Legal
Privacy Policy
We take your privacy seriously. This policy explains what data we collect, how we use it, and the controls you have over your information.
Last updated: April 18, 2026
1. Introduction
MCPCloud (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use MCPCloud and its associated services.
By using the Service, you agree to the collection and use of information as described here. If you disagree, please discontinue use of the Service. This policy is incorporated into our Terms of Service.
2. Information We Collect
We collect the following categories of information:
- Account information: name, email address, password hash, organization name, and profile settings provided during registration.
- User Content: API specifications, OpenAPI/GraphQL schemas, MCP server configurations, skill definitions, and any files you upload to the Service.
- Billing information: subscription tier and payment method tokens managed by Stripe. We do not store full card numbers.
- Usage data: feature interactions, deployment events, API calls made within the platform, error logs, and performance metrics.
- OAuth tokens: access tokens from GitHub or other connected providers, stored encrypted at rest.
- Device and connection data: IP address, browser type, operating system, and session metadata collected automatically.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service and your account
- Process payments and manage subscription billing via Stripe
- Generate MCP server code and AI skills based on your uploaded specifications
- Deploy servers to cloud targets you authorize (Cloudflare Workers, Fly.io, etc.)
- Send transactional emails such as account verification, billing receipts, and security alerts
- Improve the platform through aggregated, anonymized usage analytics
- Detect and prevent fraud, abuse, and violations of our Terms of Service
- Respond to support requests and communicate service updates
We do not use your API specifications or generated server code to train AI models without your explicit opt-in consent.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data from active systems within 30 days and from backup systems within 60 days, except where retention is required by law.
Aggregated, anonymized analytics data that cannot be linked back to you may be retained indefinitely for product improvement purposes.
6. Data Security
We apply industry-standard safeguards to protect your information, including TLS encryption in transit, encryption at rest for sensitive fields (including OAuth tokens and API keys), multi-tenant data isolation at the database layer, and role-based access controls for internal systems.
While we take security seriously, no system is completely immune to breaches. In the event of a data incident affecting your personal information, we will notify you as required by applicable law. You can reduce risk by enabling multi-factor authentication on your account.
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention obligations.
- Portability: Request an export of your data in a machine-readable format.
- Objection: Object to certain processing activities, including direct marketing.
- Restriction: Request that we limit how we use your data in certain circumstances.
To exercise any of these rights, contact us at support@mail.mcpcloud.sh. We will respond within 30 days. EU/EEA residents may also lodge a complaint with their local supervisory authority.
9. Third-Party Services
The Service integrates with third-party providers whose privacy practices are independent of ours. We encourage you to review their policies:
- Stripe — payment processing and billing
- Cloudflare — deployment infrastructure, CDN, and DDoS protection
- Anthropic — AI inference for code generation features
- GitHub — OAuth authentication and repository integrations
- Convex — database and backend services
When you connect third-party accounts (such as GitHub), we store only the minimum token scopes required for the integration to function, encrypted at rest.
10. International Data Transfers
MCPCloud operates primarily in the United States. If you access the Service from the EU, EEA, UK, or other regions with data transfer restrictions, your information may be transferred to and processed in the United States. We rely on Standard Contractual Clauses and other approved transfer mechanisms where required by applicable law.
11. Children’s Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal information, please contact us at support@mail.mcpcloud.sh and we will promptly delete it.
12. Changes to This Policy and Contact
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice within the Service at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.
For privacy questions, requests, or concerns, contact our privacy team at support@mail.mcpcloud.sh.