VASTlint

Privacy

Last updated 29 August 2026.

Validation of VAST XML still runs in your browser via WebAssembly. The CLI and library do not send tags unless you pass --contribute-sample. The hosted MCP endpoint at vastlint.org/mcp stores a redacted copy, as described below. Local vastlint-mcp over stdio does not.

What we keep

When you paste or fetch a tag in the tester, inspector, validator, the IAB Tech Lab VAST Tester fork, or when an agent sends a tag to the hosted MCP server at vastlint.org/mcp, vastlint.org may store a copy of that XML. Known device IDs, IPs, and consent query parameters are stripped from that XML before storage. The hostname of a fetched tag URL may be stored. Cloudflare also supplies the country and the network owner (ASN number and organization name, for example an ISP or a company network). We use that to see which networks send tags. We do not store the IP address. We may keep a random session id that exists only while this browser tab is open, so tags from the same tab can be grouped. If you arrived from another site, we may keep that site's hostname. If the tool URL has utm_source or utm_medium, those values may be kept. Built-in sample scenarios are not sent. Tracking pixel URLs linted on the tester and inspector may also be stored in pixellint.org's sample database (same identifier stripping, one row per URL). The local vastlint-mcp stdio server does not send tags. Tags are used to improve validation rules and for the research uses described in the terms. Submitted XML is not published as a public gallery.

How we use stored tags

We may fetch wrapper hops and request media, tracking, verification, and other URLs found in a submitted tag while developing and testing rules. Those requests can fire third-party beacons. We may also use stored tags for research and scientific publication: aggregate statistics, issue-level findings (rule identifiers and structural paths, without XML values), and papers or preprints based on those. For tags submitted after 26 August 2026, we may quote short redacted excerpts when they illustrate a finding and do not identify a natural person. By submitting a tag you license that use. Details are in the terms.

Opt out

Each tool page has a Don't send my tags control. That sets a flag in this browser only. That also stops tracking pixel URLs from going to pixellint.org. The explicit contribute this tag button on the validator still sends a sample if you click it. That control does not stop the tester and inspector network-owner record described under Analytics. It does not apply to the hosted MCP server. It does not recall tags already stored or withdraw research use of those tags. Email [email protected] to exclude a previously stored sample from research. To keep tags off the network, use local vastlint-mcp over stdio or the CLI without --contribute-sample.

Analytics

The public site uses Google Analytics and Cloudflare Web Analytics for page traffic. That is separate from tag storage. Opening the tester or inspector may also store country and network owner (ASN number and organization name) once per browser tab per day, with the same session id, referrer hostname, and utm tags described above. We do not store the IP address. Don't send my tags stops XML and Pixellint pixel-URL storage. It does not stop this network-owner record.