Legal

Privacy Policy

MCP Pulse is local-first by design. On the free tier, nothing leaves your machine.

What we collect

On the free tier: nothing. Every JSON-RPC frame, session file, and SQLite database lives in ~/.mcp-pulse/ on your machine. No data is transmitted anywhere. On paid tiers (Starter, Team, Security, Enterprise), the following anonymous signals are synced to our Supabase database to power cross-user benchmarks: • Anonymous reliability score (0–100) • Method names observed during the session (e.g. "tools/call") — not values • Param key shapes only (e.g. { "path": "..." } becomes { "path": "string" }) • Aggregated latency p95 and p50 values • Pass / fail call counts Your actual tool call values, database query results, file contents, secrets, or any PII are never collected.

How we identify you

We never collect your name, email address, IP address, or any personally identifiable information tied to your monitoring activity. Your machine is identified by a SHA-256 hash of your machine ID combined with your project path. This hash is one-way and cannot be reversed to identify you. It exists only to deduplicate benchmark contributions across sessions.

Email (Starter tier and above)

If you configure email alerts, your email address is stored by Resend (our email delivery provider) solely to send those alerts. We do not use it for marketing. You can disable alerts at any time by removing the email from ~/.mcp-pulse/config.json. Resend's privacy policy: resend.com/privacy

License keys

Your license key is stored locally in ~/.mcp-pulse/license.json and validated against our Supabase Edge Function. The validation request includes your license key and machine hash — no other data. License keys are issued by LemonSqueezy (our payment processor). Their privacy policy: lemonsqueezy.com/privacy

Third-party services

We use the following services: • Supabase — anonymous benchmark storage (ap-southeast-1, Singapore) • Resend — email delivery for paid-tier alerts • LemonSqueezy — payment processing and license key management • Cloudflare — DNS, CDN, and badge Worker • Sentry — error tracking on our web dashboard (no CLI errors sent) No advertising networks, no analytics trackers, no session recording.

Data retention

Free tier: your local data is retained for 7 days by default, configurable in ~/.mcp-pulse/config.json. Starter: 30 days. Team: 90 days. Security: 90 days. Enterprise: 365 days. Anonymous benchmark scores in our Supabase database are retained indefinitely to maintain the public scoring standard. These cannot be tied back to you.

Your rights

Since we hold no PII, there is nothing to access, correct, or delete in relation to your personal data. If you have a paid subscription and want your account data deleted, email [email protected] and we will remove your license key and associated subscription record within 7 days.

Changes to this policy

We will update this page if our data practices change. The date below reflects the last update. Continued use of MCP Pulse after changes means you accept the revised policy. Last updated: July 1, 2026

Contact

Questions about privacy: [email protected]