MCP Privacy Policy
Version 1.0. Effective date: 15 August 2026. Last reviewed: 13 August 2026.
The Senaro MCP endpoint at https://mcp.senaro.ai/mcp only. The senaro.ai website is a separate service with its own privacy policy, and it does use analytics and cookies, including on this page. This endpoint sets no cookies and runs no analytics script. See "Links back to senaro.ai" below for the one tagged link it does emit.
Today this endpoint is a stateless calculator. There is no account, no login, and no database behind it. The financial figures you send are used to compute a response and then discarded.
The financial figures you send are not stored
Balances, interest rates, income, home prices, loan terms. These exist in server memory for the fraction of a second it takes to run the calculation and return an answer.
We do not use a database for this endpoint, and we do not intentionally log, cache, back up, or train on the figures you send. We design our error handling to avoid capturing request contents in diagnostic telemetry, but we cannot guarantee that a rare unhandled error will never record a value in a diagnostic record. Any such record is deleted on the schedule below.
There is no user account to delete, because this endpoint does not create one.
What we do record
Our monitoring records operational facts about each call:
- which tool was called
- the size of the response in bytes and how long it took to produce
- whether it succeeded or returned an error
- the timestamp
- an approximate location (city, region, country) derived from the caller's IP address
These are the operational fields our monitoring is configured to record. It is not designed to record request contents or response contents.
Links back to senaro.ai
Every calculation tool's response includes a link to senaro.ai carrying a tag that identifies which tool produced it. Following the link is optional. The website is a separate service with its own privacy policy, and unlike this endpoint it uses analytics and cookies.
Your IP address
Your IP address is processed while the call is in flight: to route the request and return the response, to derive the approximate location above, and to enforce rate limits that keep the endpoint available.
We rely on the default Azure Application Insights configuration, which uses the IP address for the location lookup and then masks it, storing 0.0.0.0 in place of your address. We do not enable IP storage and do not keep IP addresses in our records.
Rate limiting uses short-lived, in-memory counters keyed to your network address. These are not written to our records and expire continuously.
What this endpoint does not collect
- Accounts, usernames, passwords. None exist here.
- Cookies. This is a JSON-RPC API, not a website. It sets no cookies and there is no browser session.
- Names, email addresses, phone numbers, postal addresses, account numbers. We do not ask for any of these. A few optional fields take a short label, like a nickname for a card, and those accept free text. Do not put identifying information in them. Anything you do send is processed only transiently as part of your request and is not stored against any identifier.
- Tracking pixels, advertising identifiers, and device fingerprints. This endpoint uses none of these.
How long we keep things
Operational telemetry is deleted automatically after 90 days. Nothing else is kept, because nothing else is stored.
Who else is involved
Microsoft. Senaro runs on Azure App Service and is monitored with Azure Application Insights, both operated by Microsoft. Microsoft is our subprocessor for hosting and monitoring, and processes the operational telemetry described above on our behalf. Our hosting region is West US 2, in the United States. Where telemetry is processed outside the EEA, the transfer relies on Standard Contractual Clauses.
Your AI assistant. Your numbers pass through whichever assistant you used, such as Claude, ChatGPT, or another MCP client, before they ever reach us. That part of the trip is governed by that provider's privacy policy, not this one. We have no relationship with them and no visibility into what they keep. If it matters to you, read their policy too.
Nobody else. We do not sell, rent, trade, or share data with advertisers, data brokers, affiliates, or anyone else. There is nothing to sell.
GDPR
Where the GDPR applies, the controller is the operator of senaro.ai, contactable at info@senaro.ai. We have not appointed a data protection officer, because our processing does not require one.
Our legal basis is legitimate interests under Article 6(1)(f): keeping a free service running, secure, and available, which covers security monitoring, rate limiting, and capacity planning.
Operational telemetry is retained for 90 days, as described above.
Because that processing relies on our legitimate interests, you have the right to object to it at any time under Article 21(1) by contacting info@senaro.ai. You also have the rights of access, rectification, erasure, restriction of processing, and data portability where they apply, and the right to lodge a complaint with your local data protection supervisory authority.
This endpoint stores no identifier that links telemetry to you, so in most cases we will not be able to locate records connected to a specific person. Article 11 addresses this situation. If you can supply information that lets us identify the relevant records, we will act on your request.
We do no profiling and no automated decision-making that produces legal effects.
California
We do not currently meet the CCPA applicability thresholds, so its obligations as a "business" are unlikely to apply to this endpoint. We follow its principles anyway.
Using the statutory categories, the operational telemetry described above may include identifiers, internet or other electronic network activity information, and coarse geolocation data. It is collected to operate, secure, and maintain the service, and is retained for 90 days.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, so no "Do Not Sell or Share My Personal Information" mechanism applies. We do not collect sensitive personal information.
California residents may write to info@senaro.ai to request access, deletion, or correction. As above, this endpoint generally holds nothing tied to an identifiable person, and we will tell you so plainly.
We review this policy at least once every 12 months.
Minors
This endpoint is a general-audience calculator. It is not directed to children or to minors, and we do not target them. New York's Child Data Protection Act protects users under 18, and we do not knowingly process the data of anyone under that age.
Security
All traffic is encrypted in transit with TLS. The financial figures you send are not stored at rest. The limited operational telemetry described above is retained for the stated period and protected by our provider. Minimizing what we store is a deliberate design choice, and it is the main reason the service is built this way.
If a security incident ever affected personal data we hold, we would notify affected people and the relevant authorities as the law requires.
Changes
If this policy changes, we will update the effective date at the top. Material changes will be noted on this page, and will apply only to data collected after they take effect.