Legal

Privacy

Last updated 26 August 2026.

Validation of OpenRTB JSON still runs in your browser via WebAssembly. The CLI, library, and local rtblint-mcp stdio server do not send payloads. The hosted MCP endpoint at rtblint.org/mcp does store a redacted copy, as described below.

What we keep

When you paste, type, drop, or share a payload in the tester, or when an agent sends a payload to the hosted MCP server at rtblint.org/mcp, rtblint.org stores a copy of that JSON. Known device IDs, IPs, consent strings, geo coordinates, and identity ids are stripped before storage. Cloudflare also supplies the country and the network owner (ASN number and organization name, for example an ISP or a company network). We use that to see which networks send payloads. We do not store the IP address. We may keep a random session id that exists only while this browser tab is open, so payloads from the same tab can be grouped. If you arrived from another site, we may keep that site's hostname. If the tester URL has utm_source or utm_medium, those values may be kept. Built-in sample scenarios are not sent. The local rtblint-mcp stdio server does not send payloads. Payloads are used to improve validation rules and are not published.

How we use stored payloads

We may parse, cluster, and derive fixtures and rules from a submitted payload while developing and testing rtblint. We do not fetch live bid URLs found in a sample. We do not sell payloads. We do not publish submitted JSON as a public gallery.

Opt out

The tester has a Don't send my payloads control. That sets a flag in this browser only. It stops new sends from that browser. It does not recall payloads already stored. It does not apply to the hosted MCP server. To keep payloads off the network, use the local rtblint-mcp stdio server or the CLI.

Analytics

The public site may use Cloudflare Web Analytics for page traffic. That is separate from payload storage.