Privacy

Last updated 29 July 2026

The short version: we don't have accounts, we don't set cookies, we don't store your IP address, and we don't sell anything about you.

No cookies. No cross-site tracking. No ad networks. The site loads nothing from any third party — the content security policy is default-src 'self', so fonts, scripts and styles are all served from tashan.sh.

What we measure about capabilities

Everything the Index publishes comes from public sources: the MCP registry, npm, and public GitHub repositories and configuration files. We do not read private repositories, and we instrument nothing on your machine.

What we record about visits

We keep first-party, aggregate analytics so we can tell which pages are worth writing. Each event records the page path, the referring host (not the full URL), a coarse viewport size, a country code derived at the edge, and an in-memory session id that lasts only for the visit. No IP address is stored, no cookie is set, and no profile is built.

Billing data

Payments are processed by Polar, the merchant of record. Card details never reach us — we cannot see them. Polar tells us your email address and subscription status so we can grant and revoke access; that is all we store, and we store it keyed to your email in order to serve your licence. Licence keys are never written to our logs or caches in plain form — only a one-way hash is cached, briefly, to check validity. See Polar's privacy policy.

Your data

Ask us to export or delete what we hold about you and we will, within 30 days. Because we hold almost nothing, this is usually one email address and a subscription status. Deleting it ends the subscription's access. hello@tashan.sh.

Being measured

If you maintain a capability we list and something is wrong, tell us and we will correct it. We will not remove an accurate, publicly-derived measurement on request — that is what makes the Index worth reading — but we will always fix an error and show the evidence. Corrections and requests.