Effective 4 August 2026
Privacy
The public catalog does not need an account.
What Sourcey processes
Public website, API, and MCP requests include ordinary network metadata such as IP address, time, path, user agent, request ID, and origin. MCP calls also contain the search terms, offer references, and company facts the caller deliberately supplies. Do not send secrets, personal health information, payment details, or facts that are not needed for the lookup.
How it is used
Request data is used to return the requested public catalog result, enforce rate limits, diagnose failures, and protect the service. Sourcey does not use MCP request bodies to train a model, build an advertising profile, or alter catalog facts. The public MCP tools are read-only and do not accept applications or redeem offers.
Storage and retention
Sourcey does not persist MCP request bodies as product records. In-memory request data ends with the request. Infrastructure and security providers may retain bounded network and error metadata for the period available under their operational settings. Public catalog revisions and provenance are retained as part of the permanent public record. A support email or public GitHub issue is retained for the life of that support or project record unless removal is required and compatible with the public evidence history.
Sharing
Cloudflare and Sourcey's hosting and network providers process requests to deliver and protect the service. Sourcey does not sell request data. Following a vendor or application link leaves Sourcey and is governed by that site's policy. Public GitHub corrections are visible to everyone.
Your request
For a private privacy request, email claims@sourcey.comwith the subject Privacy request. Include only the information needed to find the relevant communication. Catalog corrections and service defects use the paths onsupport.