Privacy Policy
Effective 29 August 2026 · How Nooticr handles data for the MCP server at mcp.nooticr.com.
The short version
- We store your account identity, your credit balance, and a log of which tools you called and when.
- We do not store the content of the posts your assistant retrieves.
- We do not sell your data, and we do not use it to train models.
- We never connect to your social accounts and cannot act on them.
What we collect
| Data | Why | Kept for |
|---|---|---|
| Account identity (email, display name, user id) | To identify your account and its balance | Until you delete the account |
| OAuth tokens issued to your AI client | To authenticate calls from that client | Until expiry or revocation |
| Credit ledger (tool name, credits, timestamp) | Billing, refunds, and your usage dashboard | Retained as financial records |
| URLs and search terms you pass to tools | Processed to fulfil the request | Not retained after the call completes |
| Operational logs (timestamps, status codes, errors) | Reliability and abuse prevention | Up to 30 days |
| Payment records (amount, date, Stripe reference) | Accounting and dispute handling | As required by tax law |
What we do not collect
- Your card number, CVC or bank details — Stripe handles payment and we only receive a reference.
- The bodies of your AI conversations. We see the tool call, not the chat around it.
- Credentials for any social network. The service reads public data only and has no access to your social accounts.
- The retrieved posts themselves. Media is streamed through to your assistant and cached only transiently to make it viewable.
Retrieved content
When a tool fetches a post, media may pass through an Nooticr proxy so it can be displayed inside your assistant. These copies are short-lived, serve only your request, and are not indexed, mined or used for any other purpose.
Retrieved posts may contain personal data about the people who published them. We process it only to answer your request. You are responsible for using it lawfully — see the acceptable use section of our Terms.
Who we share with
We share the minimum necessary with processors who run the service on our behalf:
- Cloudflare — hosting and edge delivery of this server.
- Stripe — payment processing.
- Data providers — to retrieve public posts from the supported networks.
- AI providers — for the analysis tools, to interpret the content you asked about.
We do not sell personal data, and we do not share it for advertising.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Email support@nooticr.com and we will respond within 30 days.
You can revoke your assistant's access at any time by disconnecting the connector in that client, which invalidates its tokens immediately.
Security
Traffic is encrypted in transit. Access tokens are scoped and expiring, and authentication uses OAuth 2.1 with PKCE so no long-lived secret is pasted into a chat window. Access to production data is limited to personnel who need it.
International transfers
The service runs on distributed infrastructure and data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
Children
The service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes
We may update this policy. The effective date above will change, and material changes will be announced before they take effect.
Contact
Privacy questions or requests: support@nooticr.com.
See also our Terms of Use.