---
title: "Privacy · tabnas"
description: "What the hosted tabnas MCP endpoint records, what it never records, and why running locally avoids the question entirely."
source: "https://tabnas.dev/privacy/"
---

# Privacy

This page covers the hosted MCP endpoint at `mcp.tabnas.dev` and the documentation website at `tabnas.dev`.

## The short version

The hosted MCP service processes document content in memory and does not write it to application logs or persistent storage. It records the request metadata listed here. The service does not use document content for training.

Run the MCP server locally to process documents without sending them to the hosted endpoint:

```
npx --yes @tabnas/mcp mcp
```

Local stdio processes requests on your machine. Installing the package may contact the npm registry.

## What is recorded

Shape only, per request, for keeping the service working:

-   **Tool name**: for example `parse`.
-   **A size bucket**: one of `<=1k`, `<=16k`, `<=64k`, `<=256k`. Deliberately a bucket and never a byte count: an exact document length is a weak fingerprint of the document, and this service does not hold facts about content.
-   **Duration** in milliseconds.
-   **Status and error code**: whether the tool answered yes or no, and which documented code it returned.

The service records these fields for each request. Its telemetry tests check that parsed content does not appear in an emitted record.

## What is never recorded

-   The documents, grammars, fixtures, or options you send.
-   The trees, diagnostics, or reports returned to you.
-   Any byte of request or response body, in any form.

The application does not retain request or response bodies. Cloudflare handles requests in transit as described in the next section.

## What Cloudflare sees

The endpoint runs on Cloudflare Workers, so Cloudflare operates the network path and applies its own standard protections. Being the network, it necessarily handles your request in transit and sees the connecting IP address. Per-IP rate limiting uses that address to count requests; the count is what is kept, not a log of who you are.

See [Cloudflare’s privacy policy](https://www.cloudflare.com/privacypolicy/) for its handling of network request data.

## The website

`tabnas.dev` is a static site. No analytics, no tracking pixels, no advertising, no cookies set by us. Search runs entirely in your browser.

## Changes

The website and MCP service have separate repositories. Update this page when the service’s data handling changes. Their [source repositories](https://github.com/tabnas) contain the change history.
