DRAFT — legal review required. Replace every [PLACEHOLDER] and have counsel review before publishing.
Service: Global Database MCP Server (the “Service”).
Provider: [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (“we”, “us”).
Effective date: 2026-06-10.
This policy explains how the Service handles data when accessed by an MCP client (e.g. Claude, ChatGPT) or an integrated application.
Your API key is embedded in short-lived OAuth access-token claims held in server memory only for the session. It is not written to disk by the Service. [CONFIRM after any Redis/persistence change — update this section.]
Tool calls are forwarded to the Global Database API (globaldatabase.com). Your AI client provider (e.g. Anthropic, OpenAI) processes the conversation under its own privacy terms. We do not sell your data.
OAuth tokens expire automatically and are discarded on session end or server restart. Operational logs are retained for [RETENTION PERIOD, e.g. 30 days].
Depending on your jurisdiction (e.g. GDPR), you may request access, correction, or deletion of personal data. Contact us at [PRIVACY CONTACT EMAIL].
We use HTTPS, OAuth 2.1, and least-privilege handling of credentials. No method is 100% secure; use the Service at your discretion.
We may update this policy. Material changes will be posted here with a new effective date.
[PRIVACY CONTACT EMAIL] · [SUPPORT URL]