Capability

Privacy Policy

Effective August 19, 2026

What the public service receives

The public Capability MCP endpoint does not require a Capability account. When an AI client calls it, the service receives the tool arguments sent by that client, including the requested intent and any optional input supplied for an ability. Normal HTTP and hosting metadata may also be processed for security, reliability, abuse prevention, and operational troubleshooting.

How requests are used

Request data is used to resolve the requested ability, return results or capability metadata, enforce execution policy, diagnose failures, and protect the service. Capability may query public software registries, public repositories, or other public discovery sources when resolving an ability.

Credentials and sensitive information

The unauthenticated public endpoint is intentionally not a credential vault and does not grant secret-bearing or opaque external authority automatically. Do not place passwords, API keys, private tokens, regulated data, or other highly sensitive information in public-endpoint requests.

Third parties

The service is hosted using third-party infrastructure, including Vercel, and may interact with public software ecosystems as part of capability discovery. Those providers process information under their own terms and privacy practices. Future authenticated provider connections will be documented separately before they are enabled for users.

Sale of personal data

Sithix does not sell personal information submitted to the Capability public MCP service.

Retention and security

Operational data may be retained by the application or hosting infrastructure for the time reasonably necessary to operate, secure, debug, and improve the service, subject to applicable provider settings and legal requirements. No internet-facing service can guarantee absolute security.

Contact

Questions or privacy requests can be submitted through the Sithix contact page at sithix.com/contact.