Skip to content
MCPBytes

Legal

Privacy Policy

What we collect when you use MCPBytes, why, how long we keep it, who processes it, and your choices.

Effective September 19, 2026

Who we are

MCPBytes is operated by King Of The Hour, LLC ("we", "us"). This policy covers mcpbytes.com, the console at console.mcpbytes.com, and the API and MCP server at api.mcpbytes.com. For questions or requests, write to support@mcpbytes.com.

What we collect

  • Account information from GitHub. When you sign in, GitHub tells us your GitHub user ID, username and email address (your public one, or else your primary verified one). We ask GitHub only for read access to your profile and email addresses. We never see your GitHub password, and we do not keep the access token GitHub issues.
  • Your email address, if you sign in by email. We send a one-time sign-in link to the address you enter, and the address identifies your account. For each link we keep, for up to 2 days, the address, a hash of the link, and a keyed hash of the IP address that asked for it (to limit how many emails can be requested). We send no other email unless it concerns your account or the Service.
  • Purchases. Payments are made on pages hosted by Stripe. We never see or store your card number. We keep your Stripe customer ID, what you bought and when, the state of a monthly bundle, and a record that you accepted the terms shown at checkout. Stripe collects your payment details, billing address and, if you give it, your tax ID, under its own privacy policy.
  • API keys. We store a cryptographic hash of each key, never the key itself, plus its name, first characters, and when it was created, last used and revoked.
  • Sign-in sessions. Tokens for the console and for the MCP clients you authorize. They are stored hashed, with their details encrypted.
  • Your content. The files you upload or ask us to fetch from a URL (such as 3D models and PDFs), and the output files we produce from them.
  • Job records. For each job: the input file name and size, the options, status, timestamps, and a summary of the result (such as the part count and the list of output files).
  • Technical data. Your IP address, user agent and request details, which our hosting providers process to deliver and protect the Service (for example rate limiting and abuse prevention), and our service logs.

We do not use analytics, advertising or tracking cookies, on the website or in the console.

How we use it

  • to run the Service: sign you in, process your jobs and deliver the results;
  • to apply usage limits and keep the Service secure, including detecting and preventing abuse;
  • to troubleshoot and keep the Service reliable;
  • to contact you about your account or important changes to the Service;
  • to comply with the law and enforce our Terms of Service.

We do not sell your personal information or share it for targeted advertising. We do not use your content to train AI models.

How long we keep it

Uploaded input files
Deleted within 2 days.
Output files
Available for 24 hours, then deleted within a day. Deleted at once when you delete the job.
Job records
While your account exists. Records of jobs you delete are erased within 2 days.
API keys (hash and details)
While your account exists, including revoked keys.
Account information
Until you ask us to delete your account.
Credit and purchase records
While your account exists, and afterwards for as long as tax and accounting law requires.
Sign-in link records
Deleted within 2 days.
Service logs
Up to 30 days.

We may keep information longer when the law requires it, or to resolve disputes and investigate abuse.

Who processes it

We use these service providers, which process data on our behalf:

  • Cloudflare: hosting of the website, console and API, network and security services, storage of account data, job records and files, sending sign-in emails, and email forwarding for support@mcpbytes.com;
  • Amazon Web Services: processing of jobs and their logs, in the US West (Oregon) region;
  • Stripe (including its Link service, the merchant of record for purchases): payments, invoices, taxes and fraud prevention, when you buy credits;
  • GitHub: sign-in.

Our data is stored and processed in the United States. Cloudflare's network handles requests in data centers around the world. We also disclose information when the law requires it, to protect the rights, property or safety of our users, us or others, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to it.

Security

Traffic is encrypted with TLS. API keys and tokens are stored only as hashes, and download links are signed and expire. Each job runs in an isolated environment, and files are deleted soon after use. No system is perfectly secure, but we work to protect your information.

Your choices and rights

  • Delete a job and its files at any time, in the console or with the API.
  • Revoke API keys in the console, and sign out to end a session.
  • Remove MCPBytes' access to your GitHub account in GitHub's settings, under Applications.
  • Ask us for a copy of your information, or to correct or delete it, including deleting your account, by writing to support@mcpbytes.com. We verify requests using the email address on your GitHub account.

Depending on where you live, for example California and other US states, the European Economic Area or the United Kingdom, you may have more rights: to know, access, correct, delete or port your information, and to object to or restrict some processing. We honor these rights as the law requires, and we will not discriminate against you for using them. You may use an authorized agent, and you can appeal a decision by replying to our answer.

If you are in the EEA or the UK: we process your information to provide the Service you asked for (contract), for our legitimate interests in securing and improving the Service, and to meet legal obligations. Your information is transferred to the United States. You may complain to your local data protection authority.

Cookies and browser storage

The website sets no cookies. The console keeps your sign-in session, and a short-lived sign-in state, in your browser's local storage. During sign-in, api.mcpbytes.com sets one cookie that secures the sign-in flow and expires after at most 15 minutes. GitHub sets its own cookies on github.com, and Stripe sets its own on its checkout and billing pages.

Children

The Service is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

Changes and contact

We may update this policy. The effective date at the top shows the current version. For material changes, we will give notice on this site or in the console before they take effect. Questions and requests: support@mcpbytes.com.