Privacy
Terradev.cloud
Last updated: September 7, 2026
1. What we collect, and why
We run a small, first-party analytics system to understand how people find and use this website — which pages are read, which referrers send traffic, whether visitors copy the MCP server URL, and whether those visits lead to signups. It exists to help us spend effort on the documentation and onboarding paths that actually work.
This system measures our own website only. It is not an advertising network, it does not follow you to other sites, and it does not build profiles for sale.
2. No cookies, no client-side storage
The analytics beacon does not set cookies and does not use localStorage, sessionStorage, IndexedDB, cache storage, or any other client-side persistence. Nothing is written to or read from your device. When you leave the site, the beacon leaves nothing behind.
3. What the beacon sends
A ~1 KB script records page views, scroll depth, engaged time on page, and clicks on a small, enumerated set of elements (documentation links, the MCP URL copy button, signup prompts). It also records the referrer hostname, coarse viewport size, browser language, and UTM parameters when present. It never records form field contents, keystrokes, or the text you select.
Requests to the site are also recorded in our web server's access logs (path, timestamp, user agent, referrer) as is standard for operating any website.
4. Pseudonymous identity by keyed hashing
To connect a page view to a later MCP connection or signup without cookies, we derive a visitor identifier using HMAC (keyed hashing). A server-side secret keys the hash, so the identifier cannot be computed by anyone else and cannot be reversed to recover its inputs. The secret is rotated periodically; each rotation makes all previously issued identifiers unlinkable going forward.
We never store raw API keys, authorization headers, or credential values in analytics data.
5. Global Privacy Control
The beacon checks the Global Privacy Control (GPC) signal (navigator.globalPrivacyControl) and exits before sending anything when it is set. GPC requests are also flagged server-side and excluded from analytics processing.
6. Retention
Raw analytics events are retained for 90 days. Session-level aggregates are retained for 13 months. Daily per-page and per-channel aggregate counts are kept indefinitely; they contain no visitor identifiers.
7. No third-party sharing
Analytics data never leaves our own infrastructure. There are no third-party analytics vendors, no tag managers, and no data sharing, sale, or disclosure of analytics data to anyone.
Payment information is handled by Stripe under its own privacy policy when you subscribe to a paid tier; we never see or store card numbers.
8. Questions
Questions about this policy can be raised via a GitHub issue.
Terradev.cloud is operated as a sole proprietorship based in Toronto, Ontario, Canada.
