Privacy
Last updated 2026-07-28
Short version: we hold the apps and data you create, plus the email address you sign in with. We don’t run analytics, we don’t use tracking cookies, and we don’t sell anything to anyone.
The one thing worth reading carefully is what your AI assistant sees— because that part isn’t up to us.
openmcp.app is a free public beta. It is an independent project operated by SecondFirst, based in Melbourne, Australia. Formal business registration details will be published here before we take payments or list openmcp.app in a third-party directory — whichever comes first. If anything on this page matters to you legally, please ask us before relying on the service.
What we collect
| What | Why |
|---|---|
| Your email address and display name | To sign you in and to know which account is yours. Supplied by your sign-in provider. |
| An organization identifier | Your data is stored per organization. This identifier is what keeps your content separate from everybody else’s. |
| The apps you and your AI create | The app itself (its code), its description, and its version history — that is the product. |
| The data inside those apps | Whatever you or your AI put there: lists, notes, records, preferences, and any files you attach. |
| Your email, if you ask us to keep you posted | If you leave your email on the home page, we store that address and the optional one-line answer to “what would you build?” — nothing else, no IP address, no browser details. It is used to write to you about the beta, and for nothing else. |
| Operational logs | Request-level diagnostics needed to keep the service running and to investigate faults (timestamps, endpoints, error details). Kept short-term. |
We do not collect payment details (the beta is free), we do not ask for your address or phone number, and we do not build advertising or behavioral profiles.
What we don’t do
- No third-party analytics. There is no Google Analytics, no Plausible, no PostHog, no Mixpanel, no session recorder, and no error-reporting service in this application.
- No tracking cookies. The only cookies we set are about signing you in: the one that keeps you signed in, plus a short-lived one that exists for a few minutes during the sign-in handshake and is discarded immediately after. They do nothing else.
- No selling or sharing for advertising. Not now, and if that ever changes it would require your explicit consent first — not a quiet policy update.
- We don’t read your content for product development. Access is limited to what is needed to operate the service and to investigate a fault you report.
What your AI assistant sees
This is the part that is genuinely different from an ordinary web app, so please read it.
openmcp.app works by connecting to an AI assistant you already use — Claude, ChatGPT, or another. When you ask that assistant to open or change one of your apps, the assistant requests the relevant data from us, and that data then passes through the assistant’s provider and is handled under their privacy terms, not ours.
Two consequences worth being clear about:
- You choose what to keep here. If something is too sensitive to pass through an AI assistant, it is too sensitive to store in an app you open with one.
- Your interactions with the app itself stay out of it. When you click, type, or drag inside an app, that goes directly between the app and us — the AI provider is not involved in those actions.
We have no control over, and take no responsibility for, what an AI provider does with data their assistant requests on your behalf. Their policies apply.
Who else is involved
Three parties, and that is the whole list:
- Our sign-in provider (WorkOS) handles authentication and holds your email address and name for that purpose.
- Our network provider (Cloudflare) carries traffic to our servers and therefore sees connection metadata (IP address, timing, request size).
- Your AI provider, as described above — but only for the data their assistant requests.
Your apps and their data are stored on servers we operate ourselves in Australia, not on a third-party cloud platform. If you need your data held in a particular region, this isn’t the service for you yet — tell us, because we’d like to know.
How long we keep it
- Your apps and data: for as long as your account exists.
- Backups: we take daily snapshots so a fault or mistake doesn’t lose your work. Deleted content can survive in snapshots for a short window before those snapshots rotate out.
- Operational logs: short-term only.
- Emails left on the home page: kept until the beta is over, then deleted. Ask us sooner and we’ll remove yours straight away.
Getting your data out, or getting rid of it
- Export. Your apps and their data can be exported. Ask us and we will send you a copy.
- Delete an app. You or your AI can delete any app at any time. Be aware that this removes the app, not the information it was showing: collections are shared between apps, so the items stay until they are deleted too. If your intent is to get rid of the contents, say so — “delete this app and its entries” — or ask us and we will do it.
- Delete everything. Ask us to close your account and we will delete your content from live systems promptly, and it will age out of backups as those snapshots rotate.
Depending on where you live you may also have rights to access, correct, or object to our handling of your personal data. Ask, and we will do it — we would rather answer the request than argue about whether it applies.
Security
Apps run inside a sandbox in your AI assistant’s interface, and apps that you didn’t author yourself run under further restrictions — they cannot reach the network and cannot touch data they weren’t granted. The engine’s security model is public and documented, because we would rather be checked than trusted.
No system is perfect. If you find a vulnerability, please report it privately — see contact below — and we will work on it before it becomes public.
Children
openmcp.app isn’t intended for children, and we don’t knowingly collect data from them. If you believe a child has an account, tell us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will say so on this page and update the date at the top. We will not quietly broaden what we do with your data.
Contact
Privacy questions and data requests: [email protected] (open in your mail app).
Security reports — please report privately, not in a public issue. Write to [email protected]with “SECURITY” in the subject. The same address, in machine-readable form, is published at /.well-known/security.txt; for the open-source engine you can also open a GitHub security advisory.
We aim to reply within a few days. During the beta this is a very small team, so please be patient — and please give us a chance to fix a security issue before disclosing it.