← Back to home

Legal

Privacy Policy

Last updated

Draft — review by counsel pending

This is the initial public-site Privacy Policy. Customers under a Data Processing Addendum (DPA) or Business Associate Agreement (BAA) are additionally governed by those documents. Contact privacy@mcp-guard.ai for the DPA or BAA.

1.Who we are

MCP Guard is operated by the entity identified at the bottom of this page. We provide policy-gating software for AI agent tool calls. For data-protection purposes:

  • We are a data controller for the personal data we collect about visitors to mcp-guard.ai and account holders on mcp-guard.ai.
  • We are a data processor for Customer Data that passes through the hosted Services on a customer’s behalf — that processing is governed by our Data Processing Addendum.

2.What we collect

Marketing site
Anonymous analytics (page views, referrers, country-level geo). We do not run third-party advertising trackers on the marketing site.
Account data
Email, name, organization, password hash, and authentication metadata for accounts created at mcp-guard.ai. Used to operate the product.
Billing data
Billing contact information and payment method tokens — stored by Stripe, not by us. We retain invoice records and tax data as required by law.
Product telemetry
Aggregate usage signals (evaluations per minute, latency percentiles, error rates) to operate and improve the Services. Tenant-scoped and pseudonymous; we do not analyze the content of customer policies.
Customer Data (processor role)
Action payloads, reviewer decisions, and audit-chain entries that pass through hosted Services. Processed only to perform the Services. Subject to the DPA where applicable.
Support correspondence
Emails and messages you send us. Retained for as long as needed to resolve the inquiry, then deleted on a routine schedule.

3.What we don't collect

  • We do not sell personal data to third parties. We have never sold personal data.
  • We do not run advertising trackers on the marketing site (no Google Analytics for Ads, no Meta Pixel, no LinkedIn Insight).
  • We do not retain raw request parameters in the hosted audit log by default — we store a SHA-256 hash. Customers may opt in to retain raw parameters for review-mode decisions.

4.Legal bases (GDPR / UK GDPR)

  • Contract. Operating accounts, billing, and providing the Services.
  • Legitimate interests. Aggregate telemetry, security monitoring, fraud prevention.
  • Consent. Marketing communications (where required).
  • Legal obligation. Tax records, lawful requests from authorities.

5.Subprocessors

We use a small set of subprocessors to run the Services. The current list is maintained at mcp-guard.ai/legal/subprocessors and includes — at minimum — our cloud provider (Cloudflare), database provider (Supabase), payments provider (Stripe), and email provider (Cloudflare Email Service). We notify customers under DPA of material changes.

6.International transfers

Customer data is processed primarily in the EU (eu-central-2). Where data leaves the EU/EEA, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.

7.Retention

We retain account and billing data while your account is active and for the period required by law afterwards. Audit-chain entries in hosted Services are retained per the customer’s tier-default or contracted retention window. Aggregate telemetry is retained for up to 13 months.

8.Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Email privacy@mcp-guard.ai to exercise any of these.

9.Security

Encryption in transit (TLS 1.2+) and encryption at rest are applied to all hosted Services via our infrastructure providers (Cloudflare and Supabase). Tenant data isolation is enforced via Postgres row-level security. The audit log is hash-chained and append-only by construction. Multi-factor authentication is available on all accounts, and role-based access controls (admin / reviewer / senior_reviewer / developer / viewer) gate the dashboard and API. Enterprise customers may bring their own KMS key. Incident notification is handled per the DPA for customers; we will notify affected individuals as required by law.

10.Changes

We may update this Policy from time to time. Material changes will be flagged on this page and (for account holders) notified by email at least 30 days in advance.