Privacy Policy
Last updated: June 19, 2026
This Privacy Policy explains how INFORSERVICES SERVIÇOS DE INFORMÁTICA LTDA (CNPJ 21.110.198/0001-36, Itapevi/SP, Brazil — “we”, “us”, “our”) collects, uses, shares, and protects personal data in connection with the mcppipe service at https://mcppipe.dev (the “Service”).
We act as the data controller (LGPD) / controller (GDPR) for the personal data described below. This policy is written to comply with the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and, where applicable, the EU General Data Protection Regulation (GDPR).
Data Protection Officer / Encarregado: privacy@mcppipe.dev
1. Who this applies to
This policy applies to visitors of our website, account holders, and people whose personal data we process when our customers use the Service. The applicable data-protection law depends on where you are located — for example, the GDPR applies to users in the European Economic Area regardless of where we operate.
2. Data we collect
2.1 Data you provide
- Account data: email address, a securely hashed password, and an account name/identifier (slug).
- Single sign-on data: if you sign in with Google or GitHub, we receive basic profile information (such as your email and provider account ID) from that provider.
- Tunnel configuration: subdomains, upstream targets, and the controls you configure (authentication mode, tool policy, redaction rules, rate limits, capture mode).
- Support communications: the content of messages you send us.
2.2 Data generated by using the Service
- Traffic metadata (observability mode): for tunnels in observability mode, we process metadata about MCP requests and responses — such as method, tool name, message identifier, status, and latency — and may store request/response payloads truncated to a maximum of 64 KB to power the Inspector and live tail.
- Zero-knowledge mode: for tunnels you set to zero-knowledge mode, the edge only relays bytes and does not read, parse, or store your payloads or their metadata. We process only the volume of traffic for billing.
- Technical and log data: IP address, user agent, and timestamps. We store IP addresses at full precision in our logs and audit records for security and abuse prevention; whenever an IP address is displayed back to you in the dashboard, it is masked (to a /24 network for IPv4 and /48 for IPv6) to reduce identifiability.
- Usage and billing data: plan, quota consumption (bandwidth, tool calls), subscription status, and subscription/customer identifiers from our payment provider. We do not store full payment card numbers.
- Audit log: security-relevant events (such as sign-in, key rotation, configuration changes, and account deletion), retained for accountability.
2.3 Cookies
We use a small number of strictly necessary cookies, including a secure, HttpOnly session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. See Section 9.
3. How and why we use data, and our legal bases
| Purpose | Examples | Legal basis (GDPR) / LGPD basis |
|---|---|---|
| Provide the Service | Authenticate you, route Your Traffic, enforce the controls you set | Performance of a contract |
| Billing | Manage subscriptions, enforce quotas | Performance of a contract |
| Security and abuse prevention | Rate limiting, fraud/abuse detection, audit logging, tunnel suspension | Legitimate interests / compliance with legal obligation |
| Service communications | Email verification, password reset, sign-in alerts, billing notices | Performance of a contract / legitimate interests |
| Improve and maintain | Error monitoring, diagnostics | Legitimate interests |
| Legal compliance | Respond to lawful requests, keep required records | Legal obligation |
Under the LGPD, our processing relies on the corresponding legal bases, including execution of a contract (Art. 7, V), legitimate interests (Art. 7, IX), and compliance with a legal or regulatory obligation (Art. 7, II).
4. Sharing and subprocessors
We do not sell your personal data. We share data with the following categories of subprocessors solely to operate the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Paddle (Paddle.com Market Ltd) | Payments and Merchant of Record | United Kingdom / United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States |
| Functional Software, Inc. (Sentry) (or a self-hosted equivalent) | Error monitoring | United States |
| Google LLC | Sign-in with Google | United States |
| GitHub, Inc. | Sign-in with GitHub | United States |
| Hostinger International Ltd. | Server infrastructure hosting | United States |
| Cloudflare, Inc. | DNS, network ingress, dashboard hosting, backup storage, and email routing | United States |
| Internet Security Research Group (Let’s Encrypt) | TLS certificate issuance | United States |
We may also disclose data when required by law, to enforce our Terms, or to protect the rights, safety, or property of us, our users, or the public.
5. International data transfers
We are based in Brazil, our primary server infrastructure is located in the United States, and some subprocessors are located in the United States or other countries. Where we transfer personal data internationally, we rely on appropriate safeguards permitted by the LGPD and GDPR (such as standard contractual clauses or the recipient’s own compliance commitments). By using the Service, you understand that your data may be processed in countries other than your own.
6. Retention
We keep personal data only as long as necessary for the purposes above:
- Account data — for the life of your account. When you delete your account, the data is removed from our live systems immediately; copies in backups are rotated out within up to 30 days.
- Traffic metadata and stored payloads (observability mode) — automatically deleted after a window that depends on your plan: currently 24 hours on Free, 30 days on Pro, and 90 days on Team.
- Audit logs — retained for as long as necessary for security, accountability, and to meet legal obligations.
- Billing/financial records — for as long as required by applicable tax and commercial law (in Brazil, typically up to 5 years).
- Backups — rotated out within a limited window (default: up to 30 days).
The specific windows above are our current defaults and may be adjusted; we will keep this policy consistent with our actual practice.
7. Security
We use technical and organizational measures appropriate to the risk, including TLS encryption in transit, password hashing (Argon2id), scoped credentials and tokens, IP masking when addresses are displayed back to you, rate limiting, audit logging, and the option of a zero-knowledge mode in which we do not read your traffic. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you and obtain a copy;
- correct inaccurate or incomplete data;
- delete your data (right to erasure / right to be forgotten);
- object to or restrict certain processing;
- portability of your data;
- withdraw consent where processing is based on consent;
- information about with whom we share data; and
- lodge a complaint with a supervisory authority — in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); in the EEA, your local data-protection authority.
To exercise any right, email privacy@mcppipe.dev. You can also delete most of your data yourself from the account settings. We will respond within the timeframe required by applicable law.
9. Cookies
We use only strictly necessary cookies, primarily a secure, HttpOnly session cookie for authentication. Because these cookies are essential to provide the Service you request, they do not require consent under most frameworks. We do not use cookies for advertising or cross-site tracking.
10. Children
The Service is not directed to children. You must be at least 18 years old to use it, and we do not knowingly collect personal data from anyone under that age (or under the minimum age of digital consent in your country). If you believe a child has provided us data, contact privacy@mcppipe.dev and we will delete it.
11. Changes to this policy
We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide reasonable notice. Your continued use after the changes take effect constitutes acceptance.
12. Contact
Controller: INFORSERVICES SERVIÇOS DE INFORMÁTICA LTDA — CNPJ 21.110.198/0001-36 — Itapevi/SP, Brazil
Privacy / DPO (Encarregado): privacy@mcppipe.dev