Privacy Policy
Plain-language summary — a fuller legal document will replace this before general availability.
We store your email, username, a password hash (argon2id), your subscription state, and metadata about your endpoints (service, status, connected account email, daily request counts). For the AI apps you sign in and the API keys you create we keep each app's name and the host it returns to, the name and version it reports, each key's label and first characters, and when each was created and last used. OAuth tokens and API keys are stored only as SHA-256 hashes, never in plaintext, so nobody can read them back; the dashboard shows a key in full only once.
OAuth credentials for connected services (for example, Google refresh tokens) live in an isolated per-endpoint container volume, not in the web application. Request contents that flow between your AI client and the connected service are proxied, not logged; our application logs carry endpoint IDs, never tokens or message bodies.
Payments are handled by Stripe; we never see your card number. We use your email only for account verification, password resets, and service notices — no marketing without consent, no selling data, ever.
Deleting an endpoint destroys its container and archives its data for a short retention window before removal. Contact us to delete your account entirely.
Unofficial Telegram connector
The Unofficial Telegram connector is an unofficial client built on the Telegram API. MegaMCPs is not affiliated with Telegram. Connecting it signs in to your Telegram account as a device called “MegaMCPs”.
Chats, messages and contacts are fetched from Telegram on demand, only when your AI client calls a tool, and passed to that client; we do not keep copies of your messages. MegaMCPs never uses Telegram data to train AI models.
The Telegram login session is stored only in the container dedicated to your connection, as a file on our server. It never enters our database or logs and is never backed up or copied. Besides the login it holds Telegram's usual cache of the accounts and chats it has seen (IDs, usernames, names and, where Telegram shows them to you, phone numbers) and any contact aliases you create through the connector; all of it is deleted with the session.
Our database keeps your Telegram user ID, the account label shown in your dashboard (your username or first name, deleted when that session is signed out), and a history of your sign-in attempts and disconnections.
Disconnecting signs MegaMCPs out of your Telegram account on Telegram's side and deletes the session. If Telegram stays unreachable for 24 hours we delete the session anyway and ask you to end the “MegaMCPs” device yourself in Telegram → Settings → Devices.