§ P1Privacy policy
Privacy should be legible.
This policy explains what the hosted Redra website and MCP service process, what they do not retain, and the choices available to self-hosters.
Effective July 25, 20261. What Redra is
Redra provides a website and a Model Context Protocol service that searches class-action settlement records. The hosted MCP receives tool arguments from a user's AI client; it does not automatically receive the user's entire conversation or model memory.
2. Information processed
The hosted MCP processes the tool arguments that a connected client or model chooses to send. The search tool accepts keywords, a two-letter state, settlement type, claim status, proof requirement, deadline range, and result limit. Looking up a result sends its settlement identifier. Redra does not control what a client or model places inside an argument; received arguments are processed to return settlement results.
The hosting layer may process ordinary operational metadata such as an IP address, timestamp, request path, response status, and user agent. For the hosted MCP, Redra stores each network-source IP address with a cumulative count of MCP work units for aggregate usage measurement; items in a batch count individually. That address may belong to shared ChatGPT, Claude, or other provider infrastructure and is not treated as a Redra user identity or per-user quota. Search terms and MCP tool arguments are not stored with that counter.
The Redra website uses Google Analytics to understand page traffic and site usage. Google may process information such as a visitor's IP address, device and browser information, referring page, pages viewed, and analytics identifiers, and may use cookies or similar technologies. Google Analytics is not embedded in the MCP service, and MCP search terms and tool arguments are not sent to Google Analytics.
To avoid repeating identical work, the hosted MCP keeps a short-lived, bounded in-memory cache. Cache keys are per-process keyed digests, and cached values contain public settlement results rather than submitted query arguments. The cache is not a persistent submitted-data store.
3. What Redra does not retain
The Redra application does not persist prompts, profile data, model memory, or MCP tool arguments. It does not create user accounts, sell personal information, use MCP search inputs for advertising, or use search inputs to train models. Website analytics are limited to website activity and are separate from MCP search handling. The public stats endpoint contains aggregate dataset counts and timestamps only.
4. Sensitive information
Do not send names, addresses, email addresses, account or claim numbers, health details, complete transaction records, or other identifying information to Redra. Agent plugins can use private context to identify non-sensitive brands, products, services, or incidents and send only those search terms to Redra.
5. Service providers and sources
Redra is hosted on Fly.io and uses Google Analytics for website traffic measurement. Settlement information is sourced from SettleSignal under CC BY 4.0 and may link to settlement administrators, courts, government sites, or other third-party pages. Those services operate under their own privacy policies.
6. Self-hosted deployments
A self-hosted Redra operator controls its own infrastructure, logs, integrations, access policies, and retention. This policy applies only to the hosted service operated by Redra, not to independent deployments.
7. Security and retention
Redra limits the hosted data service to private authenticated networking, applies request-size and concurrency limits at the public edge, maintains a service-wide emergency traffic ceiling, and avoids application-level storage of submitted search data. Network-source usage counters are retained until removed through maintenance or in response to a valid request. No internet service can guarantee absolute security.
8. Questions and requests
For privacy questions, contact info@sacrosaunt.com. Redra does not maintain user accounts or a submitted-data store. Because network-source addresses may be shared, they cannot reliably identify an individual Redra user. Privacy requests must provide enough information for Redra to locate and validate any applicable record.
9. Changes
This policy may change as Redra evolves. Material changes will be posted here with a revised effective date before they take effect.