Legal

Privacy Policy

Last updated: September 20, 2026

This policy explains how MCP-LINK (“we”, “us”, “our”) collects, uses, and protects information when you use our website and gateway services (the “Service”). We are committed to data minimization: we collect only what is necessary to operate the Service.

1. Overview

MCP-LINK provides an API gateway that routes Model Context Protocol (MCP) traffic between AI agents, and stores transient artifacts (such as context files) on behalf of users. This policy applies to our website at https://getmcproute.com and all associated API endpoints and subdomains.

For privacy inquiries related to the Service, contact [email protected]. Requests are handled through the MCP-LINK support team for services running on getmcproute.com.

2. Information we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information we do NOT collect

3. How we use information

PurposeLegal basis
Providing and operating the ServicePerformance of a contract (Art. 6(1)(b))
Security, abuse prevention, error monitoringLegitimate interests (Art. 6(1)(f))
Optional analytics, marketing emailsConsent (Art. 6(1)(a))
Tax, accounting, legal complianceLegal obligation (Art. 6(1)(c))

5. User content & artifacts

“User Content” means the MCP messages, context files, and artifacts you transmit through or store in the Service. Key points:

6. Service providers (sub-processors)

We use a limited number of trusted infrastructure providers:

ProviderPurposeData location
Cloudflare, Inc.DNS, CDN, edge compute (Workers/Pages), object storage (R2), database (D1), TLSGlobal edge network
Payment processor (if enabled)Billing for paid plansDetermined by the configured payment provider
Email provider (if enabled)Transactional and notification emailsDetermined by the configured email provider

To request the current list of sub-processors, email [email protected]. Material changes will be announced by email or on the product changelog when practicable.

7. International data transfers

Our infrastructure operates on a global edge network. If you access the Service from the European Economic Area (EEA), Switzerland, or the UK, personal data may be transferred to countries outside your jurisdiction, including the United States. Where required, such transfers are protected by Standard Contractual Clauses (SCCs) or other valid transfer mechanisms, and Cloudflare's data protection commitments apply.

8. Data retention

9. Security

10. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any right, email [email protected]. We will respond within 30 days. We may request verification of your identity.

California residents (CCPA/CPRA): we do not sell or share personal information for cross-context behavioral advertising. You may exercise the rights listed above; we do not discriminate based on the exercise of privacy rights.

11. Cookies & analytics

12. Children's privacy

The Service is intended for developers and businesses and is not directed at children under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or on the product changelog at least 14 days before taking effect. The “Last updated” date at the top of this page always reflects the current version. Continued use of the Service after changes take effect constitutes acceptance.

14. Contact

Questions about this policy?

Email: [email protected]

Security: [email protected]

Website: https://getmcproute.com