Privacy Policy

Your Privacy Matters

We are committed to protecting your privacy and being transparent about how we collect, use, and protect your information.

Last updated: December 30, 2024

Data Encryption

All data is encrypted in transit and at rest using industry-standard encryption.

Transparency

We clearly explain what data we collect and how we use it.

Data Control

You have full control over your data with options to export or delete.

1. Information We Collect

Account Information

When you create an account, we collect your email address, name, and authentication information from our SSO provider (lynax.ai). We do not store passwords directly.

API Configuration Data

We store your API configurations, including endpoint URLs, authentication methods, and encrypted API credentials. Sensitive stored secrets are encrypted at rest and masked in owner-facing edit screens.

Usage Analytics

We collect aggregated usage statistics including MCP server requests, response times, and error rates to improve our service quality. This data is anonymized and does not include personal information.

Payment Information

Payment processing is handled by PayPal. We store subscription status and transaction IDs but do not store credit card numbers or payment details.

2. How We Use Your Information

Service Provision

  • • Creating and managing your MCP servers
  • • Processing API requests from AI agents
  • • Providing analytics and usage dashboards
  • • Managing your subscription and billing

Communication

  • • Sending service notifications and updates
  • • Responding to support requests
  • • Sharing important security or policy updates

Service Improvement

  • • Analyzing usage patterns to improve performance
  • • Developing new features and capabilities
  • • Ensuring security and preventing abuse

3. Data Protection & Security

Encryption

All data is encrypted in transit using HTTPS/TLS. Stored API keys, Bearer tokens, Basic Auth passwords, OAuth client secrets, access tokens, and refresh tokens are encrypted at rest before being written to persistent storage.

Access Controls

Access to your data is restricted to authorized personnel only and is logged for security auditing. We follow the principle of least privilege access.

Infrastructure Security

Our infrastructure is hosted on secure cloud providers with regular security updates, monitoring, automated backup systems, and production key management isolated from the application database.

4. Data Sharing & Third Parties

We do not sell, rent, or share your personal information with third parties except in the following limited circumstances:

Service Providers

  • • Authentication services (lynax.ai SSO)
  • • Payment processing (PayPal)
  • • Cloud infrastructure providers
  • • Email service providers

Legal Requirements

We may disclose information when required by law, court order, or to protect our rights, property, or safety, or that of our users or others.

5. Your Rights & Choices

Access & Portability

You can access and export your data through your dashboard or by contacting support. We provide data in standard formats when possible.

Correction & Updates

You can update your account information and API configurations at any time through your dashboard.

Deletion

You can delete your account and all associated data at any time. Some data may be retained for legal or security purposes as required by law.

Communication Preferences

You can opt out of non-essential communications through your account settings or unsubscribe links in emails.

6. Data Retention

We retain your data only as long as necessary to provide our services:

  • • Account data: Until account deletion
  • • MCP configurations: Until manually deleted
  • • Usage logs: 30 days (for quota management)
  • • Analytics data: 2 years (aggregated and anonymized)
  • • Billing records: 7 years (legal requirement)

7. International Data Transfers

Our services may involve data processing in different countries. We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses and adequacy decisions where applicable.

8. Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send email notifications.

10. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us: