Privacy
Last updated 5 October 2026.
Validation of VAST XML still runs in your browser via WebAssembly. The CLI and library do not send tags unless you pass --contribute-sample. The hosted MCP endpoint at vastlint.org/mcp stores a redacted copy, as described below. Local vastlint-mcp over stdio does not.
What we keep
When you paste or fetch a tag in the tester, inspector, validator, the IAB Tech Lab VAST Tester fork, or when an agent sends a tag to the hosted MCP server at vastlint.org/mcp, vastlint.org may store a copy of that XML. Known device IDs, IPs, and consent query parameters are stripped from that XML before storage. The hostname of a fetched tag URL may be stored. Cloudflare also supplies the country and the network owner (ASN number and organization name, for example an ISP or a company network). We use that to see which networks send tags. We do not store the IP address. We may keep a random session id that exists only while this browser tab is open, so tags from the same tab can be grouped. If you arrived from another site, we may keep that site's hostname. If the tool URL has utm_source or utm_medium, those values may be kept. Built-in sample scenarios are not sent. Tracking pixel URLs linted on the tester and inspector may also be stored in pixellint.org's sample database (same identifier stripping, one row per URL). The local vastlint-mcp stdio server does not send tags. Tags are used to improve validation rules and for the research uses described in the terms. Submitted XML is not published as a public gallery.
How we use stored tags
We may fetch wrapper hops and request media, tracking, verification, and other URLs found in a submitted tag while developing and testing rules. Those requests can fire third-party beacons. We may also use stored tags for research and scientific publication: aggregate statistics, issue-level findings (rule identifiers and structural paths, without XML values), and papers or preprints based on those. For tags submitted after 26 August 2026, we may quote short redacted excerpts when they illustrate a finding and do not identify a natural person. By submitting a tag you license that use. Details are in the terms.
Opt out
Each tool page has a Don't send my tags control. That sets a flag in this browser only. That also stops tracking pixel URLs from going to pixellint.org and pauses session recording and Tester activity logs. The Stop session recording control in the footer pauses session recording and Tester activity logs on this browser without changing tag storage. The explicit contribute this tag button on the validator still sends a sample if you click it. That control does not stop the tester and inspector network-owner record described under Analytics. It does not apply to the hosted MCP server. Neither control deletes data already sent or withdraws research use of those tags. Email [email protected] to exclude a previously stored sample from research. To keep tags off the network, use local vastlint-mcp over stdio or the CLI without --contribute-sample.
Analytics
The public site uses Google Analytics and Cloudflare Web Analytics for page traffic. That is separate from tag storage. Opening the tester or inspector may also store country and network owner (ASN number and organization name) once per browser tab per day, with the same session id, referrer hostname, and utm tags described above. We do not store the IP address. Don't send my tags stops XML and Pixellint pixel-URL storage. It does not stop this network-owner record.
Session recordings
We record browser interactions on the homepage, tester, and inspector to find usability problems. Recordings contain page layout, clicks, scrolling, and timestamps linked by a random identifier kept for the life of one browser tab. A separate random identifier in local storage links later sessions in the same browser profile. We do not fingerprint the browser. Recordings may include visible page text, typed inputs, pasted XML, full URLs, validation results, and content shown in the tester and inspector. Third-party iframe contents and media playback may not appear in a recording. The separate tag and tool-visit storage described above still applies. Recordings are stored in a private Cloudflare R2 bucket and may be downloaded for local analysis. No automatic deletion period is configured for recordings at present. The footer control stops future session recording on this browser.
Tester activity logs
The tester logs each attempted tag URL, including its full path and query string, before fetching it. A failed fetch logs the URL, HTTP status when available, and error message. Each XML validation run logs the submitted XML and its result. Built-in samples log only the sample identifier. These entries use the same private R2 bucket and browser identifiers as session recordings. No automatic deletion period is configured. Don't send my tags and Stop session recording both stop future Tester activity logs.