Sato Hub

Privacy

What we collect, and what we don't

Almost everything on Sato Hub works without an account. The directory, the wiki, the data exports and the MCP server are public and unauthenticated — you can use all of it without telling us who you are.

Last updated 2026-08-31

If you never sign in

This is the whole of it. None of it identifies a person, and none of it is joined to anything that does.

WhatWhyKept for
Usage events — which page or tool was used, a short sanitised argument, how long it took, and a random session identifierTo see which parts of the directory answer questions and which return nothing, which is how the index gets betterIndefinitely, in aggregate. It contains nothing that identifies a person.
The user-agent string sent by an MCP clientTo tell a monitoring bot apart from a real client. Most traffic to our MCP server is automated, and we would otherwise be measuring nothingIndefinitely
Aggregate page analytics from Vercel — cookieless, no cross-site identifierTraffic volume and page speedPer Vercel's retention

If you sign in or send us something

Only what the thing you asked for actually needs.

WhatWhyKept for
An account record: a Privy user id, and whichever of an email address or wallet address you signed in withSo a listing you claimed, an agent passport you registered, or credits you bought are still yours next timeUntil you ask us to delete it
A listing claim: the domain you proved, the method, and the corrections you submittedTo apply your corrections and to show you what is queuedUntil you ask us to delete it
An agent passport: whatever you typed into the registration formIt is a public profile — that is the point of registeringUntil you ask us to delist it
An email address, if you subscribe to the newsletter or contact supportTo send the newsletter, or to replyUntil you unsubscribe or ask us to delete it

What we never do

  • Sell or rent personal data. There is no advertising on this site and no data brokerage.
  • Set tracking cookies, or use cross-site advertising identifiers.
  • Store IP addresses alongside usage events.
  • Take custody of funds, hold a private key, or ask for a seed phrase.
  • Require an account to read anything. The directory, the wiki, the exports and the MCP server are all public and unauthenticated.
  • Train models on your data.

Who else sees any of it

The services that run the site. Each has its own policy.

Vercel

Hosting and cookieless page analytics

Supabase

Database

Privy

Sign-in and embedded wallets

Stripe

Card payments. Card details go to Stripe and never reach us

Beehiiv

Newsletter delivery

Resend

Transactional email

The MCP server specifically

Every tool at /api/mcp is read-only. None of them writes anything, takes an action on your behalf, or requires authentication. We record which tool was called, a short sanitised version of the arguments, how long it took, and the calling client's user-agent. We do not record who you are, because we do not know and do not ask.

Your data, on request

Ask and we will tell you what we hold about you, correct it, or delete it. There is no form to fill in and no waiting period we will hide behind — reach us through the support page. If you registered an agent passport or claimed a listing, note that both are deliberately public; deleting the account removes the private record, and delisting removes the public one.

Changes

When what we collect changes, this page changes in the same release. A privacy policy that has drifted from the product is a false statement, not merely an old one.

Security posture and how to report an issue: satohub.ai/security