This policy explains how MCP-LINK (“we”, “us”, “our”) collects, uses, and
protects information when you use our website and gateway services (the “Service”).
We are committed to data minimization: we collect only what is necessary to operate
the Service.
1. Overview
MCP-LINK provides an API gateway that routes Model Context Protocol (MCP) traffic
between AI agents, and stores transient artifacts (such as context files) on behalf
of users. This policy applies to our website at
https://getmcproute.com and all associated API
endpoints and subdomains.
For privacy inquiries related to the Service, contact
[email protected]. Requests are
handled through the MCP-LINK support team for services running on
getmcproute.com.
2.1 Information you provide
- Account data — email address and account credentials when you register.
- API credentials — API keys and scoped tokens you create to access the gateway.
- Communications — messages you send us (support requests, waitlist sign-ups, contact form submissions).
- Billing data — if you subscribe to a paid plan, our payment processor collects billing details. We do not store full card numbers.
2.2 Information collected automatically
- Request metadata — IP address (processed at the edge and typically truncated in logs), user agent, request timestamps, endpoint paths, HTTP status codes, and response sizes.
- Usage data — API call volumes, error rates, and latency measurements, used for rate limiting, abuse prevention, and service reliability.
- Website analytics — aggregate, privacy-friendly page-view statistics (see Section 11).
2.3 Information we do NOT collect
- We do not collect special categories of personal data.
- We do not sell personal data to third parties.
- We do not inspect or mine the content of your MCP messages for advertising purposes.
3. How we use information
- Operate, maintain, and secure the Service (routing, authentication, rate limiting).
- Provide customer support and respond to inquiries.
- Detect and prevent abuse, fraud, and security incidents.
- Measure aggregate usage to improve reliability and performance.
- Send service-critical notices (e.g., security alerts, terms changes). Marketing emails are only sent with your consent and always include an unsubscribe option.
- Comply with legal obligations.
4. Legal bases for processing (GDPR)
| Purpose | Legal basis |
| Providing and operating the Service | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, error monitoring | Legitimate interests (Art. 6(1)(f)) |
| Optional analytics, marketing emails | Consent (Art. 6(1)(a)) |
| Tax, accounting, legal compliance | Legal obligation (Art. 6(1)(c)) |
5. User content & artifacts
“User Content” means the MCP messages, context files, and artifacts you transmit
through or store in the Service. Key points:
- You own your User Content. We claim no rights to it beyond what is necessary to operate the Service.
- We act as a processor for User Content when you use the gateway on behalf of your own users.
- We do not read message payloads except where required to (a) route the request, (b) respond to a security incident, or (c) comply with law.
- Do not send us data you are not permitted to share. You are responsible for having the right to transmit any personal data included in your MCP traffic.
6. Service providers (sub-processors)
We use a limited number of trusted infrastructure providers:
| Provider | Purpose | Data location |
| Cloudflare, Inc. | DNS, CDN, edge compute (Workers/Pages), object storage (R2), database (D1), TLS | Global edge network |
| Payment processor (if enabled) | Billing for paid plans | Determined by the configured payment provider |
| Email provider (if enabled) | Transactional and notification emails | Determined by the configured email provider |
To request the current list of sub-processors, email
[email protected]. Material
changes will be announced by email or on the product changelog when practicable.
7. International data transfers
Our infrastructure operates on a global edge network. If you access the Service
from the European Economic Area (EEA), Switzerland, or the UK, personal data may be
transferred to countries outside your jurisdiction, including the United States.
Where required, such transfers are protected by Standard Contractual Clauses (SCCs)
or other valid transfer mechanisms, and Cloudflare's
data protection commitments apply.
8. Data retention
- Account data — retained while your account is active; deleted within 30 days of account closure upon request.
- Request logs & metadata — retained for up to 30 days for debugging and abuse prevention, then deleted or irreversibly aggregated.
- Stored artifacts — retained until you delete them or your storage limit/expiration policy applies.
- Billing records — retained for the period required by applicable tax law (typically up to 10 years).
9. Security
- All traffic is encrypted in transit via TLS 1.2+ (HTTPS only).
- DNS responses are protected with DNSSEC where supported.
- API access is authenticated with scoped tokens; least-privilege design.
- Stored data is encrypted at rest by our infrastructure provider.
- Despite these measures, no system is 100% secure. Report vulnerabilities responsibly to [email protected].
10. Your rights
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data (“right to be forgotten”).
- Restriction & objection — limit or object to certain processing.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, for consent-based processing.
- Complain — lodge a complaint with your supervisory authority (EEA/UK residents) or applicable regulator.
To exercise any right, email [email protected].
We will respond within 30 days. We may request verification of your identity.
California residents (CCPA/CPRA): we do not sell or share personal
information for cross-context behavioral advertising. You may exercise the rights
listed above; we do not discriminate based on the exercise of privacy rights.
11. Cookies & analytics
- Essential cookies — strictly necessary for authentication and session security. No consent required.
- Analytics — we use privacy-friendly, aggregate analytics, including Cloudflare Web Analytics, that do not rely on third-party advertising trackers.
12. Children's privacy
The Service is intended for developers and businesses and is not directed at
children under 16 (or the age of digital consent in your jurisdiction). We do not
knowingly collect personal data from children. If you believe a child has provided
us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Material changes will be announced
by email or on the product changelog at least 14 days before taking effect. The
“Last updated” date at the top of this page always reflects the current version.
Continued use of the Service after changes take effect constitutes acceptance.