Last updated: September 3, 2026
The short version
The log data you paste or upload into TrustMCP is processed entirely in your own browser. The raw content is never sent to, or stored on, any TrustMCP server — we don't see it, and we can't hand it over to anyone, because we never have it. If you're logged in, we store a small summary of each check (like category counts or a checked URL) so you can view your own history — never the underlying log lines.
What we do collect
- Payment and billing information — if you subscribe to TrustMCP Pro, this is collected and processed directly by Stripe, our payment processor. We never see or store your card details. Stripe may retain your email address and billing history per their own privacy policy.
- A local access token — after a successful payment, a small signed token is stored in your browser's local storage to remember that you've unlocked Pro. This token identifies your subscription status only; it contains no log data and isn't accessible to us in any readable form.
- Account and history data, only if you log in — logging in is entirely optional. If you choose to, we store your email (via our authentication provider) and a summary of each check you run while logged in — for a log, that's the line count and category counts (e.g. "3 verified MCP, 1 scraper"); for a URL check, that's the URL and whether differentiation was detected. We never store the raw log lines themselves. This history is visible only to you and can be viewed from the "History" link once logged in.
- Standard server logs — like virtually every website, our hosting provider (Netlify) automatically logs basic request metadata (IP address, timestamp, requested page) for security and operational purposes. We don't use this for tracking or analytics.
- Abuse protection for URL checks — the live URL checker makes requests from our servers, so to stop it being abused we record a one-way salted hash of the requesting IP address (never the IP itself) with a timestamp. These records are automatically deleted after two hours and are used only to enforce rate limits.
- Aggregate site analytics — we use DataFast, a privacy-focused analytics tool, to see basic traffic patterns like page views and referrers across the site. It's designed not to rely on tracking cookies. See DataFast's own privacy policy for details on how it operates.
What we don't do
- We don't use cookies for advertising, and don't run any advertising scripts.
- We don't store, log, or transmit the access-log content you paste or upload — logged in or not.
- We don't sell or share any data with third parties beyond what's needed to process payment (Stripe), host the site (Netlify), and run authentication/history storage (Supabase) for logged-in users.
A note on the logs you paste
Server access logs often contain IP addresses and other data about your own site's visitors — which may itself be personal data under regulations like GDPR or CCPA, depending on your jurisdiction. Because TrustMCP processes this data only in your browser and never transmits it anywhere, using TrustMCP does not, by itself, involve TrustMCP as a data processor for that visitor data. You remain responsible for how you handle and store your own logs.
Your rights
Since we don't hold your raw log data, there's nothing for you to request deletion of on that front. If you've logged in and want your account and check-history summaries deleted, email hello@trust-mcp.com and we'll remove them. For billing/subscription data, you can request access, correction, or deletion by contacting Stripe directly or by emailing us at the same address.
Changes to this policy
If this policy changes — for example, if we introduce optional server-side log storage in a future version — we'll update this page and the "last updated" date above, and clearly flag any change that affects how log data is handled.
Contact
Questions about this policy? Email hello@trust-mcp.com.