Legal
Privacy Policy
Toolport reads issue data so your agent can answer questions. Here’s what that means for your data, in plain language.
Summary
The self-hosted server talks only to your issue tracker. The hosted endpoint processes requests on your behalf and keeps as little as it can, for as short a time as it can.
The self-hosted server
When you run @toolport/mcp yourself, requests go straight from your machine to your issue tracker. We receive no issue data, no tokens and no usage telemetry.
The package contains no analytics and makes no network calls except to the tracker you configure.
What the hosted endpoint processes
To run your tool calls, the hosted endpoint handles:
Account details from sign-in: your tracker user ID, display name and email address.
Your OAuth token, encrypted at rest.
Request metadata: tool name, repository, time, result count and latency.
Issue content, which passes through memory to answer the call and is never written to disk.
How we use it
We use this data to sign you in, run your tool calls, enforce rate limits, fix failures and keep the Service secure.
We don’t sell personal data, show ads or use issue content to train models.
Retention
Request metadata is deleted after 30 days. Tokens are deleted as soon as you revoke access or delete your account. Backups roll off within 35 days.
Service providers
The hosted endpoint runs on a cloud hosting provider in the United States, with an error-monitoring service for crash reports. Both are bound by data processing agreements and can only use data to provide their service to us.
This website
This site counts page views with cookie-free analytics. We don’t set advertising or tracking cookies.
Security
Tokens are encrypted at rest with AES-256, and all traffic uses TLS 1.2 or later. Access to production systems is limited to the engineers who run them and is logged.
Your rights
You can ask for a copy of your data, correct it or delete your account by emailing privacy@toolport.example. Depending on where you live, laws such as the GDPR or CCPA may give you further rights, and we honor them for everyone.
Changes and contact
If we change this policy in a way that affects you, we’ll post the update here and in the changelog at least 14 days before it takes effect. Questions go to privacy@toolport.example.
Last updated
October 4, 2026
In short
Self-hosting sends nothing to us.
The hosted endpoint never stores issue content.
No ads, no data sales, no model training.
Sample text for a template. Have a lawyer review it before you publish.