Privacy Policy

Last updated: April 6, 2026

MCPfiles.ai ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

1. Information We Collect

Information you provide

DataPurposeStored where
Email addressAccount creation, authentication (login codes), service communicationsMaster database + your tenant database
Display nameShown in the UI (optional)Your tenant database
Subdomain choiceYour unique URL (e.g., yourname.mcpfiles.ai)Master database
ArtifactsThe content you upload: markdown, JSON, links, skillsYour tenant database
Tags and project namesOrganization of your artifactsYour tenant database

Information collected automatically

DataPurposeRetention
IP addressRate limiting login attempts, audit logging90 days in login_codes; indefinite in audit_log
Access token usageLast-used timestamp, IP for security monitoringLifetime of the token + 90 days
Server logsDebugging, security monitoring30 days

Information we do NOT collect

2. How We Use Your Information

We use your information solely to:

We do not read, analyze, or train AI models on your artifact content. Your content is yours.

3. Data Isolation

MCPfiles.ai uses a database-per-tenant architecture. Each account has its own isolated MySQL database. Your artifacts, projects, tags, tokens, and audit logs are physically separated from every other user's data. There are no shared tables and no tenant_id columns -- your data lives in its own database.

The only shared database is the master tenant registry, which stores your email, subdomain slug, and account status. It does not contain any of your artifacts or content.

4. Data Sharing

We share your data only in these limited circumstances:

We do not sell your data. We do not share your data with advertisers. We do not use your content for AI training.

5. Access Tokens and AI Agents

When you generate an access token and provide it to an AI agent, that agent can interact with your account according to the token's permissions. We log which token performed each action (provenance tracking) so you can audit agent activity. You control:

We are not responsible for how third-party AI agents handle your token or the content they upload. Treat access tokens like passwords.

6. Cookies

We use a single session cookie for authentication after you log in. This cookie:

We do not use advertising cookies, tracking cookies, or third-party cookies of any kind.

7. Data Retention

DataRetention
Your artifacts and contentUntil you delete them, or 30 days after account deletion
Account informationUntil you delete your account
Login codesExpired codes purged after 24 hours
Expired/revoked access tokens90 days after expiration
Audit logs1 year
Server logs30 days

8. Your Rights

You have the right to:

To exercise any of these rights, use the web interface or API, or contact us at hello@mcpfiles.ai.

9. Security

We protect your data through:

No system is 100% secure. If you discover a security vulnerability, please report it to hello@mcpfiles.ai.

10. State-Specific Privacy Rights

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:

Categories of personal information collected: Identifiers (email address, IP address, display name); internet or electronic network activity information (access logs, token usage); content you create and upload.

Business purpose for collection: Providing the Service, authentication, security, and debugging.

Retention: See Section 7 above.

Sale of personal information: We have not sold personal information in the preceding 12 months and do not sell personal information.

To exercise your rights, contact us at hello@mcpfiles.ai. We will verify your identity by confirming your email address. You may designate an authorized agent to submit a request on your behalf.

Virginia Residents (VCDPA)

Virginia residents have the right to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of personal data for targeted advertising, sale, or profiling. We do not engage in any of these activities. To exercise your rights, contact us at hello@mcpfiles.ai. If we deny your request, you may appeal by emailing us with "VCDPA Appeal" in the subject line.

Colorado Residents (CPA)

Colorado residents have similar rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, or profiling. We do not sell data or use it for targeted advertising or profiling. To exercise your rights or file an appeal of a denied request, contact us at hello@mcpfiles.ai.

Connecticut Residents (CTDPA)

Connecticut residents have the right to access, correct, delete, and obtain a copy of their personal data. You may also opt out of sale, targeted advertising, and profiling -- none of which we engage in. Contact hello@mcpfiles.ai to exercise your rights.

Utah Residents (UCPA)

Utah residents have the right to access and delete their personal data, and to opt out of sale and targeted advertising. We do not sell data or engage in targeted advertising. Contact hello@mcpfiles.ai to exercise your rights.

Other States

Privacy laws are evolving across the United States. Regardless of where you live, we provide all users with the ability to access, export, correct, and delete their data through the web interface, API, or by contacting us. If your state enacts new privacy legislation, we will update this policy accordingly.

11. Do Not Track

We do not track users across third-party websites. We do not respond to Do Not Track (DNT) browser signals because we do not engage in the type of tracking that DNT is designed to prevent. We use no third-party analytics or advertising trackers.

12. Children's Privacy

MCPfiles.ai is not directed to children under 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us and we will delete it promptly.

13. International Data

The Service is hosted in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. By using the Service, you consent to this transfer. We process data lawfully based on your consent (account creation) and our legitimate interest in providing and securing the Service.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and changing the "Last updated" date. For significant changes, we will also send a notification to your registered email address.

15. Contact

Questions or concerns about this Privacy Policy? Contact us at hello@mcpfiles.ai.