Privacy policy
Last updated: October 6, 2026
UltimateRest is a desktop REST API client. The short version: we don't collect anything.
- No accounts, no telemetry, no analytics, no ads. The app does not send any data to its developer.
- Your requests go only where you send them. UltimateRest connects only to the URLs you enter, the OAuth token URLs you configure and, only when you run Settings › Run network check,
1.1.1.1,2606:4700:4700::1111and a DNS lookup ofexample.com. - Local storage. Collections, environments, history, settings and open tabs are stored as JSON files on your PC (in the app's private folder when installed from the Microsoft Store). Variables you mark as secret are stored in Windows Credential Manager under your Windows account, not in those files.
- MCP server. The bundled
ultimaterest-mcpserver runs only when an AI client you configured starts it. It runs on your PC and lets that client read your collections and send requests. Secret values are used but never returned to the AI client. What that client does with responses is governed by its own privacy policy. - Errors. Unexpected errors are written to
errors.login the local data folder. That file is never uploaded. - Removing your data. Uninstalling the app removes its data folder. Delete secrets in Control Panel › Credential Manager (entries starting with
UltimateRest:).
Questions: soporte@jfdeveloper.com