Privacy
Reading this website, checking a pull request, and asking an assistant to draft documentation are different data flows. This page keeps them apart.
Last updated: October 9, 2026
The website
This is a static informational site. It has no accounts, upload forms, or product backend. Images, styles, and a small clipboard script are served from the site itself; no analytics script is installed.
The site is served through Cloudflare. Like any hosting provider, Cloudflare may process IP addresses, requested URLs, timestamps, browser details, and security logs under its own privacy policy. A static site is not a promise that no request data is processed anywhere.
The site does not set its own tracking cookies. Copy buttons write the displayed installation text to your clipboard only when you press them; they never read it. Links to GitHub, npm, and other services follow those services’ policies.
Local and CI analysis
StaleDocs’ drift analysis reads repository files and Git revisions where you run it: on your machine or in your CI runner. Planning and review need no model and no StaleDocs API key.
Provider-free is not the same as offline. Installing packages contacts npm, and fetching revisions contacts your Git host. The GitHub Action runs inside GitHub Actions and posts findings, symbol signatures, documentation paths, comments, and labels to GitHub, subject to your repository settings.
This website never receives your repository data. Review the Action guide and its permissions before enabling it.
MCP and your assistant host
The local StaleDocs MCP server is pinned to the Git worktree it starts in. It returns bounded documentation context and API-change evidence to your host. Preparing and validating a draft do not write files.
Claude Code, Codex, or any other MCP host controls its own model, context, network access, history, and permissions. If your host uses a remote model, context it holds may be sent to that model provider under the host’s policies. StaleDocs never obtains your Claude subscription or turns it into an API credential.
The validation step checks prepared input and drafts for secret-like content. It is not a sandbox or a replacement for reviewing what you share. See the safe update sequence.
Direct-provider generation
Optional generation commands are separate from review. They send selected context to the model provider or endpoint you configure, under that provider’s policies and billing. Ollama is available for a local model.
Check the command, context, and provider before running generation on sensitive repositories. The security policy describes these boundaries in more detail.
Contact
Privacy questions: hello@staledocs.com. Email naturally includes your address and whatever you write.
Public GitHub issues are visible to everyone; remove credentials, private source, and personal data before posting. Report vulnerabilities through GitHub private vulnerability reporting.
No independent privacy audit is claimed. If the site’s data collection changes, for example if analytics is added, this page will be updated first.
