1. Overview
MMP is designed for scientists and researchers. We keep data handling direct and limited to operating portal sessions, tool handoffs, and protected CANFAR workflows.
2. Authentication data
When you sign in, CADC OIDC returns token and profile information. MMP stores session state in secure, HTTP-only cookies and never returns CADC tokens through browser-facing session APIs.
3. Preferences and logs
Theme and animation settings are stored in your browser. Standard server logs may record IP address, browser type, route, and status code for troubleshooting and security monitoring.
4. Connected services
MMP links to or proxies requests for services including CANFAR, CADC, GitHub, Harbor, ARC, Vault, ReadTheDocs, and PyPI. These services have their own privacy and retention practices.
5. Retention
MMP does not maintain a long-term user profile database in v0.0.1. Session state expires according to portal session settings or when you sign out.
6. Security
Use HTTPS in production, rotate credentials, review generated workflows, and report suspected vulnerabilities through the contact page.
