Privacy Policy

Last updated 11 August 2026

This explains what personal data Dynamics MCP collects, why, how long it is kept, and what you can do about it. It is written to match what the software actually does rather than to cover every eventuality.

1.Who is responsible

Dynamics MCP is the data controller for personal data processed through Dynamics MCP. For any privacy question or request, contact support@dynamics-mcp.com.

2.What we collect and why

Everything we hold is listed below. We do not collect special category data (health, biometrics, political or religious views and so on), and we do not ask for it. Please do not put it into the service.

WhatWhyLawful basisKept for
Name and email addressTo create and identify your account, and to contact you about the service.ContractFor as long as the account exists, then deleted.
PasswordTo sign you in. Stored only as a salted hash, so we never hold the password itself and cannot recover it.ContractFor as long as the account exists.
IP address and browser user-agent, recorded at sign-inSecurity (spotting unusual sign-ins) and coarse statistics about where the service is used.Legitimate interestsFor as long as the account exists, then deleted with it.
API key recordsTo authenticate your agent's requests. Only a SHA-256 hash of each key is stored, never the key itself.ContractFor as long as the account exists.
Usage counts: number of tool calls, when a key was last usedTo enforce your plan's limits, bill correctly, and understand how the product is used.ContractFor as long as the account exists.
Content you create through the service: project, table and field namesIt is the service. We store it so you can retrieve it.ContractUntil you delete it, or the account is closed.
Marketing preferenceTo know whether you agreed to receive product email, and when.ConsentUntil withdrawn, plus a record of the withdrawal.

“Legitimate interests” above means we have balanced our interest in running and securing the service against your privacy, and concluded the processing is proportionate. You can object; see section 6.

3.Marketing email

We only send product and marketing email if you ticked the optional box at sign-up, or opted in later. That box is separate from accepting the Terms, is not pre-ticked, and signing up does not require it.

You can withdraw consent at any time, using the unsubscribe link in any such email or by emailing support@dynamics-mcp.com. Withdrawing does not affect email we need to send you about your account, such as billing notices, security alerts and service changes, which we send on the basis of our contract with you, not consent.

4.Who else sees it

We do not sell personal data, and we do not share it with third parties for their own marketing. We use the following processors to run the service, each bound to act only on our instructions:

  • Google Cloud (Cloud Run): Hosting and serving the application (United States)
  • Neon: Managed PostgreSQL database (United States)
  • Paddle: Payment processing and merchant of record (once payments are enabled) (United Kingdom / European Union)
  • Resend: Sending account email: sign-in codes, password resets and service notices (United States)

We may also disclose data where the law requires it, or to establish or defend legal claims.

5.Where it is stored

The application and database are hosted in the United States. If you are in the UK, EEA or another country with transfer restrictions, that means your data is transferred outside your region. Those transfers rely on the providers' standard contractual clauses and equivalent safeguards.

6.Your rights

Depending on where you live, you may have the right to: get a copy of your data; correct it; delete it; restrict or object to how we use it; receive it in a portable format; and withdraw consent you previously gave.

Exercise any of these by emailing support@dynamics-mcp.com. We will respond within one month. You can also complain to the data protection authority where you live. In the UK that is the ICO, and in the EEA the supervisory authority in your country. We are established in Lebanon, where the competent authority under the applicable data protection law will hear complaints.

You can delete most of what you create, including projects and tables, from your dashboard at any time.

7.Security

Passwords are stored only as salted hashes. API keys are never stored in readable form, only a SHA-256 hash, which is what we compare against on each request, so a key you lose cannot be recovered by us or by anyone who obtains our database. All traffic is encrypted in transit. Access to production data is limited to what is needed to run the service.

No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority as the law requires.

8.Cookies

We set one cookie, to keep you signed in. It is strictly necessary for the service to work, so it does not require consent and there is no cookie banner. We do not use advertising or third-party tracking cookies.

9.Children

The service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.

10.Changes

If we change this policy materially we will tell you by email or in the product before the change takes effect. The version and date at the top always reflect the current text.

See also our Terms & Conditions and Refund Policy.