Privacy
publicdata.au has no accounts and sets no cookies. Nobody is asked who they are, on the pages, in the query API or through the MCP server. The site is run by National Digital.
Page views
Cloudflare Web Analytics counts page views. It is served from this site's own provider, stores nothing in the browser and does not follow anyone across sites. There is no other tracking.
Votes and dataset requests
A vote is stored under a salted hash of the date, the dataset, the address and the browser's user agent, so each browser counts once a day. The salt stays in a private store and is never published, and the hash changes every day, so votes on different days cannot be linked. Only the total for each dataset is published.
A link pasted into the backlog is looked up in the catalogue and is not stored. When it names a dataset there, it counts as a vote for that dataset in the same way. When it does not, the page suggests sending it to National Digital, which is up to you.
The query API and the MCP server
The query API answers from the data and records nothing about who asked. The MCP server records nothing about who calls it or what they ask. To keep the rate limit, it counts row tool calls per address in Cloudflare's cache for 10 seconds.
Hosting
Cloudflare hosts the site and handles every request, including the address it came from, to deliver it and to block abuse. The Cloudflare privacy policy covers that handling.
Contact
Questions about privacy go to National Digital. Security reports go to the address in /.well-known/security.txt.