Privacy Policy

Effective date: September 21, 2026

1. Who we are

KumoMCP is a cloud Model Context Protocol (MCP) gateway. It connects the services you choose to AI assistants through a personal MCP URL: Google Search Console and Google Analytics through our own read-only integrations, and any remote MCP server you add from our catalog or bring yourself. This policy explains what data we collect, why, and how you stay in control.

2. Information we collect

We collect only what the service needs to operate:

  • Account data: your email address and, if you sign in with Google, your basic profile (email, name). If you register with a password we store a salted hash, never the password itself.
  • Google OAuth tokens: when you authorize Google access we store the refresh token, encrypted with AES-256-GCM before it reaches our database.
  • Credentials for connected MCP servers: the API key or token you enter for a third-party MCP server (for example GitHub or Sentry) or for a server of your own is encrypted with AES-256-GCM before it reaches our database. It is decrypted only for the moment a request is forwarded to that server, is never shown back to you, and never appears in logs or error messages.
  • Google data accessed on your behalf: Search Console and Analytics data is fetched on demand when your AI assistant calls a tool, is returned to your MCP client, and is not retained as a copy on our servers.
  • Data from connected MCP servers: when your AI assistant calls a tool on a connected server, we forward the request with your credentials and return that server's response to your MCP client. We do not keep a copy of the response. We do store the list of tools each connected server offers (tool names, descriptions and input schemas) so you can choose which ones to expose on an endpoint.
  • Usage logs: tool name, timestamp and endpoint identifier for each MCP call, used for quotas, abuse prevention and debugging. Logs never contain your tokens, your credentials, or data returned by Google or by any connected server.
  • Cookies: session cookies required for sign-in. No advertising or cross-site tracking cookies.
  • Billing data: if you buy a paid plan, checkout is handled by Paddle, our Merchant of Record. Paddle collects your payment and billing details under its own privacy policy; we never see or store your card details. We receive only your Paddle customer ID, plan, subscription status and billing period so we can activate your plan.

3. How we use Google user data (Limited Use)

KumoMCP only requests read-only Google scopes (Search Console and, if you enable it, Google Analytics). We use this access solely to answer the queries you or your AI assistant make through your own MCP endpoint.

KumoMCP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

We do not use Google user data for advertising, do not sell it, do not transfer it to third parties except as necessary to provide the service or comply with law, and do not allow humans to read it except with your consent, for security purposes, or where required by law. We do not use Google user data to train machine-learning models.

4. Third-party MCP servers you connect

Servers you connect from our catalog, and servers you bring yourself, are operated by their own providers (or by you) under their own terms and privacy policies. We act as a proxy: your request is forwarded to the server with the credential you stored, and the server's response is passed back to your MCP client as data. We do not read, interpret or act on that content.

Tools that modify data on a connected server are disabled on every endpoint until you switch them on yourself, one at a time. We recommend creating credentials with read-only permissions wherever the provider supports it. We only connect to servers reachable over public HTTPS; private networks and internal addresses are refused.

5. Data sharing

We do not sell or rent your data. We share data only with the infrastructure providers that run the service (hosting, database, email delivery), with Paddle for payment processing, and with the third-party MCP servers you have chosen to connect (only the requests your own AI assistant makes, sent with your own credentials), each bound by their own terms, or when required by law.

6. Data retention and deletion

You can disconnect Google from your dashboard at any time; this revokes the connection and invalidates the stored token. You can also revoke access from your Google account's security settings. You can remove any connected MCP server from your dashboard at any time; its stored credential and cached tool list are deleted immediately.

To delete your account and all associated data, contact us at [email protected]. We delete account records, encrypted tokens and credentials, connected-server records and endpoint keys; aggregate usage statistics that contain no personal data may be retained.

7. Security

Google OAuth tokens and connected-server credentials are encrypted at rest (AES-256-GCM), traffic is encrypted in transit (TLS), each customer's endpoints and connected servers are isolated from every other tenant, we request the minimum, read-only Google scopes needed for the service to work, and tools that modify data stay off until you enable them.

8. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced on this page with an updated effective date.

9. Contact

Questions about privacy? Email [email protected].