Privacy Policy

Effective July 15, 2026

1. What we collect

  • Account data: email address, display name, hashed password (managed by Supabase Auth), invite code used, and plan.
  • Content you submit: product descriptions and messages sent to the Classify tool, contact form submissions, and exam answers.
  • Usage data: metered usage events, API and MCP tool calls (tool name, arguments, timing, and error status), and API key metadata. We store only a hash of API keys, never the key itself.
  • Billing data: handled by Stripe. We store your Stripe customer and subscription identifiers, not card numbers.

2. How we use it

We use this data to operate the Service, enforce plan quotas and rate limits, secure accounts, respond to support requests, improve search and classification quality, and bill paid plans. We do not sell personal data and we do not use your submitted content for advertising.

3. Subprocessors

Data is processed by a small set of infrastructure providers:

  • Supabase (database, authentication, hosting of account and usage data)
  • Vercel (application hosting)
  • OpenAI (classification and search: text you submit to the Classify tool and search queries are sent to OpenAI for processing)
  • Stripe (payments)
  • Upstash (caching and rate limiting)

4. Retention

Account data is retained while your account is active. Short-window quota counters are deleted automatically within days. Tool call logs and usage events are retained for service operation, abuse prevention, and audit. You can request deletion of your account and associated personal data at any time (see Section 6).

5. Security

Data is encrypted in transit. API keys are stored as SHA-256 hashes. Access to production data is limited to the operator. No method of transmission or storage is completely secure; report suspected vulnerabilities to fbaig@htsmcp.com.

6. Your rights

You can access, correct, export, or delete your personal data by emailing fbaig@htsmcp.com. If you are in a jurisdiction with statutory data rights (for example, GDPR or CCPA), we will honor requests consistent with those laws.

7. Cookies

We use session cookies for authentication (Supabase Auth). We do not use third-party advertising or tracking cookies.

8. Changes

We may update this policy as the Service evolves. Material changes will be announced on the site or by email. Continued use after changes take effect constitutes acceptance.