Privacy Policy
Effective September 20, 2026.
MapleMCP is operated in Ontario, Canada by the verified developer identified in the OpenAI Plugins Directory. This policy explains how MapleMCP handles personal information when you use the website, authorize the plugin, enroll a computer, contact support, or use MapleMCP tools.
Information we process
- Account information: identifiers supplied by your sign-in provider, such as email address, display name, and authentication subject.
- Device information: identifiers and basic technical details needed to identify and route requests to computers you enroll, such as device name, platform, architecture, agent version, connection status, and last-seen information.
- Authorization and security information: OAuth grants, session and security metadata, rate-limit information, and records reasonably needed to detect abuse, troubleshoot failures, and protect accounts and devices.
- Tool execution data: tool names, arguments, requested file paths or commands, notification data, visible-interface accessibility metadata, screenshots, and results may transit MapleMCP while an authorized request is completed.
- Support information: information you choose to provide when requesting support, reporting a security issue, or making a privacy request.
How we use information
We process information to authenticate users, determine which devices an account may access, route requested actions, maintain service reliability and security, enforce limits and policies, investigate abuse, provide support, and comply with applicable law. MapleMCP does not sell personal information and does not use tool execution content for advertising or to train AI models.
Tool content and your devices
File contents, command text, command output, active notification content, visible-interface accessibility data, and requested screenshots may pass through MapleMCP infrastructure while a request is being completed. MapleMCP is designed not to retain that content as an ordinary application record after the request is completed. Operations execute on the enrolled device with the permissions granted to the installed MapleMCP agent and the operating system.
On Android, Notification Access and Advanced Control are separate operating-system permissions. Notification Access can expose active notifications and media sessions. Advanced Control uses Android Accessibility to inspect and interact with the visible interface and, when requested, capture a bounded screenshot. You can disable either permission in Android Settings. MapleMCP does not bypass Android PIN, password, biometric, or lock-screen security.
When you use MapleMCP through ChatGPT or another AI service, that provider may also process the information you send or receive under its own terms and privacy policy.
Service providers and transfers
We use service providers for hosting, edge networking, security, authentication, and related infrastructure. These may include Cloudflare, the AI service through which you invoke MapleMCP, and an identity provider you choose for sign-in. Providers may process information outside Canada. We require service providers to handle information only for legitimate service purposes and subject to their own legal obligations.
Retention
We keep account and enrolled-device records while needed to provide MapleMCP and for a limited period afterward when reasonably necessary for account recovery, fraud prevention, disputes, security, or legal obligations. Security and diagnostic metadata is retained only as long as reasonably necessary for those purposes. Tool execution content is intended to remain transient unless you deliberately save it on your own computer or provide it to support.
Your choices and rights
You may stop using MapleMCP, disconnect an enrolled device, revoke authorization, change MapleMCP capability groups, disable Android Notification Access or Advanced Control, or request access to, correction of, or deletion of personal information that MapleMCP controls, subject to applicable legal and security exceptions. You may also withdraw consent where applicable, although doing so may prevent MapleMCP from providing the affected feature.
See Permissions & Control Levels for a plain-language description of what each capability enables.
Cookies and authorization state
MapleMCP uses only cookies or similar session state that are reasonably necessary for sign-in, authorization, security, and service operation. MapleMCP does not use advertising cookies.
Security
We use technical and organizational safeguards appropriate to the nature of the service and the sensitivity of the information involved. No online service can guarantee absolute security.
Privacy contact
The MapleMCP Privacy Lead is responsible for privacy inquiries. Access, correction, deletion, consent-withdrawal requests, and complaints may be sent to [email protected] with the subject "MapleMCP Privacy".
Changes
We may update this policy as MapleMCP changes. Material changes will be communicated where required by applicable law, and the effective date above will be updated.
