This Privacy Policy explains how PopMCP collects, uses, discloses, stores, and protects personal information when you visit our website, create an account, use our application, connect providers, use hosted MCP endpoints, contact us, or otherwise interact with PopMCP.
PopMCP is a control plane between MCP-compatible clients and the third-party provider accounts you connect. This Policy describes our own processing. It does not govern the independent privacy practices of the providers you connect or the AI clients you choose to use.
1. Who We Are
The Service is operated by PopMCP ("PopMCP," "we," "us," or "our"). For privacy questions or rights requests, contact privacy@popmcp.com.
2. Scope
This Privacy Policy applies to our website, account registration and sign-in, workspace and tenant management, provider connections, hosted MCP endpoints and usage, billing flows, support interactions, and related operational communications.
It does not govern third-party services you access outside PopMCP, including the providers you connect and the AI clients you use, which have their own terms and privacy policies.
3. Information We Collect
We may collect the following categories of information.
A. Account and authentication information
- name, email address, avatar, and the profile information returned by Google sign-in through our authentication provider;
- authentication identifiers and signed session information;
- tenant membership, team role, invitation status, and access-control state.
B. Workspace and organization data
- agency and organization names, settings, and configuration;
- members, roles, invitations, and approval requests;
- plan, billing interval, and service-state information for the tenant.
C. Provider-connection data and credentials
- the provider type, connection metadata, verification status, and granted scopes;
- the provider credential you supply, which is encrypted at rest before storage (see the section on how credentials are protected);
- configuration such as access mode and whether the full catalog is exposed.
D. Personal access tokens
When you create a personal access token, we store a token label, a short non-secret prefix, and a cryptographic hash of the token secret. We do not store the raw token secret; it is shown once at creation and cannot be retrieved afterward.
E. MCP usage events
Each request to a hosted MCP endpoint may generate a usage event used for analytics, rate limiting, reliability, security, and billing. A usage event may include:
- the RPC method, tool name, outcome, status code, latency, and request and response byte sizes;
- the reporting client name and version;
- a hashed representation of the network address (IP hash) rather than the raw IP address, where applicable;
- timestamps and the associated tenant, organization, instance, and token identifiers.
F. IP allowlisting and recent connection IPs
If a workspace owner enables IP allowlisting, we process the IP addresses or ranges the owner adds to the allowlist, and we record the IP addresses that recent authenticated requests to the account's hosted MCP endpoints were made from, together with the reporting client name and the workspace and connection involved. These recent connection IP addresses are shown only to authorized workspace owners so they can configure the allowlist, and are retained for a limited period before being deleted. This is separate from the hashed network address stored with usage events described above.
G. Billing and transaction information
- plan tier, billing interval, subscription status, renewal dates, and cancellation state;
- customer and subscription identifiers, payment status, refunds, disputes, and invoice metadata from
Stripe; - limited payment-method metadata, such as card brand or last four digits, where the processor makes it available.
Full payment credentials, such as complete card numbers, are collected directly by Stripe rather than by PopMCP.
H. Support, communications, and technical data
- messages, support requests, and feedback you send us, and transactional email history;
- device and browser information, request metadata, application logs, and error events;
- product analytics events, where configured, with sensitive route tokens and identifiers scrubbed before capture.
4. How We Use Information
We may use personal information to:
- create, authenticate, secure, and manage accounts, tenants, and workspaces;
- verify provider connections and route authorized MCP requests to connected providers;
- enforce roles, permissions, access modes, per-token rate limits, and IP allowlisting;
- provide usage analytics, reliability monitoring, and security investigation;
- process subscriptions, renewals, invoices, and refund or dispute handling through
Stripe; - communicate with you about your account, security, and the Service;
- detect, prevent, and respond to abuse, fraud, and security incidents;
- comply with law, enforce our agreements, and protect rights, safety, and the Service.
5. Legal Bases for Processing
Where applicable law such as the GDPR requires a legal basis, we rely on: performance of our contract with you to provide the Service; our legitimate interests in operating, securing, and improving the Service; compliance with legal obligations; and your consent where we ask for it, such as for certain optional analytics technologies.
6. How Provider Credentials Are Protected
Provider credentials are sensitive, and we apply specific protections to them.
- provider credentials are encrypted at rest using
AES-256-GCMbefore they are stored; - personal access token secrets are stored only as cryptographic hashes, never in plaintext;
- sensitive values are redacted from structured logs;
- credentials are decrypted only when needed to verify a connection or perform an operation you or your authorized client requests, and access is scoped to the relevant tenant.
We do not sell provider credentials and do not use them to access your provider accounts other than to perform the Service functions you request. These protections do not remove your responsibility for the credentials you choose to connect and the actions taken with them, which is described in our Terms and Conditions.
8. Data Retention
We retain personal information for as long as reasonably necessary to provide the Service, maintain your account and tenant, secure the Service, comply with legal and accounting obligations, resolve disputes, and enforce agreements.
- account and workspace records are typically retained while the account is active and for a reasonable period afterward;
- encrypted credentials and connection metadata are retained until you disconnect the connection, the credential expires, or we determine they are no longer needed;
- usage events and operational logs may be retained for limited periods that vary by plan, configuration, and technical need;
- IP addresses recorded for IP allowlisting, including recent connection IPs shown to workspace owners, are retained only for a limited period and then deleted;
- billing, invoice, refund, dispute, and tax records may be retained for longer periods where required for accounting, legal, fraud-prevention, or audit purposes.
Deleting a tenant or connection may not immediately remove backup, billing, security, or legal records, which are removed or de-identified according to operational and legal retention schedules.
9. Security
We use technical and organizational measures, including encryption at rest and in transit, hashed token secrets, signed sessions, role-based access controls, per-token rate limiting, secret redaction, tenant isolation, and monitoring, designed to protect personal information. More detail is provided in our Security Overview.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for protecting your account access, provider credentials, MCP URLs, and tokens.
10. International Data Transfers
PopMCP and its service providers may process and store information in countries other than where you live, which may have data-protection rules that differ from your local laws. Where required, we use contractual and organizational measures designed to support lawful international transfers.
11. Your Rights and Choices
Depending on your location and the circumstances, you may have rights under laws such as the GDPR and the CCPA to access, correct, delete, restrict, object to, or export certain personal information, to withdraw consent where processing depends on consent, and to complain to a data-protection authority. The CCPA also gives California residents the right not to receive discriminatory treatment for exercising their rights; note that we do not sell personal information.
You also have practical in-product choices, such as managing members, connections, and tokens, disconnecting providers, or canceling billing if you are the workspace owner. To submit a privacy request, contact privacy@popmcp.com. We may ask for reasonable verification before acting, and some rights may be limited where exceptions apply under applicable law. Please do not include provider secrets or token values in your message.
12. Children's Privacy
PopMCP is not directed to children, and we do not knowingly collect personal information from children under the age required by applicable law to consent to data processing. If you believe a child has provided personal information to us, contact us so we can review the situation.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, product, or operational changes. If we make material changes, we may notify you through the Service, by email, or by updating the "Last updated" date above.
14. Contact Us
Privacy questions, requests, or concerns may be sent to:
PopMCP