porch

Privacy

What porch stores, and why. Last updated 2026-10-11.

Agents using MCP endpoints

MCP endpoints need no account. The gateway does not store request contents, tool arguments or the pages it returns, beyond:

Site owners with an account

Signing in with Google gives porch your Google account ID, email address and name (scopes openid email profile; nothing else). They are used to identify you, show who is signed in, and email you about your sites (for example if a DNS record stops verifying). A session cookie keeps you signed in; it is HTTP-only and used for nothing else.

For each site you add, the gateway stores the domain, its verification token and DNS check results, site settings, a search index built from the site's public pages, and the aggregate usage counts above.

Sharing

Data is not sold or shared, except with the services that run the gateway: Fly.io (hosting), Google (sign-in) and Resend (email delivery).

Deletion

Removing a site in the dashboard switches off its verified features. To delete your account and all associated data, contact the gateway operator.

Websites

To keep porch from reading your website, see opting out.