Privacy Policy
Effective October 7, 2026
This policy explains what personal data Megido collects about the people who use the MCP server, the customer portal and this website, why, and what rights they have. Megido is the controller of this data. Contact: [email protected].
1. What we collect
Your account. Your email address and name, your password (stored only as a one-way hash), your second-factor secret if you set one up (stored encrypted), the organizations you belong to and your role in each, and when you accepted the Terms of Service and this policy.
Signing in. The IP address and time of each sign-in attempt and of each session, and the expiry of your sessions. Session and access tokens are stored only as hashes.
Using the service. Each call your organization makes: which tool, when, its status, its price, and which API key or chat app made it and for whom. The estimates behind paid calls, with their parameters. The full responses of paid calls. The projects your organization revealed and the profile parts it bought. A log of changes to accounts, keys, connections and organization settings, with who made them.
Feedback. The messages your agents send us with the feedback tool, the projects or niches they name, who sent them and through which API key or chat app, and our progress on them. A message may contain whatever the agent or you wrote into it.
Chat apps. When you connect a chat app, its name and address, and the authorizations you gave it.
This website. The website sets no cookies and runs no analytics or advertising. Your browser may store your choice of color theme locally. Our servers record requests, including IP addresses, in technical logs kept for a short time.
We do not collect payment card details.
2. Why we use it
- To provide the service under our agreement with your organization: accounts, sign-in, calls, billing in credits, reveals and purchases. Legal basis: performance of a contract.
- To keep the service and its data secure: detecting abuse, fraud, automated extraction and unauthorized access. Legal basis: our legitimate interests.
- To understand demand and improve the service, including by reading and answering feedback. Legal basis: our legitimate interests.
- To keep records the law requires, such as accounting records. Legal basis: legal obligation.
We do not sell personal data and do not use it for advertising.
3. Cookies
The portal uses two strictly necessary cookies that keep you signed in: an access cookie and a refresh cookie. They hold random tokens, are not readable by scripts, and are not used for tracking. The website uses no cookies.
4. Who sees it
- Your organization. Owners of an organization see its members, their keys and connected chat apps, and the calls each of them made. Every member sees the organization's feedback and our progress on it.
- Our service providers. Hosting and infrastructure providers process data for us under contracts that bind them to our instructions.
- Authorities and successors. We disclose data when the law requires it, and to a successor if the service changes hands.
5. International transfers
When data is processed outside the United Kingdom or the European Economic Area, we rely on adequacy decisions or on standard contractual safeguards.
6. How long we keep it
- Full responses of paid calls: 30 days.
- Sessions: until you sign out, or 30 days at most.
- Sign-in attempts and technical logs: a short time, for security.
- Your account, your organization's call records, feedback, reveals, purchases and change log: while your account exists. Afterwards we delete or anonymize them within a reasonable period, unless the law requires us to keep them longer.
7. Security
Passwords are hashed with a modern password hash, second-factor secrets are encrypted, and session tokens and API keys are stored only as hashes. Access to the systems is restricted to the people who run the service.
8. Your rights
Depending on where you are, you may have the right to access your personal data, to correct it, to have it deleted, to restrict or object to its processing, and to receive it in a portable form. To exercise them, write to [email protected]. You may also complain to a data protection authority; in the United Kingdom, this is the Information Commissioner's Office.
9. The market data
The data the service returns describes websites, not the people who use Megido. If you believe it includes personal data about you, write to [email protected].
10. Children
The service is for businesses and is not meant for anyone under 18.
11. Changes
We may update this policy. Each version shows its effective date at the top, and the portal asks you to accept a new version before you continue using the service.