# Privacy policy – Vizbl MCP connector

How the Vizbl MCP connector at https://mcp.vizbl.com handles the data that passes through it. Last updated 28 July 2026.

HTML version of this page: https://mcp.vizbl.com/privacy

## Scope

This policy covers the Vizbl remote MCP connector only – the service that lets an AI client such as Claude call the Vizbl Developer API on your behalf. Data stored in your Vizbl account is additionally governed by the agreement between you and Vizbl for the Vizbl platform.

The connector is operated by Vizbl. Contact: support@vizbl.com

## What we collect

- **Your Vizbl secret API key.** Supplied by you on the consent screen when you authorise a client.
- **Tool call arguments.** Only what a tool needs: the download URL of a model file you attached, optional metadata you asked to set (name, description, tags, category, placement), import job ids, and object identifiers.
- **Model files.** Fetched from the download URL your client provides, so they can be forwarded to the Vizbl Developer API.
- **Operational logs.** Standard server logs – timestamp, request path, response status, error messages, and duration – used to run and debug the service. Logs do not contain your API key or the contents of your model files.

We do not request or receive your conversation history, Claude memory, chat summaries, or any files other than the model file referenced by an import you asked for.

## How we use and store it

- **Your API key is never stored on our servers.** The connector is stateless: your key is encrypted into the OAuth access and refresh tokens issued to your client, and it exists on our side only in memory, for the duration of a request that uses it. There is no database of users, keys, or connections.
- **Model files are processed in transit only.** A file is held in memory, uploaded to the Vizbl Developer API under your account, and then released. The connector keeps no copy.
- **Imported models are stored in your Vizbl account** exactly as if you had uploaded them through the Vizbl app, and are subject to your account settings.
- **We do not use your data to train models** and we do not sell it.

## Sharing with third parties

The connector talks to the Vizbl Developer API and to nothing else. We do not send your data to advertising networks, analytics vendors, or AI providers.

Two categories of processor are unavoidable and act on our instructions only: the infrastructure provider hosting the service and the object storage holding your Vizbl account's files. The AI client you connect from (for example Claude) is operated by its own vendor under that vendor's terms – this policy does not cover it.

We may disclose information where legally required, and will do so as narrowly as the law permits.

## Retention

- **API keys:** not retained – held in memory during a request only.
- **Model files in transit:** discarded once the upload completes or fails.
- **OAuth tokens:** held by your client, not by us. Access tokens expire within the hour; refresh tokens expire after 90 days.
- **Operational logs:** retained up to 30 days, then deleted.
- **Imported models and their metadata:** retained in your Vizbl account until you delete them, through the app, the API, or the connector's delete tool.

## Your choices

- **Disconnect at any time** by removing the connector in your client, or revoking the secret API key in your Vizbl account – revoking a key immediately invalidates every token that carries it.
- **Limit what a connection can do** by approving only the scopes you need; tools outside the granted scopes are not exposed to the client at all.
- **Access or delete your data** through your Vizbl account, or by writing to us at the address below.

## Security

All traffic is served over HTTPS. OAuth follows the Model Context Protocol authorisation spec with PKCE, encrypted authorisation codes, and tokens bound to the client that requested them. Report a suspected vulnerability to support@vizbl.com.

## Changes

If this policy changes materially we will update the date at the top of this page. Continued use of the connector after an update means you accept the revised policy.

## Contact

Vizbl – support@vizbl.com – https://vizbl.com
