Privacy Policy

Last updated: June 19, 2026

This Privacy Policy explains how INFORSERVICES SERVIÇOS DE INFORMÁTICA LTDA (CNPJ 21.110.198/0001-36, Itapevi/SP, Brazil — “we”, “us”, “our”) collects, uses, shares, and protects personal data in connection with the mcppipe service at https://mcppipe.dev (the “Service”).

We act as the data controller (LGPD) / controller (GDPR) for the personal data described below. This policy is written to comply with the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and, where applicable, the EU General Data Protection Regulation (GDPR).

Data Protection Officer / Encarregado: privacy@mcppipe.dev


1. Who this applies to

This policy applies to visitors of our website, account holders, and people whose personal data we process when our customers use the Service. The applicable data-protection law depends on where you are located — for example, the GDPR applies to users in the European Economic Area regardless of where we operate.

2. Data we collect

2.1 Data you provide

  • Account data: email address, a securely hashed password, and an account name/identifier (slug).
  • Single sign-on data: if you sign in with Google or GitHub, we receive basic profile information (such as your email and provider account ID) from that provider.
  • Tunnel configuration: subdomains, upstream targets, and the controls you configure (authentication mode, tool policy, redaction rules, rate limits, capture mode).
  • Support communications: the content of messages you send us.

2.2 Data generated by using the Service

  • Traffic metadata (observability mode): for tunnels in observability mode, we process metadata about MCP requests and responses — such as method, tool name, message identifier, status, and latency — and may store request/response payloads truncated to a maximum of 64 KB to power the Inspector and live tail.
  • Zero-knowledge mode: for tunnels you set to zero-knowledge mode, the edge only relays bytes and does not read, parse, or store your payloads or their metadata. We process only the volume of traffic for billing.
  • Technical and log data: IP address, user agent, and timestamps. We store IP addresses at full precision in our logs and audit records for security and abuse prevention; whenever an IP address is displayed back to you in the dashboard, it is masked (to a /24 network for IPv4 and /48 for IPv6) to reduce identifiability.
  • Usage and billing data: plan, quota consumption (bandwidth, tool calls), subscription status, and subscription/customer identifiers from our payment provider. We do not store full payment card numbers.
  • Audit log: security-relevant events (such as sign-in, key rotation, configuration changes, and account deletion), retained for accountability.

2.3 Cookies

We use a small number of strictly necessary cookies, including a secure, HttpOnly session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. See Section 9.

PurposeExamplesLegal basis (GDPR) / LGPD basis
Provide the ServiceAuthenticate you, route Your Traffic, enforce the controls you setPerformance of a contract
BillingManage subscriptions, enforce quotasPerformance of a contract
Security and abuse preventionRate limiting, fraud/abuse detection, audit logging, tunnel suspensionLegitimate interests / compliance with legal obligation
Service communicationsEmail verification, password reset, sign-in alerts, billing noticesPerformance of a contract / legitimate interests
Improve and maintainError monitoring, diagnosticsLegitimate interests
Legal complianceRespond to lawful requests, keep required recordsLegal obligation

Under the LGPD, our processing relies on the corresponding legal bases, including execution of a contract (Art. 7, V), legitimate interests (Art. 7, IX), and compliance with a legal or regulatory obligation (Art. 7, II).

4. Sharing and subprocessors

We do not sell your personal data. We share data with the following categories of subprocessors solely to operate the Service:

SubprocessorPurposeLocation
Paddle (Paddle.com Market Ltd)Payments and Merchant of RecordUnited Kingdom / United States
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited States
Functional Software, Inc. (Sentry) (or a self-hosted equivalent)Error monitoringUnited States
Google LLCSign-in with GoogleUnited States
GitHub, Inc.Sign-in with GitHubUnited States
Hostinger International Ltd.Server infrastructure hostingUnited States
Cloudflare, Inc.DNS, network ingress, dashboard hosting, backup storage, and email routingUnited States
Internet Security Research Group (Let’s Encrypt)TLS certificate issuanceUnited States

We may also disclose data when required by law, to enforce our Terms, or to protect the rights, safety, or property of us, our users, or the public.

5. International data transfers

We are based in Brazil, our primary server infrastructure is located in the United States, and some subprocessors are located in the United States or other countries. Where we transfer personal data internationally, we rely on appropriate safeguards permitted by the LGPD and GDPR (such as standard contractual clauses or the recipient’s own compliance commitments). By using the Service, you understand that your data may be processed in countries other than your own.

6. Retention

We keep personal data only as long as necessary for the purposes above:

  • Account data — for the life of your account. When you delete your account, the data is removed from our live systems immediately; copies in backups are rotated out within up to 30 days.
  • Traffic metadata and stored payloads (observability mode) — automatically deleted after a window that depends on your plan: currently 24 hours on Free, 30 days on Pro, and 90 days on Team.
  • Audit logs — retained for as long as necessary for security, accountability, and to meet legal obligations.
  • Billing/financial records — for as long as required by applicable tax and commercial law (in Brazil, typically up to 5 years).
  • Backups — rotated out within a limited window (default: up to 30 days).

The specific windows above are our current defaults and may be adjusted; we will keep this policy consistent with our actual practice.

7. Security

We use technical and organizational measures appropriate to the risk, including TLS encryption in transit, password hashing (Argon2id), scoped credentials and tokens, IP masking when addresses are displayed back to you, rate limiting, audit logging, and the option of a zero-knowledge mode in which we do not read your traffic. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you and obtain a copy;
  • correct inaccurate or incomplete data;
  • delete your data (right to erasure / right to be forgotten);
  • object to or restrict certain processing;
  • portability of your data;
  • withdraw consent where processing is based on consent;
  • information about with whom we share data; and
  • lodge a complaint with a supervisory authority — in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); in the EEA, your local data-protection authority.

To exercise any right, email privacy@mcppipe.dev. You can also delete most of your data yourself from the account settings. We will respond within the timeframe required by applicable law.

9. Cookies

We use only strictly necessary cookies, primarily a secure, HttpOnly session cookie for authentication. Because these cookies are essential to provide the Service you request, they do not require consent under most frameworks. We do not use cookies for advertising or cross-site tracking.

10. Children

The Service is not directed to children. You must be at least 18 years old to use it, and we do not knowingly collect personal data from anyone under that age (or under the minimum age of digital consent in your country). If you believe a child has provided us data, contact privacy@mcppipe.dev and we will delete it.

11. Changes to this policy

We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide reasonable notice. Your continued use after the changes take effect constitutes acceptance.

12. Contact

Controller: INFORSERVICES SERVIÇOS DE INFORMÁTICA LTDA — CNPJ 21.110.198/0001-36 — Itapevi/SP, Brazil Privacy / DPO (Encarregado): privacy@mcppipe.dev