Privacy
What we collect, and what we don't
Almost everything on Sato Hub works without an account. The directory, the wiki, the data exports and the MCP server are public and unauthenticated — you can use all of it without telling us who you are.
Last updated 2026-08-31
If you never sign in
This is the whole of it. None of it identifies a person, and none of it is joined to anything that does.
| What | Why | Kept for |
|---|---|---|
| Usage events — which page or tool was used, a short sanitised argument, how long it took, and a random session identifier | To see which parts of the directory answer questions and which return nothing, which is how the index gets better | Indefinitely, in aggregate. It contains nothing that identifies a person. |
| The user-agent string sent by an MCP client | To tell a monitoring bot apart from a real client. Most traffic to our MCP server is automated, and we would otherwise be measuring nothing | Indefinitely |
| Aggregate page analytics from Vercel — cookieless, no cross-site identifier | Traffic volume and page speed | Per Vercel's retention |
If you sign in or send us something
Only what the thing you asked for actually needs.
| What | Why | Kept for |
|---|---|---|
| An account record: a Privy user id, and whichever of an email address or wallet address you signed in with | So a listing you claimed, an agent passport you registered, or credits you bought are still yours next time | Until you ask us to delete it |
| A listing claim: the domain you proved, the method, and the corrections you submitted | To apply your corrections and to show you what is queued | Until you ask us to delete it |
| An agent passport: whatever you typed into the registration form | It is a public profile — that is the point of registering | Until you ask us to delist it |
| An email address, if you subscribe to the newsletter or contact support | To send the newsletter, or to reply | Until you unsubscribe or ask us to delete it |
What we never do
- ✕Sell or rent personal data. There is no advertising on this site and no data brokerage.
- ✕Set tracking cookies, or use cross-site advertising identifiers.
- ✕Store IP addresses alongside usage events.
- ✕Take custody of funds, hold a private key, or ask for a seed phrase.
- ✕Require an account to read anything. The directory, the wiki, the exports and the MCP server are all public and unauthenticated.
- ✕Train models on your data.
Who else sees any of it
The services that run the site. Each has its own policy.
The MCP server specifically
Every tool at /api/mcp is read-only. None of them writes anything, takes an action on your behalf, or requires authentication. We record which tool was called, a short sanitised version of the arguments, how long it took, and the calling client's user-agent. We do not record who you are, because we do not know and do not ask.
Your data, on request
Ask and we will tell you what we hold about you, correct it, or delete it. There is no form to fill in and no waiting period we will hide behind — reach us through the support page. If you registered an agent passport or claimed a listing, note that both are deliberately public; deleting the account removes the private record, and delisting removes the public one.
Changes
When what we collect changes, this page changes in the same release. A privacy policy that has drifted from the product is a false statement, not merely an old one.
Security posture and how to report an issue: satohub.ai/security