DRAFT — legal review required. Replace every [PLACEHOLDER] and have counsel review before publishing.

Privacy Policy

Service: Global Database MCP Server (the “Service”).
Provider: [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (“we”, “us”).
Effective date: 2026-06-10.

1. Scope

This policy explains how the Service handles data when accessed by an MCP client (e.g. Claude, ChatGPT) or an integrated application.

2. Data we process

3. How API keys are handled

Your API key is embedded in short-lived OAuth access-token claims held in server memory only for the session. It is not written to disk by the Service. [CONFIRM after any Redis/persistence change — update this section.]

4. Third parties

Tool calls are forwarded to the Global Database API (globaldatabase.com). Your AI client provider (e.g. Anthropic, OpenAI) processes the conversation under its own privacy terms. We do not sell your data.

5. Retention

OAuth tokens expire automatically and are discarded on session end or server restart. Operational logs are retained for [RETENTION PERIOD, e.g. 30 days].

6. Your rights

Depending on your jurisdiction (e.g. GDPR), you may request access, correction, or deletion of personal data. Contact us at [PRIVACY CONTACT EMAIL].

7. Security

We use HTTPS, OAuth 2.1, and least-privilege handling of credentials. No method is 100% secure; use the Service at your discretion.

8. Changes

We may update this policy. Material changes will be posted here with a new effective date.

9. Contact

[PRIVACY CONTACT EMAIL] · [SUPPORT URL]

Terms of Service