Legal
Privacy Policy
CostMCP helps builders track AI project spend. This policy explains what we collect, why we collect it, and the choices you have.
Who we are
CostMCP is operated by Yang Space. When this policy says “we,” “us,” or “CostMCP,” we mean Yang Space and the CostMCP service available at costmcp.com and related subdomains.
Questions about privacy can be sent to support@costmcp.com.
Information we collect
- Account information such as your email address, display name, and profile details when you sign up or sign in (including via Google OAuth).
- Workspace and project data you create in CostMCP, including project names, cost records, budgets, subscriptions, and related metadata.
- API keys and OAuth connection records used to authenticate your integrations and connected MCP clients.
- Usage and technical data such as IP address, browser type, device information, and logs needed to operate, secure, and improve the service.
How we use information
- Provide, maintain, and improve CostMCP, including dashboards, APIs, and MCP tools.
- Authenticate users, authorize API and OAuth access, and prevent abuse.
- Respond to support requests and communicate about the service.
- Comply with legal obligations and enforce our Terms of Service.
How we share information
We do not sell your personal information. We share data only with service providers that help us run CostMCP (for example, hosting and database providers such as Supabase and Vercel), when required by law, or with your direction (for example, when you connect an MCP client through OAuth).
Cost records and usage metadata you submit may reference third-party AI providers (such as OpenAI or Anthropic). That data is stored to give you reporting and is not shared with those providers by CostMCP unless you choose to send it elsewhere.
Data retention
We retain account and cost data for as long as your account is active or as needed to provide the service. You may request deletion of your account by contacting support@costmcp.com.
Security
We use industry-standard safeguards including encrypted transport (HTTPS), access controls, and row-level security in our database. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your choices
- Access and update profile information from your account settings.
- Revoke OAuth connections and API keys from your workspace dashboard.
- Contact us to request access, correction, or deletion of personal data, subject to applicable law.
Children
CostMCP is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date above.
Contact
Email support@costmcp.com or visit https://costmcp.com/support.