Privacy
The Community edition is local-first. The public documentation site does not provide accounts, checkout, or an application backend.
Local MCP data
Session state, context, ledgers, checkpoints, and signing keys are written beneath the local state directory selected by the operator. The package does not include a network action tool and does not send that state to Living Stack.
Website data
The static site is hosted by Cloudflare Pages. Cloudflare may process ordinary request metadata such as IP address, user agent, and timestamps for delivery and abuse prevention under its own policies. Living Stack does not add advertising trackers or analytics scripts in this beta.
Secrets
Do not send credentials to the MCP. Redaction is defense in depth, not a secret manager.
Contact
Use the repository issue tracker for non-sensitive questions and GitHub Security Advisories for suspected vulnerabilities.