Last updated: July 29, 2026
When you use the Service (including the public PolyDocs MCP endpoint at polydocs.arcflameinteractive.com/mcp), we may collect:
We do not read, store, or log the actual content of documents generated through the Service. Document content is processed exclusively in memory during generation and is never written to long-term storage. We do not train AI models on your prompts, documents, or usage patterns. Generated files are written to a temporary output directory and auto-deleted after 24 hours of inactivity.
We use collected information solely to:
We do not sell your personal information. We may share data with trusted third-party processors (payment gateways, Cloudflare for access control) who are contractually bound to protect your data. We may disclose information if required by law.
All API traffic is encrypted via TLS 1.3. Access to the Service is gated through Application Tokens. Our infrastructure uses industry-standard security practices. However, no system is 100% secure — we recommend you do not transmit sensitive information through generated documents.
If you are located in the European Economic Area (EEA), our lawful basis for processing your personal data is:
Your data may be processed on servers located outside the EEA, including in India and the United States. We ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms as required by applicable law.
The table below summarises what data we store, how, and for how long:
| What | Stored? | Retention |
|---|---|---|
| Document content | Processed in memory only | Not stored long-term |
| Generated files | Output directory | Auto-deleted after 24h of inactivity |
| API keys | SHA-256 hashed | In SQLite for quota tracking |
| IP addresses | Access logs | Rotated weekly, 30 day retention |
| File paths | Sanitised — local paths rejected | N/A (rejected in remote mode) |
| Usage data | Monthly counts | Individual records purged after 90 days |
Billing information is retained as required by tax regulations. You may request deletion of your account data by contacting us.
You have the following rights regarding your personal data:
To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.
We may update this Privacy Policy. Material changes will be notified via email or a notice on our website. Continued use after changes constitutes acceptance.
For privacy-related inquiries or to contact our Data Protection Officer: [email protected].