MaxRemote returns basic host information only when an authenticated client calls host_info: hostname, operating-system platform, CPU architecture, OS release, and the home-directory path.
OAuth authorization codes and access/refresh tokens are held in server process memory and are cleared when the process restarts. The OAuth login password is stored locally on the authorized Mac and is not returned by the MCP tool.
MaxRemote does not implement analytics, advertising, payments, or sale of user data. Network traffic to the public MCP endpoint is transported through Tailscale Funnel and is therefore also subject to Tailscale's infrastructure and policies.