Effective 2026-10-10
Privacy
1. Who we are
Derek D. Kim operates mcpw: the website at mcpw.dev, the dashboard at app.mcpw.dev and the gateway at mcp.mcpw.dev. This policy says what we store when you use them, why, and how to get rid of it.
2. What we store
- Your account: the user id Clerk assigns you and your email address, in our database. Clerk holds your sign-in profile, such as your name and avatar, on our behalf.
- The servers you add: their URL, name, description and the list of tools the gateway fetched from them.
- Your credentials for those servers, encrypted so that only the gateway process can read them.
- Your profiles, their aliases and allowlists, and the access tokens you mint, which we store as hashes.
- Activity: for each tool call, the tool name, when it started, how long it took, its status and, when it failed, a short gateway error message. Kept for thirty days.
- An append-only audit log of account actions: what happened, when, and from which IP address.
- Short-lived operational rows: in-flight connection attempts for ten minutes, and rate-limit counters keyed by your user id or IP address for up to one day.
3. What we do not store
The arguments of your tool calls and the results that come back: they pass through the gateway and are not written down. Your sign-in password: Clerk handles sign-in, and Google sign-in gives us only your profile. Payment details: there is nothing to pay for during the soft launch.
4. How we use it
To run the gateway for you: when a client you installed calls a tool, the gateway presents your credential to the server you connected. To show you your own activity and the state of your connections. To enforce plan limits and protect the service from abuse. To contact you about the service, for example about a security issue or a change to these terms. We do not advertise, sell data, or run analytics on these pages.
5. Who else processes it
- Clerk: sign-in and sessions.
- Vercel: hosting of the dashboard and this website.
- Railway: the gateway and the database, in the US West region.
- Cloudflare: DNS, the nightly encrypted database backup kept in Western North America for thirty days, and forwarding of the contact address.
- Google: only when you sign in with Google.
- The MCP servers you connect: they receive your tool calls from the gateway under their own terms.
mcpw's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The only Google scopes requested are openid, email and profile.
6. Retention and deletion
Account data stays for as long as the account exists; activity for thirty days; backups for thirty days. Deleting your account in Settings removes your data, revokes your gateway tokens, and asks each connected service to revoke the access you granted. The Clerk account is deleted with it. Backups age out within thirty days.
7. Security
Every connection uses TLS. Credentials are sealed with HPKE to a key held only by the gateway process; the dashboard holds the public half only, and encryption keys are rotated.
8. Your rights
You can export your configuration and delete your account from Settings at any time. If you live in the EEA, the UK or California you also have rights of access, correction, deletion, portability and objection; write to us and we will act on them.
9. Children
mcpw is not for anyone under sixteen.
10. Changes
The date at the top is when this version took effect. A material change is announced on the sign-in page for thirty days.