MCP Spider private beta

Privacy Policy

Last Updated: September 11, 2026

MCP Spider is operated by Axel Rivera, in Florida, United States. It is a private beta: access is by invitation, and it is free while the beta lasts. This policy says what the service stores, what it deliberately does not store, how long it keeps things, and who else can see them. It is written plainly on purpose.

What Is Collected

  • Your account. Your name, your email address, and a one way hash of your password. Never the password itself. If you were invited, the address the invitation was sent to and who sent it.
  • Your Follow Up Boss API key. Encrypted before it is written to the database, and never displayed again after you paste it: not to you, not in a log, not to an assistant.
  • Your access tokens. Stored as digests, so the token itself exists only in the moment it is shown to you and in whatever client you paste it into. A digest cannot be turned back into a token.
  • A log of every tool call. Which tool an assistant ran, whether it worked, how long it took, and when. Not what it was about: the name, the email address, the phone number and the note that were sent are not recorded, and neither is what came back. Not masked, not truncated: never written down. You can read your own log in the application.
  • Ordinary server records. Web server logs and error reports, which include IP addresses and browser user agents, as every web server produces.

What Is Not Collected

  • Your CRM is not copied here. Requests are passed through to Follow Up Boss and the answers are handed straight back. No contact, deal, task, call, or appointment record is ever saved in this application's database, and the tool call log is not an exception to that.
  • No analytics, no advertising, no tracking. There is no analytics script, no advertising network, no third party tracking cookie, and no profile built about you.
  • Nothing is sold or rented. Your information is not sold, rented, or shared for anyone else's marketing.
  • No AI model is trained on your data. Nothing that passes through this service is used to train a model, by me or by anybody on my behalf.

Cookies

One cookie, which keeps you signed in. It is strictly necessary for the application to work, so there is nothing to consent to and no banner to dismiss. Signing out ends it, and so does time: a sign-in you have not used in 30 days stops working, as does any sign-in older than 90 days, however recently you used it.

Who Else Can See Your Information

  • Follow Up Boss. Every request this service makes on your behalf goes to Follow Up Boss under your own API key, and their privacy policy governs what happens there.
  • The AI client you choose. When your assistant calls a tool, the answer goes to that assistant, and from there to whoever operates it. Choose your client with that in mind: this service cannot control what a client does with a result once it has been returned.
  • A hosting provider and an email provider. The server and database that run this application, and the service that delivers invitations and password resets. They process data on my instructions and for no other purpose.
  • Nobody else. Beyond a lawful legal demand, which would be resisted where it is reasonable to resist it, no one else receives your information.

Data is stored on servers in the United States.

How Long Things Are Kept

  • Tool call logs: which tool ran and how it went, deleted 30 days after they are written.
  • Your API key: deleted when you delete the connection that holds it.
  • Access tokens: deleted when you revoke them.
  • Your account: kept while the account exists, and deleted when you ask for it to be.

Your Choices

You can change your name and email address, revoke any access token, and delete a connection, all from inside the application. You can also ask for a copy of what is stored about you, ask for a correction, or ask for your account and its data to be deleted entirely. Ask by writing to the address below, and expect an answer within thirty days. Depending on where you live, the law may give you these rights already. They are offered here regardless of where you live.

Security

API keys are encrypted at rest, tokens are stored only as digests, all traffic is served over TLS, and the contents of a tool call are never written to a log or a database here. No service can promise perfect security, and this one does not. If you believe something has gone wrong, write to the address below and say so.

Children

This is a tool for real estate professionals. It is not directed at children, and it is not for anyone under 18.

Changes to This Policy

This policy will change as the service does, and the date at the top of this page says when it last did. If a change meaningfully reduces what you are promised here, invited users will be told by email before it takes effect.

Contact

Questions about this policy, or about what is stored about you, go to Axel Rivera, at axel@axelrivera.dev.

See also the Terms and Conditions.