Privacy Policy

Last updated: December 2025

Effective Date: December 10, 2025

Our Zero-Trust Privacy Commitment

Cortex MCP is built on a Zero-Trust architecture. Your code, AI conversations, and development context remain entirely on your local machine. We cannot access, read, or transmit your actual content. This Privacy Policy explains what limited data we do collect and how we use it, including important information about MCP Interaction Metadata.

1. Data We Do NOT Collect

In accordance with our Zero-Trust architecture, Cortex MCP stores all sensitive data locally on your machine. We do NOT collect, access, transmit, or have any capability to access:

  • Your Source Code - Any code, scripts, configuration files, or file contents
  • AI Conversations - Your prompts, queries, or AI-generated responses
  • Context Content - The actual content stored in your Cortex context files (.md files)
  • Project Structure - Directory layouts, file names, or repository structure
  • Personal Documents - Any documents, notes, or files you work with
  • Business Information - Proprietary business logic, trade secrets, or confidential data
  • Decryption Keys - Your encryption keys for cloud sync (you control these exclusively)

Technical Guarantee: The Cortex MCP server runs entirely on your local machine. Your content data never leaves your device except when you explicitly choose to use encrypted cloud sync, and even then, we cannot decrypt it.

2. Data We Collect

We collect the minimum data necessary to provide, maintain, and improve the Service:

2.1 Account Information

When you create an account through GitHub OAuth, we collect:

  • GitHub username
  • Email address associated with your GitHub account
  • GitHub profile avatar URL
  • GitHub user ID (unique identifier)
  • Account creation timestamp

2.2 License and Subscription Data

  • License key (stored in hashed format)
  • Subscription tier (Free, Pro, or Premium)
  • Subscription status (active, expired, trial)
  • Payment transaction IDs (processed by Paddle)
  • Device identifier for license binding (non-Premium tiers)
  • License verification timestamps

2.3 Technical Data

  • IP address (for security and fraud prevention)
  • Browser type and version
  • Operating system
  • Device type (desktop/mobile)
  • Referring website
  • Pages visited on our website

2.4 AI Client Environment Information

When you use Cortex MCP through an AI development tool, we may collect basic information about your development environment to ensure compatibility and provide better support:

  • AI Client Name: The name of the AI tool you're using (e.g., "Claude Code CLI", "Claude Desktop", "Cline", "Continue")
  • AI Client Version: The version number of your AI tool
  • MCP Protocol Version: The Model Context Protocol version in use

Why We Collect This: This information helps us ensure Cortex works seamlessly with different AI tools, prioritize compatibility updates, and provide tool-specific support.

Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) - ensuring service compatibility. Collection is enabled by default, but you can opt out at any time without affecting functionality.

What This Does NOT Include: We do not collect information about which AI models you use, what prompts you write, or any content you generate with AI tools.

Your Control Over AI Client Information

You can disable AI client information collection at any time. Disabling this will NOT affect any functionality - Cortex works perfectly without this data.

  • Web Dashboard: Settings → Privacy → "Collect AI Client Information" toggle
  • CLI Command: cortex telemetry set-client-info off
  • Email Request: Contact [email protected]

Default Setting: Collection is enabled by default for compatibility support, but you can opt out at any time without any loss of functionality.

3. MCP Interaction Metadata Collection

Important Notice About MCP Interaction Metadata

With your consent, we collect anonymized metadata about how you interact with the MCP server. This is distinct from your actual content - we collect information about how you use features, not what content you create or process.

3.0 Telemetry Collection Levels (Opt-in)

Cortex offers three levels of telemetry collection. By default, NO telemetry is collected (NONE level). You must explicitly opt-in during installation or in your account settings.

🔒 NONE (Default)

Complete Privacy

  • ✓ No data collection
  • ✓ Full functionality
  • ✓ Zero telemetry

Recommended if: You prioritize absolute privacy

📊 BASIC

Minimal Technical Data

  • ✓ AI Client name/version
  • ✓ Cortex version
  • ✓ Tool call counts (aggregated)
  • ✗ No usage patterns
  • ✗ No content

Recommended if: You want to help with compatibility

📈 FULL

Detailed Usage Analytics

  • ✓ All BASIC data
  • ✓ Tool usage patterns
  • ✓ Feature utilization
  • ✓ Performance metrics
  • ✗ Still no content

Recommended if: You want to support product development

⚠️ Important: Even at FULL level, we never collect your code, AI conversations, file names, or any content. We only collect how you use features, not what you create.

3.1 What MCP Interaction Metadata Includes

When you opt-in to metadata collection, we may collect:

  • Tool Usage Patterns:
    • Which MCP tools are used (e.g., create_branch, search_context, update_memory)
    • Frequency of tool invocations
    • Sequence patterns of tool usage
  • Feature Utilization Metrics:
    • Number of branches created
    • Number of contexts stored
    • Search frequency and result counts (not search terms)
    • Context loading patterns
  • Performance Data:
    • Response times for operations
    • Operation success/failure rates
    • Resource utilization metrics
  • Error and Diagnostic Data:
    • Error types and error codes (not error messages containing your data)
    • Crash reports (sanitized to remove personal data)
    • Feature compatibility issues
  • Session Information:
    • Session duration
    • Session frequency
    • Time of day usage patterns (aggregated)

3.2 What MCP Interaction Metadata Does NOT Include

  • The content of your context files or branches
  • Your actual search queries or search terms
  • File names, project names, or directory structures
  • Any text you type or generate
  • Your AI conversation content
  • Any personally identifiable information within your work

4. Commercial Use of Aggregated Data

IMPORTANT: Commercial Data Use Disclosure

By opting into MCP Interaction Metadata collection, you acknowledge and agree that we may use this data commercially, including selling it to third parties.

Please read this section carefully before enabling metadata collection.

4.1 Aggregation and Anonymization Process

Before any commercial use, MCP Interaction Metadata undergoes:

  • Aggregation: Individual data points are combined with data from many users
  • Anonymization: All personally identifiable information is removed
  • Statistical Processing: Data is transformed into statistical summaries
  • K-Anonymity: We ensure no individual can be identified from aggregated data

Our K-Anonymity Guarantee

We enforce strict anonymization standards to protect your privacy:

  • Minimum K=5: All aggregated datasets ensure that each data point represents at least 5 different users (industry standard)
  • K=10 for Sensitive Attributes: For usage patterns that could be more identifying, we enforce a higher threshold of at least 10 users
  • K-Anonymity Validation: Before any data is aggregated or sold, we validate K-anonymity (K≥5) to prevent individual identification. Currently performed through manual review by our Data Protection team; automated validation system planned for Q2 2026.
  • No Rare Combinations: Unique or rare usage patterns are automatically excluded from datasets to prevent individual identification

Technical Note: K-anonymity means that each combination of attributes in our dataset is shared by at least K individuals, making it mathematically impossible to identify any single user from the aggregated data.

4.2 Permitted Commercial Uses

Aggregated, anonymized MCP Interaction Metadata may be used for:

  • Internal Product Development:
    • Improving Cortex MCP features and performance
    • Developing new features based on usage patterns
    • Identifying and fixing common issues
  • Industry Analytics and Reports:
    • Publishing industry insights about AI development tool usage
    • Creating benchmark reports
    • Contributing to academic research (anonymized)
  • Dataset Licensing:
    • Creating and licensing datasets for AI/ML research
    • Providing training data for AI model development
    • Supporting academic and commercial AI research
  • Commercial Sale to Third Parties:
    • Selling aggregated usage pattern datasets
    • Licensing anonymized behavioral analytics
    • Providing market intelligence to business customers

4.3 Commercial Use Restrictions

We commit to the following restrictions on commercial use:

  • We will never sell individual-level data that could identify you
  • We will never sell your actual content, code, or conversations
  • We will never reverse-engineer aggregated data to identify individuals
  • Third-party purchasers are contractually prohibited from attempting re-identification
  • All data sales are subject to data protection agreements

5. How We Use Your Data

5.1 Account and Service Provision

  • Creating and managing your account
  • Processing subscription payments through Paddle
  • Verifying license keys and tier access
  • Providing customer support

5.2 Communication

  • Sending transactional emails (receipts, license keys)
  • Important service announcements and security notices
  • Subscription renewal reminders
  • Product updates (with opt-out option)

5.3 Legal Bases for Processing (GDPR)

Data Type Legal Basis
Account Information Contract Performance
License Verification Contract Performance
Technical Data Legitimate Interest
MCP Interaction Metadata Explicit Consent
Marketing Communications Consent

6. Data Sharing and Disclosure

6.1 Service Providers

We share data with trusted service providers who assist us:

  • Paddle - Payment processing (Merchant of Record)
    • Receives: Name, email, payment information
    • Purpose: Process payments, handle taxes, issue invoices
  • GitHub - OAuth authentication
    • Receives: OAuth access credentials
    • Purpose: Verify identity during login
  • Cloud Infrastructure - Server hosting
    • Receives: Encrypted data, technical logs
    • Purpose: Host our web services

6.2 Third-Party Data Purchasers

As described in Section 4, we may sell aggregated, anonymized MCP Interaction Metadata to:

  • AI research organizations
  • Technology companies
  • Market research firms
  • Academic institutions

6.3 Legal Requirements

We may disclose data when required by law:

  • To comply with valid legal process (subpoenas, court orders)
  • To protect our rights, property, or safety
  • To protect users or the public from harm
  • In connection with a merger, acquisition, or sale of assets

7. Cloud Sync (Premium Feature)

Premium subscribers can optionally synchronize contexts across devices:

End-to-End Encryption Guarantee

  • Client-Side Encryption: Data is encrypted on your device before transmission
  • AES-256-GCM: Military-grade encryption algorithm
  • User-Controlled Keys: Encryption keys derived from your license key - only you have access
  • Your Storage: Data syncs to your personal Google Drive account
  • Zero-Knowledge: We mathematically cannot decrypt your synced data

8. Data Retention

Data Type Retention Period
Local Context Data Forever (on your device, you control deletion)
Account Information Duration of account + 30 days after deletion
License Data Duration of subscription + 1 year
MCP Interaction Metadata 3 years (or until opt-out)
Aggregated/Anonymized Data Indefinitely (cannot be linked to you)
Payment Records 7 years (legal requirement)
Security Logs 1 year

9. Your Rights and Choices

You have the following rights regarding your data:

  • Access: Request a copy of personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your account and personal data
  • Data Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request limitation of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for optional data collection at any time

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

10. Opt-Out Mechanisms

10.1 Initial Consent Process

When you first install or configure Cortex MCP, you will be presented with a clear consent prompt allowing you to choose your telemetry level:

╔════════════════════════════════════════════════════════════╗
║  Cortex Telemetry Settings                                 ║
╚════════════════════════════════════════════════════════════╝

Cortex can collect anonymous usage statistics to improve the service.
All data is stored locally and only transmitted with encryption.

Choose your telemetry level:

1. [NONE] No data collection (Default)
   - Complete privacy
   - Zero telemetry

2. [BASIC] Technical information only
   ✓ AI Client name/version
   ✓ Cortex version
   ✓ Tool usage counts (aggregated)
   ✗ No usage patterns
   ✗ No content

3. [FULL] Detailed analytics
   ✓ All BASIC data
   ✓ Feature usage patterns
   ✓ Performance metrics
   ✗ Still no content

Selection (1/2/3): [Default: 1] _
                

Your Choice is Respected: You can change this setting at any time in your dashboard settings or via the CLI command cortex telemetry set [none|basic|full].

10.2 Changing Telemetry Settings

You can change your telemetry level at any time:

  • Web Dashboard: Visit Settings → Privacy → Telemetry Level
  • CLI Command: cortex telemetry set none|basic|full
  • Email Request: Contact [email protected] to change settings and delete existing data

10.3 Data Deletion

You can request deletion of collected telemetry data:

  • CLI Command: cortex telemetry clear - Deletes local telemetry data
  • Web Dashboard: Settings → Privacy → "Delete My Telemetry Data"
  • Email Request: We will delete your identifiable telemetry data within 30 days

Note: Opting out or deleting telemetry data does not affect your ability to use Cortex MCP. All features remain fully functional regardless of your telemetry choice.

Aggregated Data: Once your data has been aggregated and anonymized for commercial use, it cannot be individually identified or deleted. However, you can prevent future data from being collected by opting out.

10.2 Marketing Communications

  • Click "Unsubscribe" in any marketing email
  • Update preferences in your account dashboard
  • Contact us to remove from all marketing lists

Note: You cannot opt out of transactional emails (receipts, security notices, license information).

11. Security Measures

We implement comprehensive security measures:

  • Encryption in Transit: TLS 1.3 for all communications
  • Encryption at Rest: AES-256 encryption for stored data
  • Access Controls: Role-based access with principle of least privilege
  • Security Monitoring: 24/7 intrusion detection and monitoring
  • Regular Audits: Periodic security assessments and penetration testing
  • Secure Development: Security-first development practices
  • Incident Response: Documented procedures for security incidents

12. International Data Transfers

Our servers are located in the United States. If you access our services from outside the US, your data will be transferred to and processed in the US.

For transfers from the European Economic Area (EEA), we rely on:

  • Standard Contractual Clauses approved by the European Commission
  • Your explicit consent where applicable

13. Children's Privacy

Cortex MCP is not intended for users under 13 years of age (or 16 in the EEA). We do not knowingly collect personal information from children. If we discover we have collected data from a child, we will delete it promptly. If you believe a child has provided us data, please contact us immediately.

14. California Privacy Rights (CCPA)

California residents have additional rights under the CCPA:

  • Right to Know: Categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out of Sale: Direct us not to sell your personal information
  • Right to Non-Discrimination: Equal service regardless of privacy choices

Do We "Sell" Personal Information Under CCPA?

Under California law, the sharing of aggregated, anonymized MCP Interaction Metadata with third parties for compensation constitutes a "sale" under CCPA's broad definition.

However, we ensure your protection through:

  • K-Anonymity (K≥5): All sold data represents at least 5 users, making individual identification mathematically impossible
  • Contractual Prohibitions: Third-party purchasers are legally prohibited from attempting re-identification
  • Automated Validation: Our system prevents any identifiable data from being included in datasets

California Residents: Your Opt-Out Rights

You can opt out of this data sale through any of these methods:

  1. Disable telemetry collection entirely (set to NONE level)
  2. Click "Do Not Sell My Personal Information" in Settings → Privacy
  3. Email us at [email protected] with "CCPA Opt-Out Request"

Important: Opting out will not affect your access to any Cortex features.

15. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under GDPR:

  • All rights listed in Section 9
  • Right to lodge a complaint with your local Data Protection Authority
  • Right to withdraw consent at any time

Data Controller: Cortex MCP
Contact: [email protected]

16. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes:

  • We will update the "Last updated" date at the top
  • We will notify you by email for significant changes
  • We will display a prominent notice on our website
  • For material changes to MCP Interaction Metadata collection or commercial use, we will request renewed consent

17. Contact Information

For privacy-related questions, requests, or concerns:

We aim to respond to all privacy requests within 30 days.

Summary of Key Points

  • Your code, conversations, and content stay on your device - we cannot access them
  • With consent, we collect MCP Interaction Metadata (how you use features, not what you create)
  • Aggregated, anonymized metadata may be sold commercially - you can opt out anytime
  • Cloud sync uses end-to-end encryption - we mathematically cannot read your synced data