# Privacy

> MCP Inspect telemetry records argument paths, never argument values. Learn what is collected, what is rejected and what usage evidence cannot prove.

Privacy here is a product feature, not a compliance checkbox. The people using
this are instrumenting servers that carry other people's data, and "what exactly
does this send?" is the first question any of them asks. The answer has to be
short, checkable, and enforced.

| Recorded                                       | Never recorded                       |
| ---------------------------------------------- | ------------------------------------ |
| That `search` was called                       | What was searched for                |
| That `query` and `limit` were present          | The value of either                  |
| That it took 42 ms and succeeded               | What it returned                     |
| That the caller called itself `claude-desktop` | Who the end user was                 |
| An anonymous per-process session id            | Any stable user or device identifier |

## How it is enforced

**One chokepoint.** `summarizeArguments()` is the only function ever handed raw
arguments, and it returns field paths. It walks into nested objects —
`filters.owner` is a field a schema change can break — but not into array
elements, because `items[3].owner` is data.

**The server refuses values.** Ingest returns `400` for a payload containing
`arguments`, `input`, `output`, `result` or `content`. The SDK runs on your
machine, so trusting it would make the guarantee unverifiable.

**Paths must look like paths.** Each entry must match a property-path shape or it
is dropped, so a sentence or an address cannot arrive labelled as a "path". That
is a shape check, not a secret detector, and is not presented as one — a token
shaped exactly like an identifier is indistinguishable from a property name. The
real guarantee is the chokepoint above, which structurally cannot emit a value.

**Nothing is inferred.** No IP geolocation, no fingerprinting, no cross-server
correlation of "the same user".

## Snapshots

A surface snapshot is your server's public interface — the tool names,
descriptions and schemas every client already receives. It is stored verbatim.

An MCP surface may legitimately vary by authorization, so a snapshot taken with a
privileged credential can describe tools most callers never see. Snapshots record
the `cacheScope` of each list and warn when one was `private`, and the console
labels such a surface as authorization-scoped. **Credentials used to take a
snapshot are never stored** — they are read from the environment at capture time,
and the snapshot records only that a header was set, not its value.

## Retention

| Data              | Retention                                  |
| ----------------- | ------------------------------------------ |
| Surface snapshots | Life of the project. They are the product. |
| Invocation stream | ~90 days, then rolled up                   |
| Daily rollups     | Your plan's window. Counts only.           |
| Client records    | Name, version, first and last seen         |

Deleting a project deletes its rows and its stored documents.
