Privacy Policy
Last updated: July 12, 2026
1. What we collect
- Email address when you join the newsletter or subscribe to the MCP. Newsletter emails are stored in our database and sent to our email provider (beehiiv).
- Billing information when you subscribe. Payment is processed by Stripe. We never store or see your full card number.
- Your MCP access key and subscription status, stored so the MCP can authenticate your requests and so cancellation can revoke access.
- Usage data, such as basic operational logs and first-party analytics events (pageviews and interactions on this site) used to keep the service reliable and improve it.
2. How we use it
We use your email to send the newsletter (via beehiiv) and, if you subscribe, to send your MCP key and receipts (via Resend and Stripe). We use billing data to process your subscription (via Stripe) and analytics to understand and improve the site. We do not sell your data, share it with advertisers, or use it for third-party advertising.
The MCP itself is retrieval-only. When your agent asks a question, our server matches it against our own knowledge base and returns sourced claims. We do not store the content of your MCP questions, and we do not send them to any third-party AI provider. The synthesis happens in your own coding agent, on your side.
3. Sub-processors
We rely on a small number of third-party providers to operate the service. Each processes only the data needed for its function:
- Convex: backend and database. Stores newsletter emails, MCP access keys, and subscription status.
- Vercel: application hosting and content delivery.
- Stripe: payment processing. Handles your card details directly; we never store card numbers.
- beehiiv: newsletter delivery. Receives your email address to send the newsletter you subscribed to.
- Resend: transactional email. Sends your MCP key and account emails from hello@tasu.ai.
- PostHog: first-party product analytics. Pageviews and interaction events, EU-hosted and reverse-proxied through our own domain, never used for advertising.
If you use the optional in-app diagnostic (by connecting your own RevenueCat, PostHog, Superwall, or GitHub account), we read that data read-only to produce your diagnosis, relevant excerpts are sent to Anthropic (Claude) for analysis under its commercial API terms and not used to train its models, and your connector credentials are encrypted at rest. You can revoke any connector at any time.
4. Retention and deletion
We keep your data while your subscription or newsletter membership is active. You can unsubscribe from the newsletter at any time from any email, and you can request full deletion of your data by emailing hello@tasu.ai. Deletion is completed within 30 days.
5. Your rights
Depending on where you live (including under GDPR and CCPA), you have the right to access, correct, export, or delete your personal data, and to object to its processing. Contact us to exercise any of these rights.
6. Cookies and analytics
We use the cookies required for security, plus first-party product analytics from PostHog to understand how the site is used: pageviews and interaction events such as clicks. These run on our own domain (EU-hosted) and are never shared with advertisers. We do not use third-party advertising trackers, and we do not record your screen or session.
7. Contact
Privacy questions and requests: hello@tasu.ai.