Privacy Policy
Last updated: August 9, 2026.
Local-first processing
MCP Config Doctor is a static website. All config diagnosis, generation, and fixing run entirely in your web browser. Your config text, error logs, environment variables, and any tokens inside them are never uploaded to our servers and are never included in any analytics event.
Product analytics (PostHog EU, cookieless)
When (and only when) the site is built with a valid PostHog EU configuration, the homepage tool sends a small number of custom product events to PostHog's EU cloud (eu.i.posthog.com, hosted in the EU) so we can tell whether the tool works for users. The SDK loads lazily on the first qualifying action and runs in cookieless mode. If the analytics configuration is absent or points anywhere else, analytics is disabled entirely: no SDK is loaded and no analytics request is made.
These events carry only derived metadata, never your data:
- Which client you selected (e.g.
cursor) and which operating system (Windows/macOS/Linux). - How the config entered the tool (typed/pasted, file, or built-in example).
- The IDs of the diagnostic rules that fired (e.g.
syntax.trailing-comma) and the counts of errors and warnings. - Whether a deterministic fix was available, and whether a fix or generated config was copied/downloaded.
A final filter on every outgoing event removes all automatically attached properties (page URL, path, referrer, query parameters, advertising click IDs, device/screen details) before anything is sent.
What the analytics never include
- The contents of your MCP config, error logs, server names, commands, arguments, URLs, file names, or env/header keys and values.
- Session replay, autocapture, heatmaps, pageview/pageleave tracking, exception capture, surveys, or feature flags — all disabled.
- User-provided identity of any kind: we make no identify calls, send no account or email data, and create no person profiles.
- Cookies, localStorage, or sessionStorage identifiers: analytics runs in cookieless mode with in-memory-only persistence.
In cookieless mode, PostHog computes a privacy-preserving hash on its servers to group events, instead of storing any identifier in your browser. Per PostHog's documentation, in this mode the client IP address is stripped before PostHog's server-side transformations run, so GeoIP enrichment is not applied to these events. We do not operate those servers and do not receive your IP address ourselves.
Hosting analytics (Cloudflare Web Analytics)
The site is hosted on Cloudflare, which provides privacy-friendly, cookieless web analytics (aggregate page views and performance metrics) as part of hosting. Cloudflare Web Analytics does not use client-side state such as cookies for tracking and does not receive your config data, because that data never leaves your device.
Advertising
The site does not display ads and includes no advertising trackers.
Browser storage
The tool does not use localStorage, sessionStorage, or cookies to store your config data, and the analytics SDK is configured to persist nothing. Everything you type into the tool disappears when you close or refresh the page.
Data retention
Your config and log data never reach us, so there is nothing for us to retain. The limited analytics events described above are stored by PostHog EU according to our project settings; they contain only the derived metadata listed above — we do not send user-provided identity, account, config, or log data in them.
Children's privacy
This tool is not directed at children under 13, and we do not knowingly collect information from children.
Changes to this policy
We may update this privacy policy from time to time. Continued use of the site after changes constitutes acceptance of the updated policy.
Contact
For privacy questions, contact us through this website.