Privacy Policy
Last updated: June 2026
This Privacy Policy explains what information mcpmake ("we", "us") collects, how we use it, and your choices. It applies to the mcpmake hosting service (the "Service").
1. Information we collect
- Account data: your email address, a hashed password, and your plan. Passwords are stored only as salted scrypt hashes.
- Content you provide: API specifications, recordings, website URLs, and API credentials ("secrets") you upload to generate and run servers. Secrets are encrypted at rest.
- Usage data: request and tool-call counts, timestamps, and server metadata used for metering, quotas, and abuse prevention.
- Payment data: handled by our payment processor, Stripe. We do not store full card numbers; we store a Stripe customer identifier to manage your subscription.
- Technical data: IP address and request logs, used for security, rate limiting, and debugging.
2. How we use information
We use your information to provide and operate the Service, authenticate you, meter usage and enforce quotas, process payments, send transactional email (verification and password reset), prevent abuse, and comply with legal obligations.
3. Cookies and sessions
We use a single first-party, HttpOnly session cookie to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.
4. Sharing
We share information only with service providers that help us run the Service — notably Stripe (payments), our hosting/infrastructure provider, and, if you configure one, your email (SMTP) provider. We do not sell your personal information. We may disclose information if required by law or to protect our rights and users.
5. The servers you deploy
Servers you create make outbound requests to the third-party APIs or websites you target, using the credentials you supply. Those third parties have their own privacy practices, which we do not control.
6. Data retention and deletion
We retain account and usage data while your account is active and as needed for billing, security, and legal compliance. You can delete your servers and secrets at any time from the dashboard. To delete your account and associated data, contact us.
7. Security
We use encryption for stored secrets, hashed credentials, network isolation for tenant containers, and access controls. No system is perfectly secure, but we work to protect your data and to limit what each component can access.
8. International users
We may process and store data in countries other than your own. By using the Service you consent to such processing consistent with this Policy.
9. Changes
We may update this Policy from time to time. Material changes will be posted here with an updated date.
10. Contact
Privacy questions or data requests: support@mcpmake.dev.