Privacy Policy

Ellis Labs MCP · Effective July 10, 2026

What this service is

Ellis Labs MCP (mcp.ellislabs.ai) is a private Model Context Protocol server operated by Ellis Labs. It connects AI assistants used by its authorized operators to accounts those operators have connected themselves — Google (Gmail, Calendar, Drive, Docs, Sheets, Contacts, Search Console), financial institutions via Plaid, DocuSign, and QuickBooks Online. It is not a public product; access is restricted to an explicit allowlist of operator accounts.

Information we access

When you connect an account, the service receives OAuth access and refresh tokens for that account and, on request, retrieves data the connected provider makes available — for example email messages, calendar events, files, contacts, bank balances and transactions, investment holdings, signature-envelope status, and accounting records. Financial access is read-only; the service cannot move money.

How information is used

Data is retrieved on demand, solely to answer requests made by the operator through their AI assistant, and is returned directly to that assistant. The service does not build profiles, run analytics on your data, use it for advertising, or use it to train models.

What is stored

The service stores only what it needs to maintain connections: OAuth tokens, connected-account identifiers (such as an email address or institution name), and operator-written account descriptors. These are held in a Redis datastore (Upstash) and transmitted exclusively over TLS. Retrieved content (emails, transactions, documents, and so on) is not stored — it passes through per request.

Sharing

We do not sell, rent, or share your information with third parties. Data flows only between the connected providers (Google, Plaid, DocuSign, Intuit), this server, and the AI assistant the operator has authorized. Infrastructure providers (Vercel hosting, Upstash storage) process data as described above on our behalf.

Google user data

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide the operator-facing features described here, is never sold or used for advertising, and is never used to train AI models.

Revoking access

Any connection can be removed at any time in the admin area, which deletes its stored tokens (and, for financial institutions, revokes the connection at Plaid). Access can also be revoked provider-side: Google account permissions, your bank's connected-apps settings, DocuSign connected apps, or QuickBooks connected apps.

Data retention and deletion

Account content (financial transactions, balances, holdings, emails, documents) is fetched on demand and never stored by this server, so its retention period is zero. Stored records are limited to access credentials and connection metadata: authorization codes expire in minutes and are single-use, access tokens expire after 24 hours, refresh tokens expire after at most 180 days and are replaced on each use, and connection records are kept only while the connection exists — disconnecting deletes them immediately. Deletion of all records associated with you can also be requested at any time via the contact below.

Contact

Questions about this policy: thellis@gmail.com.

Home · End-User License Agreement