Legal

Privacy Policy

Last updated: July 8, 2026

MCP Tutor is an AI-literacy training tool. Teaching, conversation, and assessment happen inside Claude; MCP Tutor is the progress-tracking and content-delivery layer behind it. This policy explains what data we collect, how we use and store it, who we share it with, and how long we keep it.

What we collect

  • Account information. Your name, email address, and the organization you belong to, plus your role (member, manager, or admin) and plan.
  • Training progress. Which chapters you have started or completed, timestamps, and scores.
  • Demonstration records. The text you submit for a chapter’s demonstration and the written assessment of it. This is the core function of the product — recording your practice attempts.
  • Playbook records. The playbooks you create (their titles, descriptions, and step content) and a log of your playbook runs — which playbook you ran, how many steps you completed, optional verification notes, and timestamps — used to power the usage view for your organization’s admins.
  • Operational logs. Request metadata (timestamps, the tool invoked, latency, and error class) used to operate and debug the service. We do not log the content of your Claude conversations.

We do not request or access your Claude memory, chat history, files, or any data outside the training records described above. We do not collect health data, and we do not sell personal data.

How we use it

  • To deliver curriculum content and track your progress through it.
  • To walk you through your playbooks and log runs for your organization’s usage view.
  • To show managers and admins aggregate progress for their own organization.
  • To authenticate you and operate, secure, and debug the service.

How we store and secure it

Data is stored in a Postgres database (Supabase) with row-level security that limits each account to its own records and each organization to its own members. Connections use HTTPS/TLS. Access to the training server is authenticated with OAuth 2.0 — Claude obtains a short-lived access token after you sign in and authorize the connection; tokens are never placed in URLs.

Who we share it with (sub-processors)

We use the following service providers to run MCP Tutor:

  • Supabase — database, authentication, and storage.
  • Railway — hosting for the MCP server.
  • Vercel — hosting for the web dashboard.
  • Resend — transactional email (sign-in codes).
  • Anthropic (Claude) — the AI client you connect; your conversation happens in Claude under Anthropic’s own terms and privacy policy.

We share data with these providers only as needed to operate the service. We do not sell or rent personal data, and we do not share it for advertising.

Retention

We keep account, progress, demonstration, and playbook records for as long as your account is active. When an account or organization is deleted, its progress, demonstration, and playbook records are deleted with it. Operational logs are retained for a limited period for debugging and security and then rotated out.

Your choices

You may request access to, correction of, or deletion of your personal data by contacting us. Organization admins can remove members, which deletes the member’s associated progress and demonstration records.

Contact

Questions about this policy or your data? Email privacy@mcptutor.com (or support@mcptutor.com for general support).

Changes

We may update this policy as the service evolves. We will revise the “last updated” date above when we do.