Privacy policy

Last updated 5 September 2026

MCP Hub ("the hub") is a private tool operated by Zynora Technologies ("we") for the businesses it serves. It is not offered to the public. This policy explains what the hub stores when an authorised person connects a business's accounts to it, and how that information is used.

What the hub stores

When you connect a service, the provider (Google, Meta, HeyGen or another) issues the hub an access token, and where offered a refresh token, for the account you signed in with. The hub stores those tokens encrypted at rest, together with the identifiers needed to use them: which business the connection belongs to, the email address of the person who connected it, when it was connected, and where you have chosen one, the specific Page, account or property the connection is pinned to. For services that use an API key instead of sign-in, the key is stored encrypted in the same way.

The hub does not keep copies of the data those services return. Reports, posts, reviews, analytics and videos are fetched when an assistant asks for them and passed through to that assistant; they are not written to storage by the hub. Images an assistant supplies for publishing are held for up to one hour so the destination service can fetch them, then expire. Standard request logs (URL, status, timing, no bodies) are retained by our hosting provider for a short period for operational troubleshooting.

How it is used

Tokens and keys are used for exactly one purpose: to carry out the actions that an authorised person, or an AI assistant acting on their instruction, requests through the hub for that business. We do not sell, rent or share this information, do not use it for advertising, and do not use it to train models.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The hub requests only the scopes each connector needs: managing Business Profile listings, reading Search Console data, reading Analytics data, and managing the business's own Google Ads accounts (reporting, keyword research, and campaign changes the person has approved).

Who can access it

The dashboard and every MCP endpoint sit behind Cloudflare Access (only this page, the terms and the home page are public), and only email addresses the operator has explicitly allowed can sign in. AI assistants reach the hub through an OAuth flow that also requires one of those allowed identities. Zynora Technologies staff who administer the hub can see which businesses and services are connected; they cannot read the stored tokens in plain text.

Deleting your data

Disconnecting a service on the dashboard deletes its stored tokens or key immediately. Deleting a business deletes every connection under it. You can also revoke the hub's access from the provider's side at any time, for example in your Google Account under third-party access, which makes the stored token useless.

Contact

Questions about this policy or a request to delete data: justine@zynoratechnologies.com.