Glimind is designed so that contributing data cannot leak your inputs.
us, eu)langchain, claude, ts) — never identityThe ingest endpoint hard-rejects any unexpected field or anything that resembles a raw payload; shape skeletons are validated to contain only type tags. Everything we keep is structure or metadata — designed so the dataset is valuable to the whole ecosystem yet can never leak your data. See the SDK README for the exact client-side derivation.
For requests to our own site/API we keep aggregate counts only (by traffic source, page, region, and referrer) plus a salted, one-way hash of IP + user-agent to count unique vs returning visitors. We do not store raw IP addresses, and the hash cannot be reversed to identify you. These visitor hashes are retained for at most 90 days, then deleted.
We process this structure/metadata under legitimate interests (operating and improving a neutral reliability service) with data minimisation by design — no raw payloads or PII are ever stored. You may request access to, or deletion of, any data associated with you (e.g. a reporter id or API key): email [email protected] and we act promptly. You can stop contributing at any time by uninstalling the SDK; server operators can remove a server from measurement at https://glimind.com/opt-out.
Value-free structure/metadata (shapes, error classes, aggregates, ecosystem history) is retained to keep the dataset useful over time. Anything closer to a person — visitor hashes — is capped at 90 days. We never sell personal data.
For servers we discover from public registries, we perform only the MCP initialize handshake and
tools/list. We never invoke a tool. Probes carry a descriptive User-Agent linking here, honor a
do-not-probe list, and are rate-limited. Opt out at https://glimind.com/opt-out.
Privacy questions or data requests: [email protected].