Privacy

This site is a handful of static pages. It sets no cookies, runs no analytics or tracking scripts, embeds no third-party resources, has no accounts, and has no forms. There is nothing here that collects, stores, or shares personal information.

Server logs

Like nearly every web server, the one serving this site writes standard access logs (IP address, user agent, requested path) for operations and debugging. They are retained briefly, looked at rarely, and never sold, shared, or joined with other data.

The gem

The hitch-rails gem runs entirely inside your own Rails application and your own infrastructure. It sends no telemetry, no usage data, and no phone-home requests to this site or anywhere else. What your application does with the data that flows through its MCP endpoint is governed by your application’s privacy policy, not this one.

The gem makes exactly one kind of outbound request. When an MCP client authorizes — at /oauth/authorize, or at /activate in the device flow — Hitch fetches that client’s Client ID Metadata Document from the https URL the client presents as its own client_id. New installations have this on: the generated initializer sets config.client_id_metadata_enabled = true, and setting it to false removes the gem’s only outbound request. The fetch is capped per signed-in principal and per process, cached, never follows redirects, and is documented in the gem’s own docs. It goes to the client’s URL, never to this site.

If any of this changes, this page changes first.

← Back to the front page