Privacy Policy
Last updated: October 9, 2026
PublicWWW (publicwww.com) is a search engine for the source code of web pages. This policy
explains what we learn about you when you use the website, the API, the MCP server and the
apps you connect to your account, and what you can do about it. Questions:
support@publicwww.com.
What we collect
- Your account: your email address, your plan and how long it is paid for. Accounts
created before sign-in by email code also have a password, stored only as a salted hash.
- Your searches: the queries you run on the website, through the API and through the MCP
server, with the time, the IP address and the browser or client name. They count your daily
quota and let you page through results.
- Tokens and connected apps: API tokens you create and the apps you connect with OAuth
(for example an AI assistant) - the app's name, its address and when the token was last used.
- Payments: what you bought and when. Card payments are handled by our payment reseller;
we never see your card number.
- Server logs: IP address, requested address, browser name and referring page, as every
web server records them.
- Cookies: a sign-in cookie that lasts up to 100 days, and your recent activity kept on your
own device for up to a week. No advertising or third-party analytics cookies - see the
Terms.
AI assistants and the MCP server
When you connect an assistant such as Claude or ChatGPT, it sends us only what its tool calls
contain: the search query, the number of rows and pages, whether to include snippets, and your
token. We do not receive your conversation, your prompts, your files or anything else the
assistant knows. Disconnect an app at any time on your profile page, under
API / MCP; its token stops working at once.
How we use it
To run the service: sign you in, run your searches, apply the limits of your plan, take
payments, answer support requests, and protect the site from abuse and automated scraping. We
also count searches and visits in aggregate to see how the service is used. We do not sell your
data and do not use it for advertising.
Who else sees it
Only those who help us run the service, for that purpose alone: our hosting providers, and the
payment reseller for card payments. We may also disclose information when the law requires it,
to collect a debt, or with your permission.
How long we keep it
- Server logs - 180 days.
- Your account, tokens, connected apps and search history - while the account exists.
- Payment records - as long as accounting and tax rules require, also after the account is
deleted.
Your choices
- Delete tokens and disconnect apps on the API / MCP page of your profile.
- Delete your account on your profile page. This removes your sessions, tokens, connected apps,
clusters, messages and search history, and replaces your email address with a placeholder.
Payment records stay, as above.
- Ask us what we hold about you, or to correct it: support@publicwww.com.
Security
Everything travels over HTTPS. A new API token is shown to you once and is never sent by
email.
Changes
When this policy changes, the date at the top changes too.