A little storage.
A clear choice.

What MCPBinder stores in your browser, how optional measurement works, and how to manage your preferences.

On this page

Essential storage

Authentication and security cookies support sign-in and requested account features. The current authentication session lifetime is seven days, with renewal during use. Session and temporary verification cookies may have different lifetimes.

Browser storage remembers your selected light, dark, or system theme until you change it or clear storage. The mcpbinder.cookie-preferences local storage entry and mcpbinder_privacy cookie store your analytics and advertising choices, notice version, configuration status, and choice time for up to 180 days. They remember your choice and are not advertising identifiers. The essential mcpbinder_privacy_receipt cookie holds a random reference for your privacy-choice records for up to 180 days; it is not shared with analytics or advertising providers. Choice records include the notice text and version, server time, available IP/browser details, and your account reference when signed in. Request details are encrypted and expire after 90 days; choice receipts expire after 365 days, subject to documented legal holds.

Account signup source

The signed, HttpOnly mcpbinder_signup_source cookie records the first public landing page, available external referring domain, allowed campaign labels, and arrival time for up to 30 days. This first-party account attribution is always enabled, independently of optional analytics and advertising choices. It is cleared after successful sign-in. At signup, the source is stored with your account, visible to authorized administrators, included in your personal export, and removed during account deletion. Full referring URLs, arbitrary query parameters, fragments, and ad click identifiers are excluded. This account record is not sent to analytics or advertising providers.

Optional analytics and advertising measurement

When configured and you accept analytics, PostHog in the US helps measure public-page visits, signup and onboarding milestones, page performance, and technical browser errors. A random identifier in mcpbinder.analytics-session session storage groups events within a tab for up to 30 minutes, then is replaced on a later event. It is removed when analytics is turned off; session storage ends when the tab is closed. It does not identify an account or email address.

Public analytics includes the page path, time, and optional identifier. Signup and onboarding use a separate random flow cookie lasting up to one day. Technical errors and performance measurements use anonymous event IDs and route categories, without workspace names or account identities. Error messages and private content are removed. Basic public analytics excludes form contents, query strings, fragments, and referrers, and does not forward your IP address or browser headers. Campaign labels and ad click identifiers are handled separately as described below. Session recording, person profiles, and automatic interaction capture are disabled. Google Analytics is not used.

Anonymous server error reports and aggregate scheduled-worker health measurements help us operate the service independently of optional browser analytics. They contain technical code locations and timing, with no account identities, request contents, or raw error messages.

When campaign measurement is enabled and you allow analytics or advertising, the HttpOnly mcpbinder_campaign cookie holds a random first-party identifier for up to 30 days. We retain allowlisted campaign labels (source, medium, campaign, campaign ID, creative, and keyword slugs), public landing paths, and first and last campaign touches. Full URLs, arbitrary query parameters, fragments, form contents, and referrers are excluded. Do not put personal information in campaign labels.

Within our database, campaign records can be linked to your account to measure confirmed signup, onboarding, meaningful task activity, successful agent use, payments, refunds, and return activity after seven days. With analytics consent, PostHog receives these outcomes with a random campaign identifier and campaign labels, including amounts and currencies for payment events. We do not send account IDs, email addresses, workspace names, work content, or ad click identifiers to PostHog. These first-party campaign records are retained for up to 90 days, and ad click identifiers are encrypted and removed within 30 days. The browser identifier expires after 30 days; linked account outcomes can be measured during the 90-day record period while consent remains valid.

Advertising is a separate choice. Cookie settings names the currently configured destinations among Google Ads, Meta, and Reddit; unavailable destinations remain off. With advertising consent, we may retain the destination’s ad click identifier and send confirmed registration, activation, agent-use, and first-payment events, their time, a deduplication identifier, a public source-page URL, and payment amount/currency where applicable. Reporting uses server-to-server APIs. We do not load advertising pixels, upload customer lists, send email or hashed-email matching data, or build remarketing audiences in this integration. Google conversion uploads mark ad personalization denied. Each provider processes conversion information under its own terms and privacy policy.

Optional reporting starts only after a current affirmative choice. Enabling campaign measurement, changing configured advertising accounts or destinations, or changing the consent notice requires a fresh choice. Global Privacy Control keeps advertising off; Do Not Track disables analytics. Withdrawal stops the affected collection and cancels queued reporting once our server receives the change. Rejecting both categories removes the linked first-party campaign records. When you are signed in, withdrawal also applies to campaign records linked to that account. Clearing a browser alone does not notify our server; sign in and use Cookie settings or contact support to withdraw linked measurement. Previously delivered events cannot be recalled through cookie settings; contact support@mcpbinder.com for deletion assistance. Failed deliveries may be retried for up to 47 hours, with consent checked before delivery.

You can change your mind

Use Cookie settings below to reject optional use, accept it, or choose categories. Essential features work regardless of optional choices. Analytics starts only after affirmative consent and stops when that consent is withdrawn or expires. Previously received events cannot be recalled by changing browser settings. If analytics was unconfigured when you chose, we ask again after it becomes available.

A browser Global Privacy Control signal keeps advertising off, including when Accept optional is selected. Do Not Track disables analytics. Choices apply to this browser; a different browser or cleared storage may prompt you again. Analytics stays off if consent cannot be saved in both browser storage and its consent cookie.

Questions or requests

MCPBinder is operated by Reed Stories, LLC in Colorado, USA. Contact support@mcpbinder.com about browser storage or your privacy choices.

Read the privacy notice