L2 Legal

Privacy Policy

1. Scope

This policy explains how the Operator handles personal information when you use this AlltoMCP deployment. Third-party APIs, MCP clients, ChatGPT, Claude, and other connected services operate under their own privacy policies.

2. Information processed

3. How information is used

The Operator uses information to provide and secure accounts; create, store, and execute connectors; authenticate MCP clients; route requests to APIs you select; troubleshoot failures; prevent abuse; maintain the Service; and meet legal obligations.

4. How information is shared

Information is sent to upstream APIs and MCP clients as directed by you. It may also be processed by infrastructure and service providers used by the Operator, and disclosed when required by law, to protect rights and security, or in connection with a business transfer. The seed application does not include advertising or data-sale functionality.

5. Credentials and security

Stored upstream credentials are encrypted using AES-256-GCM. Passwords and static MCP token secrets are stored as derived values or hashes rather than retrievable plaintext. Token secrets are displayed only when created or rotated. No system is completely secure, and you remain responsible for limiting scopes, rotating credentials, and reviewing tool access.

6. Retention

Connector records remain until you delete them or the Operator removes them. Account, session, OAuth, backup, and security records are retained according to the Operator’s operational and legal needs. Contact the Operator to request account deletion or obtain the deployment-specific retention schedule.

7. International processing

Your information may be processed where the Operator, hosting providers, connected MCP clients, or upstream APIs operate. Those locations may apply different data-protection rules. The Operator is responsible for implementing any required transfer safeguards.

8. Your choices and rights

You can edit or delete connectors, revoke or rotate connector tokens, and stop connecting an MCP client. Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Submit requests to the Operator; identity verification may be required.

9. Children

The Service is not intended for children or for use by anyone who cannot legally agree to the Terms. Do not knowingly submit children’s personal information.

10. Changes

The Operator may update this policy as practices or legal requirements change and should publish the revised effective date. Material changes should be communicated through an appropriate notice.

11. Contact

Privacy questions and rights requests should be sent using the contact method published by the Operator of this deployment.