Porch

Privacy

What Porch stores, and why. Last updated 2026-10-11.

Agents using MCP endpoints

MCP endpoints need no account. Porch does not store request contents, tool arguments or the pages it returns, beyond:

Site owners with an account

Signing in with Google gives Porch your Google account ID, email address and name (scopes openid email profile; nothing else). They are used to identify you, show who is signed in, and email you about your sites (for example if a DNS record stops verifying). A session cookie keeps you signed in; it is HTTP-only and used for nothing else.

For each site you add, Porch stores the domain, its verification token and DNS check results, site settings, a search index built from the site's public pages, and the aggregate usage counts above.

Sharing

Data is not sold or shared, except with the services that run Porch: Fly.io (hosting), Google (sign-in) and Resend (email delivery).

Deletion

Removing a site in the dashboard switches off its verified features. To delete your account and all associated data, email contact@porch.tools.

Websites

To keep Porch from reading your website, see opting out.