The short version
- We collect what we need to run MegaMCP: your account, your connected platforms' tokens (encrypted), and a record of the changes you approve.
- Reports your AI asks for pass through to your AI app. We don't keep them.
- We never sell your data and never use it to train AI models.
- Google data is handled under Google's Limited Use rules; Meta data under Meta's Platform Terms.
- Disconnect or delete anytime. Email privacy@megamcp.com for anything else.
1. Who we are
MegaMCP is operated by QC DEVWORKS, LLC d/b/a MegaMCP (“MegaMCP”, “we”, “us”). MegaMCP is a hosted service that lets AI apps you choose (like Claude, ChatGPT, Cursor, Claude Code and VS Code) read and, with human approval, change your marketing accounts on Google and Meta. This policy explains what we collect when you use megamcp.com and the MegaMCP service, why, and what you can do about it.
Questions or requests: privacy@megamcp.com. Postal address for notices: c/o Entity Protect Registered Agent Services LLC, 205 N Michigan Ave, Ste 810, Chicago, IL 60601-5902, USA.
For the data in your workspace (your team, your connected accounts), your organization decides what to connect and who can use it. Where privacy law distinguishes the two, we act as a processor (or service provider) for that workspace data on your organization's behalf, and as a controller for account, billing and website data.
2. What we collect
- Account details. Your email address and (if you add one) your name, the workspaces you belong to, your role in each, and workspace settings like name and time zone.
- Sign-in data. When you sign in we email you a one-time link. We store a SHA-256 hash of that link's token and of your session cookie, never the tokens themselves, plus the IP address and browser user agent of each session so you can see and end your sessions.
- Connected platform credentials. When you connect Google or Meta, we receive OAuth access and refresh tokens, the scopes you granted, and the id and email of the Google or Meta account you connected with. Tokens are encrypted at rest (see Security).
- Account metadata. The ad accounts, GA4 properties, Search Console sites and Tag Manager containers your connection can reach: their ids, names and currency, and which ones you switched on.
- Platform data you ask for. When you or your AI app runs a read tool, we fetch the requested data from Google or Meta and pass it to your AI app. We don't store those results. We do store what's needed to review and undo changes: each proposed change plan with its before and after values, who approved it, and what was applied.
- The flight recorder. A log of activity in your workspace: which tool was called and with which arguments, by whom, from which AI app, plus plans, approvals, connections, team and billing events.
- AI app details. When you connect an AI app, we store the name and redirect address it registered with, and hashes of the access and refresh tokens we issue to it.
- Scheduled workflows. Their settings, schedule and a summary of each run, and the emails they send.
- Billing. Your Stripe customer id, plan and subscription status. Card details are entered on Stripe's pages and go to Stripe directly; we never see or store full card numbers.
- Launch updates. If you sign up for updates, your email address, the role you picked (optional) and which page you signed up from.
- Technical logs. Our hosting provider keeps standard server logs (IP address, request path, time, errors) for a limited time to run and secure the service.
Cookies. We use strictly necessary cookies only: a session cookie that keeps you signed in and security tokens that protect forms. No advertising cookies, no third-party analytics or tracking scripts.
3. How we use it
- To provide the service you asked for: run the tools your AI app calls, build and apply change plans you approve, run your scheduled workflows, and show your history. (Legal basis: performance of our contract with you.)
- To keep the service secure and reliable: authentication, rate limiting, abuse prevention, debugging. (Legitimate interests.)
- To bill you and keep required records. (Contract and legal obligation.)
- To send service emails: sign-in links, invitations, workflow results, billing and security notices. (Contract.)
- To send launch updates if you signed up for them. Unsubscribe anytime. (Consent.)
We don't sell your personal information, we don't share it for cross-context behavioral advertising, and we don't use your data or your platform data to train AI or machine-learning models, ours or anyone else's.
4. Data from Google APIs (Limited Use)
MegaMCP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, we request access to Google Ads, Google Analytics, Search Console and Tag Manager so the tools you use can work. Specifically, we:
- use Google user data only to provide and improve the user-facing features of MegaMCP that you use, such as answering your AI app's requests and applying changes you approve;
- transfer Google user data to others only as needed to provide those features at your direction (for example, returning a report to the AI app you connected), to comply with applicable law, for security purposes, or as part of a merger or acquisition with notice to you;
- do not use or transfer Google user data for serving advertisements, including retargeting or personalized or interest-based advertising;
- do not sell Google user data, and do not use it to determine credit-worthiness or for lending purposes;
- do not use Google user data to develop, improve or train generalized or non-personalized AI or machine-learning models;
- do not allow humans to read Google user data unless you give us permission for specific data (for example, in a support request), it's necessary for security purposes such as investigating abuse, to comply with applicable law, or the data is aggregated and anonymized for internal operations.
You can revoke MegaMCP's access at any time by disconnecting in your dashboard or at myaccount.google.com/permissions.
5. Data from Meta
When you connect Meta, we request permission to read and manage the ad accounts you choose (ads_read, ads_management, business_management). We process Meta Platform Data only to provide MegaMCP's features to you, in line with Meta's Platform Terms and Developer Policies. We don't sell it, don't use it for advertising or profiling, don't use it to train AI models, and don't share it except with our service providers as needed to run MegaMCP, when the law requires it, or when you direct us to (for example, returning results to the AI app you connected). You can remove MegaMCP from Facebook Settings → Business Integrations at any time; see data deletion below.
6. The AI apps you connect
MegaMCP works through AI apps you choose and connect yourself, such as Claude (Anthropic), ChatGPT (OpenAI), Cursor, or GitHub Copilot in VS Code. When your AI app calls a MegaMCP tool, we send the result (for example, a campaign report) to that app, because that's what you asked for. What the AI app does with it is governed by your agreement with its provider, not by this policy. Pick an AI app and plan whose data terms you're comfortable with; many business plans don't train on your conversations by default.
8. How long we keep it
- Platform tokens: until you disconnect the connection, remove the workspace, or the platform revokes them. Disconnecting wipes the stored tokens immediately and asks the platform to revoke them.
- Report data from read tools: not stored.
- Change plans and the flight recorder: for as long as your workspace exists, so you can audit and undo. Your plan sets how far back the dashboard shows.
- Sign-in links and sessions: sign-in links expire after 15 minutes and sessions after 30 days. Access tokens we issue to AI apps expire on their own, and revoking an app ends its access immediately.
- Billing records: as long as tax and accounting law requires.
- Launch updates: until you unsubscribe or ask us to remove you.
- After you ask us to delete your account or workspace: we delete it from our live systems within 30 days. Backups roll off on our hosting provider's backup schedule.
9. Deleting your data
- Disconnect a platform: in the dashboard, open Connections and click Disconnect. Tokens are wiped and revoked, and the accounts are switched off.
- Revoke from the platform side: Google at myaccount.google.com/permissions; Meta under Facebook Settings → Business Integrations.
- Disconnect an AI app: dashboard → Connect AI → Revoke.
- Delete everything: email privacy@megamcp.com from the address on your account and ask us to delete your account (and, if you're an owner, your workspace). We'll confirm, then delete within 30 days.
10. Your rights
Depending on where you live (for example the EU, UK, or California), you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email privacy@megamcp.com. We'll respond within 30 days and won't treat you differently for asking. You can also complain to your local data protection authority. If your organization manages your workspace, we may refer workspace-data requests to them.
11. Security
OAuth only, encrypted tokens, hashed credentials, least-privilege roles, human approval for every change and a full audit log. The details are on our Security page. No system is perfectly secure; if we learn of a breach affecting your data, we'll notify you without undue delay.
12. International transfers
We and our providers may process data in the United States and other countries. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
13. Children
MegaMCP is a business tool and isn't meant for anyone under 16. We don't knowingly collect data from children.
14. Changes to this policy
We'll update the date at the top when this policy changes, and email account owners before material changes take effect.
15. Contact
privacy@megamcp.com for privacy questions and requests, security@megamcp.com for security reports. QC DEVWORKS, LLC d/b/a MegaMCP, c/o Entity Protect Registered Agent Services LLC, 205 N Michigan Ave, Ste 810, Chicago, IL 60601-5902, USA.