Privacy and Data Processing
Data processed
Public directory pages do not require sign-in. Servers may process request addresses, timestamps, user agents, language preferences, and basic error data for security, caching, and quality diagnostics.
Search and AI recommendations
Directory filters read published snapshots. Natural-language input is processed only after a user submits it. Do not submit passwords, API keys, identity documents, or other sensitive information.
Public sources
Project information comes from public GitHub repositories and documentation. Only the current quality-gated public projection is published; internal queues, model runs, and governance fields remain private.
Retention and processors
Diagnostic data is retained only as operationally and security-relevant. Hosting, network, and model providers may process requests when necessary. Project-search content is not sold.
Hosted MCP inputs
The anonymous Hosted MCP receives only the fields submitted to a selected tool: project queries or identifiers, typed constraints, locale, browsing filters, and an optional caller-generated request ID. It does not receive the complete ChatGPT or Codex conversation unless the host places that text in a declared tool argument. Do not submit credentials, private source code, or confidential documents.
Hosted MCP logs and retention
The application does not create a database of MCP inputs or results. Its privacy-safe operational telemetry excludes raw queries, constraints, result payloads, credentials, cookies, and authorization headers. The public gateway processes IP addresses in memory for TLS and abuse prevention. Its dedicated access log stores only timestamp, HTTP status, total duration, and upstream duration; it omits IP address, URI/query, referrer, User-Agent, and request body. Security and error logs may contain network metadata including IP addresses. Nginx logs rotate daily and retain 14 rotations.
Hosted MCP deletion requests
For a privacy or deletion request concerning identifiable gateway log data, email zxhwolfe@gmail.com with the relevant IP address and a narrow timestamp range. Requests are processed where the record can be located, subject to security, recovery, and legal retention needs. Do not send prompt text or credentials in the request.