Privacy Policy
Last updated: July 29, 2026
Who we are
mpak is operated by NimbleBrain Inc. ("NimbleBrain", "we", "us"). This policy covers the mpak.dev website, the registry at registry.mpak.dev, and the mpak CLI tool.
What we collect
- Account information: When you create an account, we collect your email address and display name via our authentication provider (Clerk).
- Package data: When you publish a package, we store the package contents, metadata, and your publisher identity.
- Usage data: We collect aggregate download counts per package. The CLI does not send telemetry or track individual users.
- Server logs: Our servers log IP addresses and request metadata for security and abuse prevention. Logs are retained for 30 days.
- Site analytics: The registry at registry.mpak.dev loads Google Tag Manager to measure aggregate usage, such as which pages are visited. This may set cookies in your browser. The mpak.dev website and the CLI do not load it.
What we don't collect
- We don't sell or share personal data with third parties.
- We don't track which packages you install.
How we use your data
- To operate the registry and serve packages.
- To display publisher identity on packages you publish.
- To prevent abuse and enforce our terms of service.
- To send transactional emails about your account (no marketing emails).
Third-party services
We use the following services to operate mpak:
- Clerk for authentication.
- AWS for hosting and package storage.
- Google Tag Manager for aggregate usage analytics on the registry.
Each service has its own privacy policy governing its handling of your data.
Data deletion
You can delete your account at any time by contacting us. We will remove your account data and unpublish any packages you've published, unless they have downstream dependents.
Contact
Questions about this policy? Email us at privacy@mpak.dev.