Privacy Policy
Discover how Image MCP Server protects your data, handles image uploads, secures API authentication tokens, and enforces zero-training guarantees.
⚡ Plain English Privacy Commitments
- ✓No Model Retraining: We NEVER use your prompts or generated media to train public AI models.
- ✓No Selling Data: We never sell your personal contact info, prompt histories, or API metrics.
- ✓End-to-End Encryption: API calls and secret keys are encrypted using AES-256 and TLS 1.3.
- ✓Full Data Control: You can export your usage logs or request complete account erasure anytime.
1. Information We Collect
To provide our Model Context Protocol server, API capabilities, and developer dashboard, we collect specific categories of information when you interact with our platform:
Email address, name, profile avatar, and authentication provider IDs received via Google or GitHub OAuth.
API request timestamps, tool names executed (generate_image, remove_background), credits consumed, response latencies, and IP address.
Text prompts, mask coordinates, source images sent for background removal/inpainting, and generated output URLs required for image rendering.
Payment records, subscription plan tier, credit pack transactions, and billing history. Full credit card numbers are handled securely by PCI-DSS compliant partners.
2. How We Use Your Information
We utilize the collected data strictly for operational, security, and service delivery purposes:
- Core Functionality: Processing image tool calls from your MCP client (Claude Desktop, Cursor, AI agents) or REST API requests.
- Credit Accounting: Accurately tracking usage balances and deducting appropriate credit amounts per tool invocation.
- System Security & Fraud Prevention: Monitoring rate limits, preventing automated abuse, enforcing safety filters, and protecting against unauthorized access.
- Developer Communication: Sending critical security notifications, billing receipts, or system status notices.
3. Image & Media Data Handling
When you submit an image for inpainting, background removal, or upscaling, your input file is transmitted securely over TLS encryption to our isolated worker nodes.
🛡️ Zero Model Retraining Commitment:
We strictly enforce zero retention training policies with our AI model providers. Your uploaded images and custom generation prompts are processed ephemerally for model inference and are never added to training corpora for public foundation models.
Generated assets are stored temporarily in secure cloud storage buckets to allow your client to download or display them in your application dashboard.
4. Third-Party AI & Cloud Infrastructure
To deliver state-of-the-art image capabilities, Image MCP Server partners with vetted cloud and AI compute infrastructure providers:
- Google Cloud Platform / Vertex AI: Primary enterprise compute, secure image generation, and database hosting.
- Dodo Payments / Stripe: PCI-DSS compliant billing processors for credit pack and subscription handling.
- Specialized GPU Clusters: Low-latency edge worker nodes for real-time background removal and upscaling.
All third-party partners are bound by data processing agreements (DPAs) ensuring strict compliance with global privacy standards.
5. Data Security & Encryption Standards
We implement enterprise-grade security protocols to protect developer accounts and API tokens:
7. Your Data Rights (GDPR & CCPA)
Depending on your location, you hold key rights regarding your personal data:
- Right to Access & Export: Request a complete JSON export of your account data and API transaction history.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your account, API keys, and associated logs.
- Right to Rectification: Update or correct your profile info via the Dashboard.
- Opt-out of Marketing: Unsubscribe from optional product updates at any time.
8. Data Retention & Automatic Cleanup
API request logs and telemetry data are retained for up to 90 days for debugging and security auditing, after which they are automatically purged or aggregated anonymously.
When an account deletion request is initiated, all active API keys, session tokens, and personal identifiers are permanently removed within 30 days.
9. International Data Transfers
Information collected by Image MCP Server may be stored and processed in servers located in the United States or other jurisdictions where our cloud providers operate. Cross-border transfers comply with standard contractual clauses (SCCs).
10. Children's Privacy
Our services are intended for software developers and AI practitioners and are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
11. Contact Us & Data Protection Officer
For any privacy inquiries, data export requests, or security vulnerability reports, contact our Data Protection Officer: