to [email protected] and it is done the same day.
Payments run through Lemon Squeezy, who are the merchant of record. Card details are entered on their side and we never see them — we receive the fact that a subscription started, changed or ended.
What we keep is the plan, the dates and their subscription number. Enough to know what you are entitled to, and nothing that could be used to charge you.
Our agent reads your repository on your machine. Nothing is uploaded for scanning: the rules ship inside the binary and it works with no network at all.
If you run it with --report, what leaves your machine is the finding — rule, severity, file, line — so the same list appears in your dashboard. No file contents, no source.
Add --snippets and the offending line is stored with the finding, because a finding without it can be hard to read. It is off unless you ask for it, and it is dropped after 90 days while the finding stays.
Secrets are the exception with no switch: when a rule fires on a live key, token or password, the agent sends a fingerprint of it, never the value — and the value is rejected on our side even if some other client tries to send one. A leaked key must not become leaked twice.
Analytics sets its own cookies to tell a returning visitor from a new one. They carry no personal data.
One more is ours and holds a single thing: whether you switched the site to the light theme. It never leaves your browser.
Any of them can be blocked in browser settings — the site works fine without them. Analytics can also be opted out of with Google's own browser add-on.
There are no ads on the site today. If they appear, this page will say so before they do, and the security section will stay free of them: a page judging whether a server is safe cannot carry a paid block next to that judgement.
We fetch data from public sources: the official MCP registry, npm, PyPI and GitHub. We do not send them anything about you.
Everything the site publishes about servers and skills is public information plus our own measurements. If you are an author and a number about your project looks wrong, write to us — the correction takes one check.
If this policy changes, the date above changes with it. There is no mailing list to notify, by design.