Effective 31 August 2026

Privacy

The public catalog does not need an account.

What sourcey processes

Public website, API, and MCP requests include ordinary network metadata such as IP address, time, path, user agent, request ID, and origin. MCP calls also contain the search terms, offer references, and company facts the caller deliberately supplies. Do not send secrets, personal health information, payment details, or facts that are not needed for the lookup.

How it is used

Request data is used to return the requested public catalog result, enforce rate limits, diagnose failures, and protect the service. sourcey does not use MCP request bodies to train a model, build an advertising profile, or alter catalog facts. The public MCP tools are read-only and do not accept applications or redeem offers.

Optional Sourcey accounts

Account sign-in is optional. Sourcey asks Google only for the OpenID scope and receives a stable issuer and account subject. Sourcey does not request your Google name, email, profile, Drive, Analytics, Search Console, or other Google data for sign-in. Google access and ID tokens are handled inside the purpose-specific login service and are not retained by Sourcey's account application.

Sourcey stores an opaque account identifier, the provider namespace and stable subject, verification and use timestamps, and a hash of each opaque browser session secret. Sign-in proves only which Sourcey account is present. It does not prove control of a company, link a Catalog Entity, grant provider API access, or authorize a payment.

Storage and retention

sourcey does not persist MCP request bodies as product records. In-memory request data ends with the request. Infrastructure and security providers may retain bounded network and error metadata for the period available under their operational settings. Public catalog revisions and provenance are retained as part of the permanent public record. A support email or public GitHub issue is retained for the life of that support or project record unless removal is required and compatible with the public evidence history.

Account identity events are retained as security and authority records. Sourcey agent keys are shown once and stored only as hashes. Commercial, claim, and submission records are retained by their own stated work and evidence lifecycles; they are not copied into the public Catalog merely because an account exists.

Sharing

Cloudflare and sourcey's hosting and network providers process requests to deliver and protect the service. sourcey does not sell request data. Following a vendor or application link leaves sourcey and is governed by that site's policy. Public GitHub corrections are visible to everyone.

Your request

For a private privacy request, email claims@sourcey.com with the subject Privacy request. Include only the information needed to find the relevant communication. Catalog corrections and service defects use the paths on support.