Effective 3 September 2026

Privacy

isWebMCP is a public-web analysis project. You choose what URL to audit. Do not provide private, authenticated, local-network, or secret-bearing URLs.

What is processed

When you request an audit, the service processes the submitted public URL, optional goal text, fetched public response, and the resulting report. The service retains the normalized public URL and audit outcome for product analytics. URL credentials, query strings, and fragments are removed before storage. Integrations may also process supplied tool-contract text.

Retention

Sanitized URL-attempt records are retained for 90 days in the project's managed Postgres store, then deleted during subsequent writes. Each record contains the normalized origin and path, hostname, entry surface, timestamp, outcome, response status, error code, and report ID when one was created. Malformed, credential-bearing, or locally addressed inputs are counted without retaining the submitted value. Optional goals, fetched markup, IP addresses, user agents, query strings, and fragments are not stored in this analytics table.

Interactive reports remain ephemeral and are not published to the readiness index. Vercel, Neon, and security infrastructure may process ordinary request metadata under their operational policies.

Browser and editor integrations

The Chrome extension reads the active tab URL and title only after you invoke it. It does not inject a content script or request browsing history. Editor and agent integrations send only the audit inputs you choose to the published isWebMCP endpoints.

Public index data

WRI v1 is a frozen, audited-partial research artifact built from public domains. It is uncalibrated and is not a complete 100,000-site observation or a product-quality ranking.

Questions

Use the support page for current support and disclosure channels.