CuratedMCP

Last updated 2026-07-22

Privacy Policy

This page describes what curatedmcp.com collects when you use the website, and — separately — what the CLIs (the Hub, the shadow-MCP scanner, Sentinel, TokenShield) do and don't send anywhere. This is a plain description of our actual practices, not a template.

The local-first CLIs

The Hub, the shadow-MCP scanner, Sentinel, and TokenShield are open-source (MIT) and run entirely on your machine. Reading your MCP configs, grading risk, and enforcing policy all happen locally — nothing is uploaded automatically.

The one exception is explicit: if you run the shadow-MCP scan and choose to share the report, the CLI sends a sanitized summary (server names and risk flags only — never commands, arguments, environment variables, or file paths) to generate the shareable report URL. That upload only happens for that one command; nothing else phones home.

Account sign-in

Signing in uses GitHub, Google, LinkedIn, or GitLab OAuth. We receive the name, email address, and avatar your provider shares with us — we never see your password. Account data is used to run your dashboard, publish listings, and manage team/billing state.

Billing

Payments are processed by Stripe. We store your Stripe customer ID and subscription status to run the product (e.g., unlocking Team/Control Plane features) — we don't store card numbers ourselves; that lives with Stripe.

Forms and lead capture

Whitepaper downloads, pilot applications, and similar forms collect the fields you submit (typically name, email, and company) so we can send the requested content and follow up. We don't sell this data to third parties.

Analytics and site visitors

We use Google Analytics 4 to understand traffic and which pages/CTAs work, with a server-side mirror so events aren't entirely lost to ad blockers.

We also use RB2B, a B2B visitor-identification service, which can identify the company of US-based business visitors from IP address for sales follow-up. It does not identify individual people, and it's not active for visitors outside its supported regions.

Email

Transactional and product emails (receipts, scan reports, pilot follow-ups) are sent via Resend. Every marketing email includes an unsubscribe link, and unsubscribing takes effect immediately.

Your choices

Changes to this policy

If our practices change materially, we'll update the date at the top of this page.

Questions

Email [email protected], or see security.txt for vulnerability disclosure.