Privacy policy

What we collect, why, who we share it with, and the choices you have.

Tip: use your browser's Print command and choose “Save as PDF” to download a copy.

Last updated: October 2026

This Privacy Policy explains how privacymcp.ai ("we", "us") collects, uses and shares personal information when you use Privacy MCP: our website at privacymcp.ai, the connector at mcp.privacymcp.ai, and the related service (together, the "Service"). It should be read with our Terms of Service and Security Controls.

1. The short version

  • Privacy MCP connects your own OneTrust tenant to an AI assistant you choose (such as Claude, ChatGPT or Gemini).
  • We do not store the contents of your OneTrust records. They pass through our servers in memory on their way to your assistant.
  • We do not sell personal information, and we do not use advertising or third-party tracking cookies.
  • We do not use your data to train AI models.
  • You can delete your organization at any time, which removes the data described in section 10.
  • Questions or requests: hello@privacymcp.ai.

2. Who is responsible for what

  • For your account and billing information, we decide how and why it is used. We are the "controller" (or "business").
  • For content that passes through the Service on your organization's behalf (such as OneTrust data you ask your assistant to retrieve), your organization decides how and why it is used and we process it on your instructions. We are the "processor" (or "service provider"). A data processing agreement is available on request at hello@privacymcp.ai.

3. Information we collect

Account information. Your name and email address, and whether your email has been verified. You sign in through our identity provider, Neon Auth. Your password is handled by that provider; we never see or store it.

Organization information. Your organization's name, plan and subscription status; each person's role and read-only setting; the email addresses of members; and invitations (the invited email address, who invited them, the role offered, and when it expires).

Your OneTrust connection. Your OneTrust host name and API client ID, and your API client secret, which is encrypted before it is stored and cannot be viewed again once saved.

Connections from your AI assistant. The name and redirect address an assistant registers when it connects, and the access tokens issued to it. Tokens are stored only as one-way hashes.

Activity records (audit log). For each call made through your organization: who made it (their email), which operation, the request method and path, when, the outcome, how long it took, and the size of the result. Request arguments are recorded only as names plus a one-way hash of their values. The content of OneTrust results is not stored. Changes to your team (invitations, role and access changes, removals) and exports of the log are recorded too.

Catalog activity. When an assistant searches or looks up descriptions of OneTrust operations, we record the person, the operation or search term, and the time. We use this only to detect abuse, and we keep it for about 8 days.

Usage. The number of calls made by each organization.

Billing information. Payments are handled by Stripe. We receive and store your Stripe customer and subscription identifiers, your plan, subscription status and renewal date. Card details go directly to Stripe and are never seen or stored by us.

Technical information. Our hosting and security systems process standard technical data such as IP address, browser type and request details. We also keep short-lived counters of failed sign-in or token attempts by IP address to block guessing attacks.

Communications. If you email us, we keep the message and our reply.

Cookies and similar technologies. We use a sign-in session cookie so you stay logged in, and your browser's temporary storage remembers the page you were heading to (for example an invitation) for up to 30 minutes while you finish signing in. We do not use advertising or analytics cookies.

4. Information we do not collect

  • The contents of your OneTrust records or other data returned to your assistant.
  • Your conversations with your AI assistant.
  • Payment card numbers.
  • Your password.

5. How we use information

  • To provide, operate and secure the Service, including signing you in, connecting your assistant to your OneTrust tenant, and enforcing the access settings your administrators choose.
  • To record the audit log your organization relies on.
  • To process payments and manage subscriptions.
  • To detect and prevent abuse, fraud and security incidents, including heavy scraping of our operation catalog.
  • To provide support and respond to you.
  • To meet legal obligations and enforce our Terms.
  • To understand overall usage using aggregate counts.

6. Legal bases (EEA, UK and similar regions)

Where those laws apply, we rely on: performing our contract with you; our legitimate interests in running a secure and reliable service and preventing abuse; legal obligations; and consent where it is required.

7. How we share information

Service providers. We use providers to run the Service:

ProviderWhat they doLocation
VercelApplication hostingUnited States
NeonDatabase and sign-in (Neon Auth)United States
StripePayments and billingPer Stripe

At your direction. Data you ask your assistant to retrieve is sent to your AI assistant provider (for example Anthropic, OpenAI or Google), and requests go to OneTrust, using the credentials you gave us. Those companies handle data under their own terms and privacy policies.

Within your organization. Administrators can see the members of the organization, their roles and the organization's activity log.

Legal and safety. We may disclose information if required by law or to protect the rights, safety or security of people or the Service.

Business transfers. If we are involved in a merger, acquisition or sale of assets, information may be transferred, and we will tell you.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

8. International transfers

We host the Service in the United States. If you use it from elsewhere, your information will be processed in the United States. Where the law requires it, we put appropriate safeguards in place for international transfers, such as standard contractual clauses.

9. Security

We protect information with encryption in transit, encryption of your OneTrust secret, hashed tokens, per-organization isolation, and an audit log, among other controls. See our Security Controls for details. No method of transmission or storage is perfectly secure.

10. How long we keep information

InformationHow long
Account informationWhile your account is active
Organization data (connection, members, invitations, usage, audit log, access tokens)Until an organization admin deletes the organization, which removes it immediately
Catalog activityAbout 8 days
Failed-attempt counters (by IP address)About an hour
Billing records at StripeAs Stripe and financial regulations require
Backups and server logsPer our providers' retention periods, then they age out

When an organization is deleted we also cancel its subscription and permanently remove its stored OneTrust credentials, access tokens and connections, members, invitations, usage records, audit log and related alerts. Admins can export the audit log before deleting.

To have your personal account deleted, email hello@privacymcp.ai and we will do it within 30 days, except where we must keep information for legal reasons.

11. Your rights and choices

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain uses, and withdraw consent. You will not be treated differently for using these rights.

To use them, email hello@privacymcp.ai. We may need to verify your identity, and we aim to respond within 30 days. If your account belongs to an organization, we may direct requests about organization data to its administrators.

  • US state privacy laws. Residents of states with comprehensive privacy laws (such as California, Colorado and Virginia) have rights to know, access, correct and delete their personal information and to opt out of sale and targeted advertising. We do not sell personal information or use it for targeted advertising. You can appeal a decision by replying to our response.
  • EEA and UK. You may also lodge a complaint with your local data protection authority.
  • Do Not Track. We do not track you across other websites.

12. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

13. Links to other sites

The Service may link to other websites, such as Stripe and your AI assistant. We are not responsible for their privacy practices.

14. Changes to this policy

We may update this policy. For material changes we will notify you by email or in the Service before they take effect. The date at the top shows when it was last updated.

15. Contact

privacymcp.ai — hello@privacymcp.ai