Privacy Policy
Privacy Policy — SearchMCP
Effective date: 2 October 2025
Last updated: 2 October 2025
1) Who we are
SearchMCP ("SearchMCP", "we", "us") provides a Search API and MCP server for LLMs and AI agents at https://searchmcp.io.
Contact: privacy@searchmcp.io
Registered Entity: Good Something
2) Scope
This policy explains how we process personal data when you:
• visit our website or docs
• create an account, subscribe, or contact support
• use the SearchMCP API / MCP server
• integrate our SDKs, plugins, or tools
3) Data we collect
A) Account & Billing
• Email, name (optional), password hash, auth tokens
• Company, role, VAT/GST info (if provided)
• Billing contact, invoices, payment instrument (processed by our PCI-compliant processor; we do not store full card numbers)
B) Product Usage & Logs
• API keys, request/response metadata (timestamps, latency, status codes)
• Query parameters and endpoint paths
• IP address, user agent, and service identifiers
• For search requests: query text and result URL metadata may be processed for abuse prevention, quality, caching, and debugging. You can opt-out of query body retention (see Section 10).
C) Website Analytics & Cookies
• Page views, referrers, device and browser info
• Cookie identifiers where permitted
• You can control cookies via browser settings and our cookie banner.
D) Communications
• Emails, support tickets, and feedback content
• Social or community handles if you interact with us there
4) How we use data (purposes)
• Provide and secure the service (auth, routing, DDoS/abuse mitigation)
• Measure reliability and improve relevance/quality
• Usage-based billing, invoices, receipts, tax determination
• Customer support and incident response
• Announcements for critical changes, security, or service updates
• With your consent: product tips, newsletters, and surveys (you may opt out anytime)
5) Legal bases (GDPR/UK GDPR)
• Contract performance (Art. 6(1)(b)) for delivering the service
• Legitimate interests (Art. 6(1)(f)) for security, abuse prevention, analytics proportionate to risk
• Consent (Art. 6(1)(a)) for optional marketing or non-essential cookies
• Legal obligation (Art. 6(1)(c)) for tax and compliance record-keeping
6) Sharing & processors
We use trusted subprocessors for:
• Cloud hosting and CDN
• Log aggregation, monitoring, alerting
• Email delivery and support tooling
• Payment processing and subscription management
We require appropriate data protection terms and only permit processing necessary to provide the service. A current list of processors is available on request at privacy@searchmcp.io.
7) International transfers
Your data may be processed in jurisdictions outside your own. Where required, we rely on appropriate safeguards (e.g., EU Standard Contractual Clauses, UK Addendum) and risk assessments.
8) Retention
• Account and billing records: as required by tax/compliance (generally 6–10 years)
• API logs: typically 30–90 days for security and reliability, unless a longer period is needed for investigations
• Search query bodies: default up to 30 days for debugging/quality; configurable/opt-out by request (Section 10)
• Backups: time-limited rolling backups for disaster recovery
9) Security
We use industry-standard controls: encryption in transit, key management, network isolation, least-privilege access, logging, and continuous monitoring. No system is perfectly secure; report issues to security@searchmcp.io.
10) Your choices
• Query retention: request opt-out or reduced retention for query bodies at privacy@searchmcp.io
• Data export or deletion: request via privacy@searchmcp.io (subject to legal retention)
• Marketing: unsubscribe via email footer or request removal
• Cookies: manage via banner and browser settings
11) Your rights (GDPR/UK GDPR)
Subject to law, you may have rights to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority (e.g., ICO in the UK).
12) Children
Our service is for businesses and developers; we do not knowingly collect data from children.
13) Third-party content
When your queries direct us to third-party sites/APIs, their privacy policies apply to your use of those properties.
14) Changes to this policy
We may update this policy. Material changes will be announced via the site or email. Continued use of the service after changes constitutes acceptance.
15) Contact
Privacy questions or requests: privacy@searchmcp.io
Security disclosures: security@searchmcp.io