Privacy Policy
elixirmcp.dev is operated by Noizu Labs. It documents the open-source Elixir MCP library
(hex package noizu_mcp) and hosts a public demo MCP server at
mcp.elixirmcp.dev. This page describes what data the site and the demo
process, where it is held, and for how long. Contact:
[email protected].
Reading the site
Reading elixirmcp.dev requires no account and no sign-in. The site has no database and does not store visitor profiles.
Signing in to the demo
Sign-in is requested only when you authorize an MCP client (or mcp-mount)
to use the hosted demo. You choose GitHub or Google. No password is collected by this site.
-
GitHub — requested scope
read:user. The demo reads your numeric GitHub account ID from the GitHub user API and keeps only that ID. -
Google — requested scopes
openid email profile. The demo verifies Google's signed ID token and keeps only the account subject identifier (sub). Your email address, name and profile picture are returned by Google during sign-in but are not stored, displayed or used.
The access token issued by GitHub or Google is used once, to fetch your account identifier, and is then discarded. It is not stored and is not used to call any other GitHub or Google API.
The retained identity is the pair (provider, account ID). It is used only to bind the demo authorization to the browser session that completed sign-in. It is placed in:
- the site's signed session cookie (see Cookies below), and
-
the claims of the signed OAuth access tokens issued to your MCP client
(
identity_provider,provider_subject).
Each authorization is assigned a separate random subject identifier; the demo does not link one authorization to another and does not build a history per account.
Demo sandbox data
Each authorization receives an isolated sandbox of dummy files, a writable
/workspace directory and virtual /dev control files. The sandbox
contains only demo data. No real filesystem, repository or production database is
connected to it. Anything you write into the sandbox is held in server memory, limited
to 64 KiB per session, and is visible only to tokens issued for that authorization.
Do not write personal or confidential information into the sandbox.
Where data is held and for how long
All demo state — OAuth clients, authorization grants, tokens, login state and sandbox files — is held in memory in a single server process. There is no database and nothing is written to disk. A restart or redeploy of the service erases all of it.
- Provider sign-in state: expires after 5 minutes.
- Authorization codes: expire after 60 seconds.
- Access tokens: expire after 15 minutes.
- Refresh tokens and their token family: expire after 1 hour.
- Registered MCP clients and consent records: expire 1 hour after creation and are removed by a sweep that runs every minute.
- Sandbox files: removed when the authorization's token expires.
You can end an authorization early by revoking its token through the demo's OAuth
revocation endpoint (/oauth/revoke) from your MCP client, and you can
remove the demo's access to your provider account at any time in your GitHub
(Settings → Applications) or Google (Account → Security → Third-party connections)
settings.
Cookies
The site sets one first-party cookie, _elixirmcp_dev_key. It is HttpOnly,
SameSite=Lax, and has no expiry date, so the browser discards it when the browsing
session ends. It is signed but not encrypted. It contains random CSRF and session
identifiers used by the web framework and, during demo sign-in, the authorization
state and the (provider, account ID) pair described above. It is not used for
advertising or cross-site tracking.
The site does not currently load analytics. The site code can load Google Analytics 4 when a measurement ID is configured; none is configured. If analytics is enabled, this page will be updated first to describe the additional cookies and data it involves.
Third parties
- GitHub and Google process your sign-in under their own privacy policies when you choose them as the sign-in provider.
-
Google Fonts — pages load fonts from
fonts.googleapis.comandfonts.gstatic.com, so your browser sends a request (including your IP address and user agent) to Google when a page loads.
Noizu Labs does not sell, rent or share personal data with anyone else, and does not use it for advertising.
Server logs
The application does not log sign-in identities or sandbox contents. As with any web service, the hosting infrastructure in front of the application may record standard request metadata (such as IP address, request path, status code, user agent and time) in operational logs used for security and troubleshooting.
Your choices and deletion requests
Because demo data is held only in memory and expires within about an hour, there is normally nothing to delete after that period. To request earlier deletion, or to ask any question about this policy, email [email protected].
Children
The site and demo are developer tools and are not directed at children under 13.
Changes
Changes to this policy are published on this page with a new effective date. See also the Terms of Service.