Bassethound
Privacy Policy
Last updated: July 25, 2026
Bassethound is operated by NimbleBrain, Inc. ("NimbleBrain," "we," "us"). Bassethound is a stateless remote MCP server that, given a domain name, returns a correlated intelligence dossier about that domain. This policy explains what we do, and don't do, with data when you use it.
The short version
Bassethound is stateless and read-only. It analyzes public
information about the domains you submit and returns a result. The MCP
endpoint requires you to sign in; the /sniff playground on this
site does not. We store your results against your account. We don't build user profiles, and we don't sell data.
What we collect
- The domain you submit. The
sniff_domaintool receives a domain (or URL) and analysis options, which we process to produce the dossier. - Request metadata. Standard server logs (IP address, timestamp, and the requested operation) used for rate-limiting, abuse prevention, and debugging.
- Analysis results. We store the domain you submitted, the options you passed, the resulting dossier, your account identity, and the IP the request came from.
- Authentication token. If you connect with a Bearer token, we process a one-way hash of it to identify your plan and apply your rate limit. We do not log the raw token.
We do not collect the content of your conversations with your AI client, nor any data from your device beyond the request itself.
What we analyze
To build a dossier, Bassethound fetches publicly available
information about the submitted domain: its web pages, DNS records,
TLS certificate, and well-known files (e.g. robots.txt,
llms.txt, security.txt). This is the same information
any visitor or search engine can access. We do not attempt to access private,
authenticated, or non-public areas of a site.
How we use data
- Operate the service and return your dossier.
- Enforce rate limits and prevent abuse.
- Cache results briefly so repeated lookups are fast and cheap.
- Maintain and improve reliability and detection quality.
We do not use your requests to build advertising profiles, and we do not sell or rent data to third parties.
Storage and retention
- Result cache: dossiers are cached for a short, time-limited window (up to 24 hours) and then evicted. The cache is keyed by domain and profile, not to your identity.
- Server logs: retained for up to 30 days for security and operations, then deleted.
- Analysis results: retained indefinitely, including your account identity and the request IP stored alongside the dossier.
- Billing: a paid plan stores only the minimum needed for billing and plan enforcement, governed by this policy.
Third-party services
We rely on a small set of infrastructure and processing providers to run the service:
- Amazon Web Services for cloud infrastructure and hosting.
- Anthropic provides the LLM used for parts of the analysis pipeline. Domain content fetched during analysis may be sent to the model to produce the dossier; it is not used to train models.
- A managed crawl/render backend used to fetch public pages during analysis.
These providers process data only to deliver the service and are bound by their own terms and security commitments.
Your choices
- Don't submit sensitive domains you don't want analyzed. The tool acts on whatever domain it's given.
- Contact us to ask what request metadata we hold about your IP or token, or to request deletion, at the address below.
Children's privacy
Bassethound is a developer tool and is not directed to children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected by the "Last updated" date above.
Contact
Questions or requests about this policy or your data: privacy@bassethound.ai, NimbleBrain, Inc.