Privacy by default
The default scan is designed to stay local and static. This page explains the boundary between local scanning, the public website, and the commercial flow.
What the default scan does not do
The default Lite scan does not need an MCP Preflight account and does not require connecting to the MCP server as part of the scan path. It reviews local setup material on disk before first trust.
What the website touches
The website is a public brochure and documentation surface. Standard web hosting, checkout, and marketplace surfaces may log normal request data. That is separate from the default local scan model.
What changes if you buy Pro
Pro adds a payment event and a local license-token workflow. The buying flow should be understandable before checkout, with public terms, refunds, support, and security pages.
Boundary statement
MCP Preflight is strongest as a local preflight review tool. Do not treat it as a promise that no data ever leaves your environment through unrelated marketplaces, checkout providers, or tooling you choose to install.