Privacy Policy
Last updated: June 2026
This Policy explains what data OverMCP collects and how it is used. This is a template starting point and not legal advice — have it reviewed before launch.
1. Data we collect
- Scan inputs: URLs and repositories you submit, and the public code/content fetched from them.
- Scan results: findings, scores, and reports generated from your submissions.
- Contact: your email address when you request a report or enable monitoring.
- Payments: payment identifiers from NOWPayments. We do not store card or wallet credentials.
- Connected platforms: OAuth tokens you authorize (GitHub, Vercel, Netlify, etc.), used only to perform actions you request.
2. How we use data
- To run scans, generate reports, and deliver fixes/deploys you request.
- To send transactional and monitoring-alert emails (via Resend).
- To process payments and unlock paid features.
3. Third-party processors
We share data with service providers strictly to operate the Service: DeepSeek (AI analysis), Turso (database), Resend (email), NOWPayments (payments), and your connected hosting/Git platforms. Submitted code may be sent to the AI provider for analysis.
4. Retention
Scan records and monitoring configurations are retained to provide the Service. You can request deletion of your data or stop monitoring at any time.
5. Your rights & contact
To request access or deletion of your data, contact privacy@overmcp.app.