Privacy notice.
Talandor is designed to inspect public MCP surfaces with as little personal data as possible.
Who operates the service
Talandor is operated by the legal operator identified in the Legal notice.
What the public checker processes
When you submit a check, Talandor stores the public HTTPS endpoint and the resulting technical observations so it can produce a report and compare public contracts over time. Never submit credentials, private URLs or confidential data: the public checker does not need them and never calls MCP tools.
Free account
A free account stores the email address used to sign in, a one-time link that expires after 15 minutes and works once, a session that expires 30 days after sign-in, and the public connector addresses you save, together with the assistant you selected. Saving a connector does not start monitoring. Watch is not part of the free account. Card data does not pass through Talandor.
Operational data
The hosting infrastructure may process ordinary security and access-log data such as an IP address, request time, path and browser information. This data is used to operate, protect and troubleshoot the service, not to build advertising profiles.
Watch
Watch is a future paid offer. It is not part of the free account. No subscription or alert is created from this page. If a payment exists later, the hosted checkout names the seller of record. Card data does not pass through Talandor.
What is established
- A sign-in link works once and expires after 15 minutes. A session expires 30 days after sign-in.
- A free account stores the sign-in email, the public connector addresses you save, and the assistant you selected. Saving a connector does not start monitoring.
- A public check stores the HTTPS address and the technical observations needed for the report. It does not call tools and does not ask for MCP credentials.
- Card data does not pass through this service. Watch checkout is not open, so no Watch payment is collected.
- No self-serve export or deletion control is published.
- A session expiring does not delete the account, the saved connectors, or the public observations.
- Product interaction counts are kept for 90 days. They do not include the account email.
- A unique visit for the current UTC day is a short hash of the day, the network address and the browser string. The raw address is not stored.
- Public observations are kept with no calendar limit. They are the service dataset. A report page shows a recent excerpt; that display limit is not a retention period.
- No self-serve deletion control is published yet. When it exists, deletion will be immediate. Identifying account data will be anonymized and will not stay attached to the person. Public observations stay in the dataset.
- Hosting and sign-in email are both provided by OVHcloud. No other processor is engaged. If Watch checkout opens, the seller authorized to collect payment is the one named on the legal notice. No Watch payment is collected while checkout stays closed.
Needs confirmation from the operator
These points are not yet published facts. They stay listed until the operator confirms them.
- How long access logs are kept. Access logs are the technical traces of a visit, such as an address, a time, a path and a browser. No duration has been set.
Your requests
For a privacy question, correction, export, deletion or public-endpoint opt-out, contact support@talandor.com. Do not include passwords, API keys or MCP credentials.
.