Last updated 2026-07-22
Privacy Policy
This page describes what curatedmcp.com collects when you use the website, and — separately — what the CLIs (the Hub, the shadow-MCP scanner, Sentinel, TokenShield) do and don't send anywhere. This is a plain description of our actual practices, not a template.
The local-first CLIs
The Hub, the shadow-MCP scanner, Sentinel, and TokenShield are open-source (MIT) and run entirely on your machine. Reading your MCP configs, grading risk, and enforcing policy all happen locally — nothing is uploaded automatically.
The one exception is explicit: if you run the shadow-MCP scan and choose to share the report, the CLI sends a sanitized summary (server names and risk flags only — never commands, arguments, environment variables, or file paths) to generate the shareable report URL. That upload only happens for that one command; nothing else phones home.
Account sign-in
Signing in uses GitHub, Google, LinkedIn, or GitLab OAuth. We receive the name, email address, and avatar your provider shares with us — we never see your password. Account data is used to run your dashboard, publish listings, and manage team/billing state.
Billing
Payments are processed by Stripe. We store your Stripe customer ID and subscription status to run the product (e.g., unlocking Team/Control Plane features) — we don't store card numbers ourselves; that lives with Stripe.
Forms and lead capture
Whitepaper downloads, pilot applications, and similar forms collect the fields you submit (typically name, email, and company) so we can send the requested content and follow up. We don't sell this data to third parties.
Analytics and site visitors
We use Google Analytics 4 to understand traffic and which pages/CTAs work, with a server-side mirror so events aren't entirely lost to ad blockers.
We also use RB2B, a B2B visitor-identification service, which can identify the company of US-based business visitors from IP address for sales follow-up. It does not identify individual people, and it's not active for visitors outside its supported regions.
Transactional and product emails (receipts, scan reports, pilot follow-ups) are sent via Resend. Every marketing email includes an unsubscribe link, and unsubscribing takes effect immediately.
Your choices
- Delete your account and associated data by emailing us (below).
- Unsubscribe from any marketing email via the link in that email.
- Skip the account entirely — the scan, the Hub, and browsing the catalog don't require signing in.
Changes to this policy
If our practices change materially, we'll update the date at the top of this page.
Questions
Email [email protected], or see security.txt for vulnerability disclosure.