maisecrets / Privacy
Privacy
Last updated: 26 September 2026
The short form
The maisecrets plugin collects no data. It sends nothing to mcpgate or to anybody else. It has no telemetry, no account and no licence check.
What the plugin stores, and where
Everything stays on your machine:
- Detected values go into a local vault: the macOS login keychain, the Windows Credential Locker, or an encrypted file on Linux. Each value has a time to live. When it expires, the plugin deletes the value.
- An index in
~/.maisecrets/index.jsonholds metadata and keyed fingerprints, never a value. - An event log and an audit log in
~/.maisecrets/record which rule matched and which placeholder was resolved, never a value. - The clipboard receives the rewritten prompt when the plugin blocks a prompt.
You can read and delete all of it. python3 -m maisecrets.cli list shows the entries.
Network access
No hook of the plugin opens a network connection. The source code in the public repository is the proof: it uses only the Python standard library, and you can read every file it runs.
Reports you send
The command /maisecrets:report opens a prefilled issue on GitHub in your browser. You decide whether to send it. The report contains the rule name and the plugin version, never the detected value. GitHub processes the issue under its own privacy statement.
This website
This page is part of mcpgate.de. The website sets no cookies and runs no analytics. The privacy policy of mcpgate.de covers the server logs of the website and names the controller.
Contact
For questions about privacy, see the Impressum.