Information we collect
We collect information that you provide and information created when you use Sourced.
- Account information. This can include your name, email address, authentication identifiers, organization, and team membership. Clerk provides account authentication.
- Project content. This can include OpenAPI specifications, generator configuration, repository metadata, uploaded source files, generated SDKs, documentation previews, reports, and release approvals.
- Hosted MCP configuration. If you use managed MCP hosting, we store the selected tool definitions, endpoint configuration, and an encrypted upstream API credential when your API requires one. Sourced stores only a hash of the MCP endpoint access token.
- Connected-service information. If you connect GitHub or approve a registry action, we receive the identifiers and permissions needed to perform the action you requested.
- Billing information. Stripe processes payment-card details. Sourced receives billing status, plan, customer and subscription identifiers, and transaction metadata. Sourced does not receive your complete card number.
- Support information. We receive the messages and contact details you send when you ask for help or contact the Sourced team.
- Technical and usage information. This can include IP address, device and browser details, page paths, referrers, interactions, errors, performance data, and session recordings.
How we use information
We use information to provide and secure Sourced, generate the outputs you request, operate review and release workflows, process billing, answer support requests, diagnose errors, prevent abuse, and improve the product.
Sourced does not publish to a connected repository, package registry, or production documentation domain until an authorized user starts or approves that external action.
When you call a hosted MCP tool, Sourced sends the requested operation and arguments to the upstream API in your project configuration. Safe read tools are enabled by default. Workspace users control which generated tools the endpoint exposes.
Analytics and session replay
Sourced uses PostHog to measure product use, diagnose errors, and understand where users have difficulty. PostHog can use cookies and local storage and can record page interactions, browser console output, network diagnostics, and session replays.
We configure analytics to block password, payment-card, file-upload, token, secret, and API-key fields. You should not enter secrets into ordinary text fields. You can block analytics with browser privacy controls or an appropriate content blocker.
Retention and deletion
We keep account and project information while your account is active and as needed to provide Sourced, meet legal obligations, resolve disputes, and enforce agreements. Generated artifacts can have plan-specific or run-specific expiration dates. Logs and backups can remain for a limited period after account or project data is removed.
To request account or project deletion, email founder@sourced.sh. We can retain information when the law requires it or when it is needed for security, fraud prevention, billing records, or legal claims.
Security
We use access controls, private artifact storage, transport encryption, secret filtering, and approval gates intended to protect information. No online service can guarantee complete security.
Your choices and rights
You can request access to, correction of, or deletion of personal information associated with your account. You can also ask questions about how we process your information. We can require reasonable verification before completing a request.
Email founder@sourced.sh to make a request.
International processing
Sourced and its service providers can process information in the United States and other countries. Privacy laws in those locations can differ from the laws where you live.
Children
Sourced is a business and developer service. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Policy changes
We can update this policy when the product, providers, or legal requirements change. We will update the date at the top of this page when we make a change.
Contact
For privacy questions or requests, email the Sourced team at founder@sourced.sh.