url2md-testnet · privacy
What url2md-testnet keeps
The page you convert is never stored. The fact that you asked for it is kept for a while. If you sign in to the hosted connector, the only thing kept about you is your numeric GitHub id.
The service
The Markdown is never stored: it is converted, returned, and no copy is written anywhere. What is kept is the request itself. The URL you asked for, your IP and your User-Agent stay in Cloudflare's request logs for 7 days. Every paid call also writes a ledger row — the URL, your payer address, the payment's nonce and transaction, the client name and User-Agent your request sent, and what the call returned — and that row is kept indefinitely, because it is the record of what you were charged and the thing the ledger is reconciled against on-chain. Payments are on a public blockchain, so payer, amount and transaction are public and permanent regardless. A signed-in call through the hosted MCP connector writes a row too — the URL, your account id and the outcome, at $0 — kept for 90 days. If a URL is itself a secret, that is worth knowing before you send it.
The hosted MCP connector
The hosted connector at https://url2md-testnet.url2md.workers.dev/mcp is used through a client such as claude.ai, signed in with GitHub.
- Signing in. url2md asks GitHub for no scope. It reads your numeric GitHub id once, with a token it uses for that one request and never stores, and keeps nothing else from GitHub: no email, no username, no repositories. The id is the key to your allowance and is written on each of your $0 rows, which are kept 90 days.
- What a sign-in leaves behind. A registration for the client you used (90 days), the grant it holds with its refresh token (30 days) and an access token (1 hour). The keys that count your allowance (31 days, one per call, for a 30-day window). And, while you are on the consent page, one cookie (
__Host-url2md_oauth, HttpOnly, 10 minutes) that carries the sign-in state and nothing about you. - Leaving. Remove the connector in your client and its token is revoked. A grant nobody uses expires on its own. To have your rows removed sooner, write to hello@url2md.io with the GitHub id.
Who else sees what
- Cloudflare runs the service and keeps its request logs, as described above.
- GitHub sees that you signed in to url2md, under GitHub's own terms.
- The x402 facilitator and the Base blockchain, for paid HTTP calls only: a payment is public and permanent, as described above. The hosted connector never makes one.
No tracking
No analytics, no advertising, no third-party scripts. The consent cookie above is the only cookie this service sets, and the landing page sets none.
Contact
hello@url2md.io for anything about your data, product or security. This page is the current statement. The same retention sentence is published by the service itself at GET / and in llms.txt.