Privacy
This site is a handful of static pages. It sets no cookies, runs no analytics or tracking scripts, embeds no third-party resources, has no accounts, and has no forms. There is nothing here that collects, stores, or shares personal information.
Server logs
Like nearly every web server, the one serving this site writes standard access logs (IP address, user agent, requested path) for operations and debugging. They are retained briefly, looked at rarely, and never sold, shared, or joined with other data.
The gem
The hitch-rails gem runs entirely inside your own Rails application and your own infrastructure. It sends no telemetry, no usage data, and no phone-home requests to this site or anywhere else. What your application does with the data that flows through its MCP endpoint is governed by your application’s privacy policy, not this one.
The gem makes exactly one kind of outbound request. When an MCP client
authorizes — at /oauth/authorize, or at
/activate in the device flow — Hitch fetches that
client’s Client ID Metadata Document from the https URL the client
presents as its own client_id. New installations have this on:
the generated initializer sets
config.client_id_metadata_enabled = true, and setting it to
false removes the gem’s only outbound request. The fetch is capped per
signed-in principal and per process, cached, never follows redirects, and is
documented in the gem’s own docs. It goes to the client’s URL,
never to this site.
If any of this changes, this page changes first.