Privacy Policy
Effective September 16, 2026
1. Scope
This policy explains how the Operator handles personal information when you use this AlltoMCP deployment. Third-party APIs, MCP clients, ChatGPT, Claude, and other connected services operate under their own privacy policies.
2. Information processed
- Account data: name, email address, password hash and salt, account identifier, and creation date.
- Connector data: API names and URLs, uploaded contracts, REST endpoint definitions, GraphQL documents, tool descriptions, authentication configuration, and selected tools.
- Credentials and tokens: optional upstream credentials encrypted at rest; MCP token hashes and prefixes; browser sessions; and OAuth authorization, access, and refresh records.
- Usage and technical data: requests, timestamps, IP address, user agent, errors, and security events that may be processed by the application, hosting platform, or network infrastructure.
- Upstream content: tool inputs and API responses processed transiently to fulfill an MCP request. Avoid submitting personal or sensitive data unless necessary and lawful.
3. How information is used
The Operator uses information to provide and secure accounts; create, store, and execute connectors; authenticate MCP clients; route requests to APIs you select; troubleshoot failures; prevent abuse; maintain the Service; and meet legal obligations.
4. How information is shared
Information is sent to upstream APIs and MCP clients as directed by you. It may also be processed by infrastructure and service providers used by the Operator, and disclosed when required by law, to protect rights and security, or in connection with a business transfer. The seed application does not include advertising or data-sale functionality.
5. Credentials and security
Stored upstream credentials are encrypted using AES-256-GCM. Passwords and static MCP token secrets are stored as derived values or hashes rather than retrievable plaintext. Token secrets are displayed only when created or rotated. No system is completely secure, and you remain responsible for limiting scopes, rotating credentials, and reviewing tool access.
6. Retention
Connector records remain until you delete them or the Operator removes them. Account, session, OAuth, backup, and security records are retained according to the Operator’s operational and legal needs. Contact the Operator to request account deletion or obtain the deployment-specific retention schedule.
7. International processing
Your information may be processed where the Operator, hosting providers, connected MCP clients, or upstream APIs operate. Those locations may apply different data-protection rules. The Operator is responsible for implementing any required transfer safeguards.
8. Your choices and rights
You can edit or delete connectors, revoke or rotate connector tokens, and stop connecting an MCP client. Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Submit requests to the Operator; identity verification may be required.
9. Children
The Service is not intended for children or for use by anyone who cannot legally agree to the Terms. Do not knowingly submit children’s personal information.
10. Changes
The Operator may update this policy as practices or legal requirements change and should publish the revised effective date. Material changes should be communicated through an appropriate notice.
11. Contact
Privacy questions and rights requests should be sent using the contact method published by the Operator of this deployment.