Privacy Policy
This policy describes how CaleraLabs processes data when you use our hosted APIs, dashboards, and agent integrations — including the FinanceSec Model Context Protocol (MCP) server.
1. What we process
- Account data: email, auth identifiers (Firebase), organization membership, billing metadata (Stripe).
- License / API keys: used to authenticate
/api/query, MCP tool calls, and spreadsheet connectors. Keys are secrets; we do not publish them. - Query text & responses: natural-language questions you submit to FinanceSec (HTTP API or MCP
query_financial_sec), plus verified answers orSAFE_REFUSALoutcomes and provenance metadata (filing accession, XBRL concept, audit hash). - Operational telemetry: request timestamps, latency, HTTP/MCP status codes, auth failure counts, region — for reliability and abuse prevention. We do not log full license keys or OAuth access tokens.
- OAuth consent (MCP Directory path): when you approve Claude (or another MCP client), we bind your chosen FinanceSec license to an access token. Consent can be revoked by rotating the license key.
2. MCP / agent-specific notice
FinanceSec MCP is a transport to our verified fact API. The MCP server does not call OpenAI, Anthropic, Gemini, or any other LLM to invent or polish financial numbers. Agent clients (Cursor, Claude, VS Code) may process tool outputs under their own privacy terms — review those products separately.
Install documentation: finsec.caleralabs.com/mcp.
3. Purpose & legal bases
- Provide the contracted API / MCP service and meter usage against your license.
- Security, fraud prevention, and incident response.
- Product reliability (uptime, latency) and support (48h SLA target for pilot tickets).
- Legal compliance and enforcement of acceptable use.
4. Retention
- Query / MCP operational logs: retained for up to 90 days for debugging and abuse review, then deleted or aggregated, unless a longer period is required for an active incident or legal hold.
- Account & billing records: retained for the life of the account plus applicable tax/accounting periods.
- OAuth auth codes: short-lived (minutes). Access tokens expire; refresh tokens rotate and are invalidated on license revoke.
5. Subprocessors
- Google Cloud Platform — Cloud Run hosting (API + MCP), Cloud Storage (EDGAR corpus ops), Firestore, Cloud KMS (LLM vault envelope only — not on the MCP fact path).
- Firebase Authentication — console sign-in.
- Stripe — payment processing.
- Firebase Hosting — static marketing and FINSEC web UI.
We do not send FinanceSec query contents to third-party LLM providers for fact generation.
6. Sharing
We do not sell personal data. We share data with subprocessors under contract, or when required by law, or with your direction (e.g., connecting an MCP client you control).
7. Security
TLS in transit for hosted services. License keys and OAuth tokens must not appear in public docs or screenshots. Distroless non-root containers for MCP. Report security issues to support@caleralabs.com.
8. Your rights & contact
Depending on your jurisdiction, you may request access, correction, or deletion of account personal data, or contact pilot / product support, by emailing support@caleralabs.com.
9. Changes
We may update this policy; the effective date above will change. Material MCP logging changes will be reflected on this page and linked from the MCP install docs.