Privacy policy
How WebMCP Workbench processes information when you check websites, build tools, and use your account.
Do not include passwords, access tokens, private document links, or personal information in website URLs or tool inputs.
Website checks
The checker sends your submitted URL to our service and retrieves HTML, scripts, and permitted resources from the website and allowed redirect destinations. It processes tool definitions, schemas, registration evidence, timestamps, and coverage findings. Target websites receive our service’s connection information and may keep their own logs.
A fresh Chromium session runs website JavaScript to observe registered tools. It does not inherit your browser login, submit forms, or execute tools during a check. Requests are restricted by public-address validation, byte limits, concurrency limits, and deadlines. These controls do not guarantee complete coverage or security.
The latest 10 check summaries are stored in your browser, including URLs, times, outcomes, and tool counts. Clear history removes these local summaries. They do not sync across devices. Retrieved checker content and full results are held temporarily during processing and display. Our server also stores submitted website-check and free-scan URLs (without query strings or fragments), times, activity types, and available account identifiers for administrator review.
Accounts and credits
Supabase Auth processes your email and sign-in information. Our server verifies your session and stores your account identifier, verified email, credit ledger, task reservations, and outcomes in the database. Session credentials are stored in your browser; signing out removes the local session but does not delete database records.
Credit requests store your account identifier, verified email, reason, time, and review status. Administrators can review requests, grant credits, and enable or disable accounts. Administrative changes are recorded with the administrator’s identity and timestamps. Credits are app usage units, not money. Eligible newly registered, verified accounts receive a one-time welcome credit grant while the welcome campaign is active. Campaign grants are recorded in the credit ledger.
AI recommendations and saved tools
AI recommendations are optional. They send bounded public page content, labels, field definitions, the sanitized page URL, existing tool descriptions, detected JavaScript function names and parameter names with source locations, and observed JSON response structure to OpenAI. Function bodies and literal argument values are not included in this additional JavaScript evidence. Request headers, cookies, form input values, and JSON response values are excluded. Website content may itself contain information, so only submit pages appropriate for sharing.
AI requests are stored in the operator’s OpenAI dashboard logs under OpenAI’s applicable API data policies. Successful paid AI results are saved with your account, scanned URL, recommendations, and credit charge. History shows the latest 20 saved AI scans and reopening them makes no additional AI call or charge.
Generated tool definitions and JavaScript exports are saved in the database. The recent export list displays up to 10 items. These display limits are not deletion limits. Export installation is manual and does not grant Workbench access to your hosting account.
API tests and playground
API tests send the inputs you enter to the public GET endpoint you configure, without your normal browser cookies. The live playground opens a separate backend browser and returns screenshots to your signed-in session. Browser state, inputs, results, and screenshots are held in memory for the session. Sessions close after five minutes or explicit cleanup; requests already sent cannot be recalled.
Website tools execute only when you start a test. They may contact external services, use the website’s API allowance, or change real data. Non-GET requests are blocked unless you approve a specific endpoint for one JSON POST execution. Returned HTML previews block scripts and external resources. Educational examples use fictional data and do not make real purchases.
Contact submissions
The contact form stores your name, email, subject, message, submission time, and review status in the database for administrators to review. Submissions are not emailed automatically.
Analytics and operational logs
With your permission, analytics records a browser-tab session identifier, page categories, visits, active time, scroll depth, and feature events. Signed-in activity may be associated with your account ID. Analytics does not collect typed content, submitted website URLs, passwords, messages, or screen recordings. Administrators can review usage and funnels. These signals do not directly measure satisfaction.
You can decline analytics or change your choice through Analytics preferences in the footer. Do Not Track is respected. Operational API logs contain request identifiers, route groups, methods, statuses, timing, and AI usage or failure categories; they exclude credentials and request or response bodies. Hosting, proxy, target website, and provider logs have separate handling.
Storage and your choices
Database records have no automatic deletion schedule. Signing out, clearing local history, or leaving a page does not remove database records or third-party logs. Contact us for questions about your information or deletion requests; there is no self-service account deletion interface.
The interface requests fonts from Google Fonts. External documentation and platform links follow their own privacy policies. WebMCP Workbench is independent of Google and Chrome.
Contact us about your data