Ed in Park City LLC

Privacy

This notice describes how Ed in Park City LLC handles information in the ThisMCP control plane and gateway service.

Last updated June 12, 2026

Operator and service boundary

ThisMCP is operated by Ed in Park City LLC as a Client Explorer OAuth app and remote MCP provider. Client Explorer remains the source of truth for users, groups, group invitations, OAuth apps, private API keys, entities, callbacks, workflows, agents, usage ledgers, Redis workflow buffers, and MCP provider registration.

ThisMCP is responsible for proxy-local gateway state, upstream MCP definitions, policy, manifests, aliases, access keys, capsules, approvals, budgets, generated capability review, and proxy logs.

Information processed

The categories below describe information the service may process depending on how a group configures and uses ThisMCP.

  • Account and identity data, such as Client Explorer user IDs, names, email addresses, group IDs, group membership context, local gateway roles, OAuth session state, and delegated access tokens used for Client Explorer calls.
  • Gateway configuration data, such as proxy group names, upstream MCP service names, endpoint URLs, documentation URLs, transport settings, headers, environment variables, commands, args, working directories, access keys, per-key upstream overrides, aliases, manifests, keyword rules, result policy rules, governance records, budgets, capsules, approvals, and generated capability proposals.
  • MCP payload and audit data, such as tool names, prompt names, resource identifiers, request arguments, request payloads, returned result payloads, raw upstream results, transformed results, HTTP request and response envelope metadata, matched policy rules, evidence payloads, routing decisions, error text, timestamps, duration, and character-count usage metrics.
  • Collaboration and messaging data, such as shared records, mailbox records, titles, statuses, message bodies, recipient identifiers, task capsule links, read timestamps, and related payloads.
  • Product telemetry, such as page URL, page title, referrer, pathname, timestamp, event name, action name, Client Explorer group ID, and scalar action properties for product analytics.

Sensitive data and secrets

The service is designed to store sensitive external identifiers, lookup values, tokens, serialized payloads, exact-match filters, upstream credentials, and MCP payload material through encrypted string fields with hash sidecars rather than plaintext sensitive payload storage.

Access keys, private API keys, OAuth client secrets, upstream credentials, and similar secrets should not be stored or transmitted outside the intended secret-handling paths. Some secret values are write-only after entry and may be stored only as hashes, encrypted previews, or encrypted values.

How information is used

Information is used to authenticate users, connect Client Explorer groups to proxy groups, operate group-scoped MCP endpoints, enforce runtime policy, route MCP calls, apply approvals and budgets, generate and review capability manifests, audit gateway behavior, investigate security issues, maintain reliability, and provide support.

Runtime calls may use group membership context, assigned access-key context, task capsule state, policy state, and selected upstream MCP integrations to complete actions you initiate, configure, or authorize.

Legal bases where applicable

Where privacy law requires a legal basis for processing, the bases may include providing and administering the service, performing a contract or taking steps requested before a contract, legitimate interests in security, reliability, fraud prevention, debugging, product analytics, and service improvement, compliance with legal obligations, and consent where consent is required.

Analytics

ThisMCP sends product telemetry to Client Explorer analytics. Browser page events are sent through a same-origin ThisMCP endpoint and may include the current URL, document title, referrer, pathname, timestamp, and group ID when available.

Server-side action events may be sent on a best-effort basis with the action name and scalar non-secret properties. Analytics events should not include secrets, tokens, private API keys, recipient emails, upstream headers, environment variables, commands, tool arguments, tool results, message bodies, provider redirect URLs, or third-party session identifiers.

Sharing and recipients

The service may exchange information with Client Explorer, selected upstream MCP providers, model providers chosen by users or their clients, identity providers, hosting providers, database providers, security and observability services, and other infrastructure providers as needed to operate the service.

Information may also be shared with organization administrators, group owners, approvers, assigned key owners, and authorized group members through the control plane, approval screens, logs, collaboration views, and audit surfaces.

Third-party upstream services receive the information needed for the MCP calls, prompts, resource reads, or other actions that users configure or authorize. Those services handle information under their own terms and policies.

Model training

ThisMCP is not designed to use customer MCP payloads, tool results, upstream secrets, or gateway logs to train general-purpose AI models. User-selected model providers or upstream MCP providers may have their own training, retention, and privacy practices, so review those provider terms before routing data to them.

Retention

Records are retained as needed for operation, audit, security, compliance, troubleshooting, account administration, and legitimate business purposes, unless deletion is required by applicable policy, law, or a controlling written agreement.

Retention criteria may depend on record type, group configuration, operational need, security risk, audit value, legal obligations, backup schedules, and whether the record is still needed to provide or defend the service. Access keys remain until revoked or expired by configuration; logs and policy records may be retained for audit and security review.

Security

Security controls include encrypted storage for sensitive fields, hash sidecars for exact-match lookup, HTTP-only authentication cookies, redaction of secret-bearing HTTP headers in gateway envelope logs, policy enforcement at discovery, request, and response phases, approval workflows, access-key revocation, and role-based control-plane access.

No security measure is perfect. You should use least-privilege upstream credentials, rotate secrets, revoke unused keys, review logs, test policies, and avoid routing sensitive data through tools or providers that are not authorized for that data.

Your choices and rights

You can manage many records through Client Explorer or the ThisMCP control plane, including upstream configuration, access keys, overrides, approvals, capsules, policy rules, and collaboration records, depending on your role.

Depending on where you live and how the service is provided to you, you may have rights to request access, correction, deletion, restriction, portability, objection, or information about how personal information is used and disclosed. Requests should be directed through the support or account channel provided with your service access.

California privacy disclosures

If California privacy law applies, the categories of personal information collected are described in this notice, and the purposes are operation, security, analytics, support, compliance, and the other purposes described above.

ThisMCP is not designed to sell personal information or share personal information for cross-context behavioral advertising. It is not designed to use sensitive personal information to infer characteristics for advertising.

International processing

Information may be processed in the United States and in other locations where Ed in Park City LLC, Client Explorer, infrastructure providers, or selected upstream providers operate. If your organization requires specific data residency or transfer terms, those should be handled in a separate written agreement before routing regulated data through the service.

Children

The service is intended for business and developer use and is not directed to children. Do not use the service to knowingly submit personal information from children where parental consent or other special handling is required unless you have the required authorization and safeguards.

Contact

Questions, requests, and privacy concerns should be directed through the support or account channel provided with your service access. The service is operated by Ed in Park City LLC.