Privacy Policy

Last updated: October 9, 2026

PublicWWW (publicwww.com) is a search engine for the source code of web pages. This policy explains what we learn about you when you use the website, the API, the MCP server and the apps you connect to your account, and what you can do about it. Questions: support@publicwww.com.

What we collect

  • Your account: your email address, your plan and how long it is paid for. Accounts created before sign-in by email code also have a password, stored only as a salted hash.
  • Your searches: the queries you run on the website, through the API and through the MCP server, with the time, the IP address and the browser or client name. They count your daily quota and let you page through results.
  • Tokens and connected apps: API tokens you create and the apps you connect with OAuth (for example an AI assistant) - the app's name, its address and when the token was last used.
  • Payments: what you bought and when. Card payments are handled by our payment reseller; we never see your card number.
  • Server logs: IP address, requested address, browser name and referring page, as every web server records them.
  • Cookies: a sign-in cookie that lasts up to 100 days, and your recent activity kept on your own device for up to a week. No advertising or third-party analytics cookies - see the Terms.

AI assistants and the MCP server

When you connect an assistant such as Claude or ChatGPT, it sends us only what its tool calls contain: the search query, the number of rows and pages, whether to include snippets, and your token. We do not receive your conversation, your prompts, your files or anything else the assistant knows. Disconnect an app at any time on your profile page, under API / MCP; its token stops working at once.

How we use it

To run the service: sign you in, run your searches, apply the limits of your plan, take payments, answer support requests, and protect the site from abuse and automated scraping. We also count searches and visits in aggregate to see how the service is used. We do not sell your data and do not use it for advertising.

Who else sees it

Only those who help us run the service, for that purpose alone: our hosting providers, and the payment reseller for card payments. We may also disclose information when the law requires it, to collect a debt, or with your permission.

How long we keep it

  • Server logs - 180 days.
  • Your account, tokens, connected apps and search history - while the account exists.
  • Payment records - as long as accounting and tax rules require, also after the account is deleted.

Your choices

  • Delete tokens and disconnect apps on the API / MCP page of your profile.
  • Delete your account on your profile page. This removes your sessions, tokens, connected apps, clusters, messages and search history, and replaces your email address with a placeholder. Payment records stay, as above.
  • Ask us what we hold about you, or to correct it: support@publicwww.com.

Security

Everything travels over HTTPS. A new API token is shown to you once and is never sent by email.

Changes

When this policy changes, the date at the top changes too.