Legal

Privacy Policy

Effective 29 August 2026 · How Nooticr handles data for the MCP server at mcp.nooticr.com.

The short version

  • We store your account identity, your credit balance, and a log of which tools you called and when.
  • We do not store the content of the posts your assistant retrieves.
  • We do not sell your data, and we do not use it to train models.
  • We never connect to your social accounts and cannot act on them.

What we collect

DataWhyKept for
Account identity (email, display name, user id)To identify your account and its balanceUntil you delete the account
OAuth tokens issued to your AI clientTo authenticate calls from that clientUntil expiry or revocation
Credit ledger (tool name, credits, timestamp)Billing, refunds, and your usage dashboardRetained as financial records
URLs and search terms you pass to toolsProcessed to fulfil the requestNot retained after the call completes
Operational logs (timestamps, status codes, errors)Reliability and abuse preventionUp to 30 days
Payment records (amount, date, Stripe reference)Accounting and dispute handlingAs required by tax law

What we do not collect

  • Your card number, CVC or bank details — Stripe handles payment and we only receive a reference.
  • The bodies of your AI conversations. We see the tool call, not the chat around it.
  • Credentials for any social network. The service reads public data only and has no access to your social accounts.
  • The retrieved posts themselves. Media is streamed through to your assistant and cached only transiently to make it viewable.

Retrieved content

When a tool fetches a post, media may pass through an Nooticr proxy so it can be displayed inside your assistant. These copies are short-lived, serve only your request, and are not indexed, mined or used for any other purpose.

Retrieved posts may contain personal data about the people who published them. We process it only to answer your request. You are responsible for using it lawfully — see the acceptable use section of our Terms.

Who we share with

We share the minimum necessary with processors who run the service on our behalf:

  • Cloudflare — hosting and edge delivery of this server.
  • Stripe — payment processing.
  • Data providers — to retrieve public posts from the supported networks.
  • AI providers — for the analysis tools, to interpret the content you asked about.

We do not sell personal data, and we do not share it for advertising.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Email support@nooticr.com and we will respond within 30 days.

You can revoke your assistant's access at any time by disconnecting the connector in that client, which invalidates its tokens immediately.

Security

Traffic is encrypted in transit. Access tokens are scoped and expiring, and authentication uses OAuth 2.1 with PKCE so no long-lived secret is pasted into a chat window. Access to production data is limited to personnel who need it.

International transfers

The service runs on distributed infrastructure and data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

Children

The service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

Changes

We may update this policy. The effective date above will change, and material changes will be announced before they take effect.

Contact

Privacy questions or requests: support@nooticr.com.

See also our Terms of Use.