About this version
- Updated contact-form and public-page analytics descriptions for open signup.
- Archived access requests keep their original removal schedule.
Published September 28, 2026. Permanent link to this version.
Effective September 28, 2026. Privacy notice version 2026-09-28-open-signup.
Who we are
MCPBinder is operated by Reed Stories, LLC in Colorado, USA. Austin Howe is its founder and the contact responsible for privacy requests. Reach us at support@mcpbinder.com for privacy questions, legal notices, or an appeal.
MCPBinder is for adults aged 18 or older based in the United States. This notice covers our public website, support communications, accounts, and workspaces. Organizations determine how their members use shared workspace content; their own policies may also apply.
Information we receive
The contact form collects an email address, optional name, request topic, and the message you enter. We also record the request time and the policy version shown. Correspondence sent directly to our support address is handled through our email providers.
Accounts include identity and authentication records, profile details, sessions, workspace memberships, invitations, and recorded terms acceptance. Workspace records include projects, tasks, notes, revisions, schedules, permissions, and uploaded files, sharing links, and resource links or metadata. Passwords are stored as hashes. Passkeys, authenticator settings, and recovery information support account security.
When you authorize a connection, we receive the account identifiers, credentials, file metadata, and content needed for requested operations. Provider credentials and background-job payloads are encrypted in storage. Agent grants record the accounts, workspaces, projects, permissions, and expiry you approve.
Hosting, authentication, email delivery, and security systems process technical information such as timestamps, IP addresses, browser details, errors, and delivery outcomes. The intake rate limit uses a keyed email hash. Administrative history records limited identifiers and actions rather than passwords, tokens, or submitted messages.
How we use information
We use information to reply to support and privacy requests, authenticate users, operate shared workspaces, perform authorized agent/provider actions, deliver requested service messages, prevent abuse, investigate security issues, and maintain the service.
Creating an account or contacting support does not subscribe you to general marketing. General marketing requires a separate appropriate choice.
We do not use customer workspace content to train our own AI models. Providers or agents you connect operate under their own terms and privacy practices. Review those terms before sharing content or authorizing access.
Policy notices and your choices
We notify signed-in users about material privacy updates and ask for agreement to material Terms changes when they take effect. Acknowledging a privacy notice does not give permission for analytics or advertising. Those choices remain separate and can be declined.
To document your choices, we record your account identifier when signed in, the action and choices submitted, a server timestamp, the exact notice or agreement and its version and integrity fingerprint, and a non-reversible session reference. For signed-out cookie choices, an essential first-party mcpbinder_privacy_receipt cookie holds a random reference for up to 180 days; it is used only to record privacy choices and is never sent to advertising or analytics providers.
We also keep encrypted request IP and browser user-agent details when available. IP addresses come from our hosting provider’s trusted request header and may identify a proxy or shared network, rather than a person. They are not identity verification. We do not guess missing historical IP addresses or mark older users as having read a newer notice.
Policy acceptance and acknowledgment records remain while your account exists and are included in your personal export. Optional-choice receipts are kept for up to 365 days. Request IP and browser details are removed after 90 days. Linked records are removed during account deletion, subject to the existing deletion and legal-hold process. Archived policy text contains no account information and remains publicly available in the Policy archive.
Who can receive information
Workspace collaborators, authorized agents, and recipients of sharing links receive information according to workspace permissions and your sharing choices. A public sharing link can make its selected content available to anyone with the link until it expires or is revoked. Direct editing permissions can permit changes without separate approval for every action. Revocation prevents future authorized access; it cannot recall information already received by another party.
Workspace owners and admins can configure outbound task webhooks. For selected task events, MCPBinder sends an event ID, type and time, plus task ID/number, project ID, title, status, workflow status ID, version and update time to the public HTTPS endpoint they choose. Delivery may be repeated or out of order. Revoking a webhook stops queued sends that have not started; it cannot recall a request already in flight or information already received. The endpoint operator handles that information under its own terms and privacy practices. API keys are stored as hashes; webhook URLs and signing secrets are encrypted.
We use Vercel for application hosting and Neon for the database. Transactional email delivery is configured through Twilio SendGrid. PostHog provides optional analytics, browser performance and error measurements, and anonymous operational diagnostics in its US region. Support email is also processed by our mailbox provider. Where configured, Amazon Web Services stores uploaded files. If paid plans are enabled, Stripe processes checkout and payment details; we retain workspace billing identifiers, plan, subscription status, and relevant transaction metadata rather than your full card number. These providers handle information needed to perform their services; contact us for current provider and processing-location details.
Form submissions are kept as encrypted database records. Optional notifications to support@mcpbinder.com contain an internal request link, not the submitted contact details or message. Authorized support operators can open requests after authentication and privilege checks; those reads and management actions are recorded.
Staff access is limited to requested support, security, necessary operations, and legal obligations. Workspace support access requires the applicable authorization and records its use. Application administration does not automatically grant access to every workspace's content.
Google and GitHub may provide sign-in if enabled. Google Drive access is separately authorized for supported operations. Other sites, connected services, and external agents have their own practices. We may disclose necessary information to comply with law, protect legal rights, or complete a business transfer subject to applicable privacy obligations.
Cookies and optional analytics
Essential storage supports sign-in, security, theme preferences, and your privacy choices. When PostHog is configured and you accept analytics, we send public-page visits, a canonical page path, event time, and a random identifier valid for up to 30 minutes within a browser tab.
Basic public-page analytics excludes account identifiers, email addresses, form contents, private workspace and authentication pageviews, query strings, fragments, and referrers. Optional campaign measurement is described separately below. When first-party onboarding analytics is configured and you consent, our database also records allowlisted signup, authentication, project-setup, and connection-setup milestones with a random browser flow identifier. These events contain no account IDs, email addresses, project content, or credentials. They are also forwarded to PostHog when configured; first-party milestone records are deleted after 30 days. The optional flow cookie lasts up to 24 hours and is removed when you withdraw consent. Our server does not forward your IP address or browser headers to PostHog. Person profiles, session recording, and automatic interaction capture are disabled. Our hosting systems still process their own request logs. Google Analytics is not used.
With the same analytics choice, we collect browser technical errors and page performance across the application. These contain error types, code filenames and positions, route categories, release identifiers and performance values. Workspace names, account identities and raw error messages are removed. Each technical event has a fresh anonymous identifier.
Separately, anonymous server error reports and aggregate scheduled-worker health measurements help operate the service. They contain technical code locations, release identifiers, timing and aggregate counts, without account identities, request contents or raw error messages. They do not depend on optional browser analytics. Our server does not forward your IP address or browser headers to PostHog. Person profiles, session recording, and automatic interaction capture are disabled. Hosting systems still process their own request logs. Google Analytics is not used.
Cookie settings let you reject optional use or change your choices. Choices last up to 180 days. Turning off analytics stops new events and removes the optional identifier, but cannot recall events already received. Do Not Track disables analytics; Global Privacy Control keeps advertising off. Choices made before analytics was configured require a new choice before collection starts.
When campaign measurement is enabled and you allow analytics or advertising, the HttpOnly mcpbinder_campaign cookie holds a random first-party identifier for up to 30 days. We retain allowlisted campaign labels (source, medium, campaign, campaign ID, creative, and keyword slugs), public landing paths, and first and last campaign touches. Full URLs, arbitrary query parameters, fragments, form contents, and referrers are excluded. Do not put personal information in campaign labels.
Within our database, campaign records can be linked to your account to measure confirmed signup, onboarding, meaningful task activity, successful agent use, payments, refunds, and return activity after seven days. With analytics consent, PostHog receives these outcomes with a random campaign identifier and campaign labels, including amounts and currencies for payment events. We do not send account IDs, email addresses, workspace names, work content, or ad click identifiers to PostHog. These first-party campaign records are retained for up to 90 days, and ad click identifiers are encrypted and removed within 30 days. The browser identifier expires after 30 days; linked account outcomes can be measured during the 90-day record period while consent remains valid.
Advertising is a separate choice. Cookie settings names the currently configured destinations among Google Ads, Meta, and Reddit; unavailable destinations remain off. With advertising consent, we may retain the destination’s ad click identifier and send confirmed registration, activation, agent-use, and first-payment events, their time, a deduplication identifier, a public source-page URL, and payment amount/currency where applicable. Reporting uses server-to-server APIs. We do not load advertising pixels, upload customer lists, send email or hashed-email matching data, or build remarketing audiences in this integration. Google conversion uploads mark ad personalization denied. Each provider processes conversion information under its own terms and privacy policy.
Optional reporting starts only after a current affirmative choice. Enabling campaign measurement, changing configured advertising accounts or destinations, or changing the consent notice requires a fresh choice. Global Privacy Control keeps advertising off; Do Not Track disables analytics. Withdrawal stops the affected collection and cancels queued reporting once our server receives the change. Rejecting both categories removes the linked first-party campaign records. When you are signed in, withdrawal also applies to campaign records linked to that account. Clearing a browser alone does not notify our server; sign in and use Cookie settings or contact support to withdraw linked measurement. Previously delivered events cannot be recalled through cookie settings; contact support@mcpbinder.com for deletion assistance. Failed deliveries may be retried for up to 47 hours, with consent checked before delivery.
Cookie details and settingsRetention and deletion
We use the following retention schedule. A privacy request can lead to earlier removal. Narrow exceptions apply to an unresolved security incident, a documented legal hold, a legal obligation, or shared workspace records that other authorized members still need. We restrict retained exceptions to their stated purpose and review them when that purpose ends.
Archived access requests: remove 12 months after their original submission. Support requests: retain while being handled and for 12 months after resolution. Successful email-job contents: remove seven days after confirmed delivery. Failed or unconfirmed email-job contents: remove after 30 days from the applicable terminal status. Status records contain limited operational metadata, not the deleted message body.
Active account and workspace information is retained while the service is used. Following an approved closure, our target is to remove account data within 30 days. Account deletion includes a seven-day cancellation period and requires transfer of any workspace ownership first. Removing an individual account does not erase the team's shared work or another member's records. Contact us to arrange closure and deletion of an entire workspace.
Routine security history is retained for 90 days, with limited extensions for unresolved incidents or documented legal holds. Provider logs follow their configured retention and expiry rules. Backup copies are isolated from ordinary use and rotate out under provider settings; our operating target is no more than 30 additional days after live deletion. Deletion must be reapplied if a backup is restored.
Optional analytics uses short-lived browser identifiers. Events already received by PostHog remain subject to the project's configured retention and deletion settings. Contact support@mcpbinder.com for current retention details or assistance with a request. Archiving work or disconnecting an integration is not the same as deleting it; deleting a Binder reference does not delete the original provider file.
Your requests and choices
Email support@mcpbinder.com or use the Contact form to request access, correction, export, deletion, or an appeal of a privacy decision. Include enough information to locate the record, but do not send passwords, access tokens, or identity documents unless we specifically arrange a necessary secure verification step. We verify identity proportionately before releasing or changing personal information.
Account security settings provide available export, account deletion, session, provider, and agent-access controls. Team requests may require coordination with the workspace owner. If you cannot sign in or do not agree to updated terms, you may still make a request by email or the public Contact form.
Your legal rights depend on where you live and the laws that apply. These may include access, correction, deletion, portability, objection or restriction, withdrawal of consent, and opt-outs from sale, sharing, targeted advertising, or certain profiling. We do not deny service merely because you exercise applicable privacy rights or reject optional cookies.
We respond within applicable legal deadlines, explain a refusal or necessary extension, and explain the available appeal process. Send an appeal to support@mcpbinder.com with ‘Privacy appeal’ in the subject so the founder can review it. You may also complain to your state attorney general or another appropriate regulator. Withdrawing consent does not invalidate processing that occurred before withdrawal.
Contact usSecurity and processing locations
We use authentication, scoped permissions, encryption of stored credentials and sensitive job/intake payloads, and recorded administrative access to reduce risk. No service can guarantee absolute security.
Reed Stories, LLC operates in the United States. Providers and services you choose may process information in the United States or other locations where they operate. US-only initial eligibility is not a promise that all processing stays in the United States. We do not claim a certification or special regulated-data capability that has not been established.
Children and changes
MCPBinder is intended for adults 18 and older, not children. Contact support@mcpbinder.com if you believe a child has provided information so we can investigate and remove it as appropriate.
We identify the effective date and version of this notice. For material changes we provide appropriate advance notice where required, such as through the website or service email. New optional tracking purposes or vendors require an updated privacy choice before activation.