Effective August 30, 2026

Privacy

The Community edition is local-first. The public documentation site does not provide accounts, checkout, or an application backend.

Local MCP data

Session state, context, ledgers, checkpoints, and signing keys are written beneath the local state directory selected by the operator. The package does not include a network action tool and does not send that state to Living Stack.

Website data

The static site is hosted by Cloudflare Pages. Cloudflare may process ordinary request metadata such as IP address, user agent, and timestamps for delivery and abuse prevention under its own policies. Living Stack does not add advertising trackers or analytics scripts in this beta.

Secrets

Do not send credentials to the MCP. Redaction is defense in depth, not a secret manager.

Contact

Use the repository issue tracker for non-sensitive questions and GitHub Security Advisories for suspected vulnerabilities.