Effective September 11, 2026
This Privacy Policy explains what information MCPifex collects, how we use and share it, and the choices you have. MCPifex is operated by Amdose (“MCPifex”, “we”, “us”). It applies to the website at mcpifex.com, the portal at portal.mcpifex.com, and the MCP gateway at mcpifex.com/mcp (together, the “Service”).
1. Information we collect
Account information
When you create an account, we collect your name, email address and password. If you sign in with Google or Apple, we receive the basic profile information they share, such as your name, email address and profile picture. Our authentication provider, Clerk, stores and verifies this information for us. If you create or join a team, we also process the team name, its members and invitations.
Configuration you provide
To host an MCP server for you, we store the connection settings you enter for it. For example, a database server needs a host, port, database name, username and password. We need these values to start and run the server on your behalf. Fields marked as secret are hidden in the portal after you save them.
API keys
We store a hash and a short prefix of each API key, not the key itself. The full key is shown to you only once, when it is created.
Usage records
When an AI client calls a tool through the gateway, we record which instance, API key and tool were used, whether the call succeeded, how long it took, and when it happened. If a call fails, we may store the error message returned by the MCP server, which can include part of that server’s output. We also keep daily counts of calls and errors for each API key.
The gateway relays tool arguments and results between your AI client and the MCP server. It does not store the arguments you send or the results of successful calls. Our servers keep diagnostic logs, which can include error output from MCP servers, to operate and troubleshoot the Service.
Billing information
Payments are handled by Paddle, which acts as our merchant of record. Paddle collects your payment details directly, and we never receive your full card number. We store subscription information we receive from Paddle, such as your plan, billing interval, subscription status, and customer and transaction identifiers. We also store the event records Paddle sends us, which can include your name, email address and billing details.
Website analytics and technical data
The mcpifex.com website uses Umami to measure page visits, and the portal uses Vercel Web Analytics. Both are designed to work without advertising cookies. The website loads its fonts from Google Fonts. Our hosting, security and infrastructure providers may process your IP address, browser type and similar request information when you use the Service, for example in server logs.
Messages you send us
If you contact us, we keep your message and our reply so we can help you.
2. Google user data
Some MCP servers need access to your Google account, for example to read Google Search Console data. When you choose to connect a Google account to such a server, MCPifex receives OAuth tokens for the permissions you approve, along with basic account details such as your email address.
- We use this data only to run the tools you enable for that server, when your AI client requests them, and to show you which Google account is connected.
- We do not sell Google user data, use it for advertising, or use it to train artificial intelligence or machine learning models.
- We do not transfer it to others except as needed to provide the features you use, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not allow people to read it unless you ask us to for support, it is necessary for security purposes or to comply with applicable law, or it has been aggregated and anonymized for internal operations.
MCPifex’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can remove MCPifex’s access to your Google account at any time from your Google Account permissions page.
3. How we use information
- To provide the Service: signing you in, running hosted MCP servers with your configuration, routing tool calls, and enforcing the tools you have enabled.
- To show you instance status, usage and billing information in the portal.
- To process subscriptions and apply plan limits.
- To secure the Service, prevent abuse, and investigate and fix problems.
- To send you account messages, such as verification codes and team invitations.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not use your configuration, tool calls or connected data for advertising or to train artificial intelligence models.
4. How information is shared
We share information only as described here.
Service providers
- Clerk provides sign-in, account and team management. Clerk uses Cloudflare Turnstile to block automated sign-ups.
- Paddle processes payments, taxes and invoices as our merchant of record.
- Vercel hosts the portal and provides portal analytics.
- Amazon Web Services hosts our database in the European Union.
- Akamai (Linode) hosts the website and the MCP gateway.
- Umami provides website analytics.
- Google serves website fonts, and provides Google sign-in and Google account connections if you use them.
- Apple provides Apple sign-in if you use it.
Systems you connect
When you run an MCP server through MCPifex, the gateway gives that server the configuration you entered, and your tool calls reach the systems it connects to, such as your database or a third-party service. Those systems are operated by you or by third parties under their own terms and privacy policies.
Legal and business reasons
We may disclose information if required by law, to protect the rights, property or safety of MCPifex, our users or others, or in connection with a merger, acquisition or sale of assets, in which case this policy will continue to apply to your information.
5. Storage and security
Information travels between you and the Service over encrypted HTTPS connections. Our database is hosted in the European Union. Some of our providers are based in, or process data in, the United States and other countries, so your information may be processed outside the country where you live.
We limit access to production systems to the people who operate MCPifex, store API keys only as hashes, and hide secret configuration fields in the portal. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We recommend giving MCPifex credentials with the least access needed, such as a read-only database user.
6. Data retention
We keep account, configuration, usage and billing records while your account is active and as long as needed to provide the Service, resolve disputes, and meet legal, tax and accounting obligations. Deleting an instance or revoking an API key stops it from being used, but the related records may be kept. To ask us to permanently delete your data, contact us at the address below.
7. Your choices and rights
- You can update your account details, delete instances and revoke API keys in the portal.
- You can ask us to access, correct, export or delete your personal information by emailing us.
- Depending on where you live, for example in the European Economic Area, the United Kingdom or California, you may also have the right to object to or restrict certain processing, and to complain to your local data protection authority.
We will respond within a reasonable time and may need to verify your identity first.
8. Cookies
The portal uses cookies from Clerk that are necessary to keep you signed in. Paddle may set cookies during checkout. We do not use advertising cookies.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we do, we will change the effective date above. If a change is significant, we will give additional notice, for example by email or in the portal.
11. Contact
MCPifex is operated by Amdose. For privacy questions or requests, email support@amdose.com.