Privacy Policy
This policy applies to the Blocksize Capital developer portal, public remote MCP discovery server, authenticated OpenAI, Claude, and Cursor MCP connectors, and paid HTTP market data API made available at mcp.blocksize.info.
What We Collect
- Basic request metadata such as timestamps, user agent, and network-level diagnostics needed to operate and secure the service.
- Free discovery queries, such as symbol searches and service listings, so we can monitor reliability and product usage.
- OAuth account identifiers and scopes needed to authenticate connector users, isolate account entitlements, and prevent abuse. Direct identifiers are not returned in connector credit responses.
- Read-only connector tool names, requested instruments, result status, credit accounting, and reliability diagnostics needed to deliver and audit the service.
- Wallet identifiers, payment headers, or credit headers when you use paid or credit-based routes.
- Payment proof material, transaction hashes, and related verification data when x402 settlement is used.
- Support communications you send to us directly.
How We Use Data
- To deliver discovery responses, documentation access, and paid market data.
- To authenticate connector users and maintain account-scoped starter-credit records.
- To verify payment proofs, prevent replay attacks, and reduce fraud or abuse.
- To troubleshoot outages, improve latency, and understand which product surfaces are being used.
- To respond to support requests and maintain service quality.
AI and Model Training
Blocksize does not use MCP connector request content, plugin data, or user content to train machine-learning or generative-AI models. We process this data only for the operational, security, support, analytics, billing, and compliance purposes described in this policy.
Retention
We retain operational, security, and billing-related records only for as long as they are reasonably needed for service delivery, fraud prevention, debugging, compliance, or contractual obligations. Retention periods can vary by log type and use case.
Sharing
We may use infrastructure and analytics subprocessors to run the service, but we do not sell request data or wallet activity data. We may disclose data where required by law or to protect the security of the service and its users.
Your Choices
If you need additional information about data handling, enterprise retention expectations, or a data access request, contact us through the support channel listed on the support page.