# Mistra > The private, show-only way to share what you made in AI. One self-contained HTML page per share, served show-only and gated to specific recipients by a passwordless magic link. Published pages cannot collect data, make network requests, submit forms, or navigate the viewer — the browser enforces this (sandboxed iframe + strict Content-Security-Policy). Download is off by default and opt-in per share. Recipients prove who they are with a one-time email link. Hosted in the EU. Publish from any MCP client (the `publish_artifact` then `share_with` tools) or directly in the dashboard. ## Pages - [Home](https://app.mistra.io/): product overview and pricing - [Privacy](https://app.mistra.io/privacy) - [Terms](https://app.mistra.io/terms) - [Cookie policy](https://app.mistra.io/cookies) - [MCP endpoint](https://api.mistra.io/mcp): connect an AI client over MCP (OAuth 2.1) ## Notes - Self-contained: no external URLs, CDNs, or fonts. A share is one HTML file, or one HTML file plus a local /assets bundle (images/fonts/CSS/JS). - Per-recipient access; expired or revoked links stop working.