Privacy Policy

This page says what docs2mcp collects, who else sees it, where it is processed and how long it is kept. It describes what the service does today, not what it might do later.

Who we are

docs2mcp is operated by Bojan Gasparovic, registered in Spain. Bojan Gasparovic is the controller of everything described here.

[email protected] is the address for every request on this page, and for anything here you think is wrong.

What we collect

We ask you for no name, no job title and no company. If a document you upload contains any of those, we hold it because it is in your document, not because we asked for it.

Why, and on what basis

Everything needed to run the service — storing a document, converting it, indexing it, answering a search, keeping your account attached to your documents — we process to perform our contract with you.

The counts, and the record of which tool ran when, we process on our legitimate interest in keeping the service standing up: enforcing a plan's ceilings and its rate limits, and investigating abuse. The ledger we keep on the same interest, for the one thing it answers — what the service costs us to run.

The record of what you paid us we keep because tax law obliges us to.

Who else processes it

That is the whole list. We sell nothing to anybody, and we use your documents to train no model of our own.

One more company can end up holding the contents of your documents, and it is not on that list because we did not hire it: the AI client you connect. The next section is about that one.

Connecting an AI client

The connector is how an AI client — Claude, ChatGPT, Cursor, or another one that speaks the same protocol — reads the documents you uploaded. You connect it from inside that client and approve the connection on a screen we serve. Nothing is connected until you do that, and connecting is optional: uploading works without it.

What the client gets back is the contents of your documents. A search returns the text of the passages that matched, the title we extracted, which pages they came from and a link to the region on the page. Asking about one document returns its filename, its page count and every field we extracted from it. Asking about one table cell returns the whole row it sits in. All of that leaves us and arrives inside the client, where the company operating the client handles it under their privacy policy and not this one. We did not choose that company and we hold no agreement with it. You chose it, and what they say they do with what they receive is worth reading before you connect.

The connector only reads. It offers five tools — list your documents, list your collections, describe one document, search, and expand one result — and not one of them can create, change or remove anything. An AI client connected to your library cannot add to it and cannot delete from it.

What a tool call writes is on our side. One line in the log described above, naming which tool ran and when, and carrying the words of the search when the tool was a search. That text is composed by the AI client out of your conversation with it rather than typed by you, and we keep it the same way we keep a search you typed yourself. Two counters move as well: how many questions your organisation has asked in the current period, and how many requests it has made in the current minute.

A search made through the connector goes to OpenAI to be turned into an embedding before it can run, exactly like any other search. The section below says more about that transfer.

The links in a result are not keys. Opening one asks you to sign in as yourself first, so a link that has travelled into a transcript or anywhere else opens nothing on its own.

Signing in goes through Supabase, our sign-in provider. The client ends up holding an access token, never a password, and there is no password here for it to hold. Removing the connector inside the client ends its access. If you connected without an account, its access ends when your 48 hours run out.

Where it is processed

Everything we run ourselves sits within the European Union. Our servers and our database are on Railway, in its Amsterdam region. The files you upload live in Cloudflare R2, under R2's EU jurisdiction. Your sign-in identity is with Supabase, whose region is eu-west-1 — Ireland. Two countries, which is why this section names a union rather than a city.

Text from your documents is sent to OpenAI, and so is every search you run. It goes on two occasions: when we build the index, to generate the embeddings and extract the metadata that make search work, and each time a search runs, to turn the words you searched for into the same kind of embedding. There is no way to use docs2mcp without that happening, and running everything else within the European Union does not change it. If your documents are confidential, this is the paragraph to read twice.

How long we keep it

If you upload without an account, your documents go 48 hours after your first upload. The following go with them: the files, the text taken from them, the search index, your searches, and the anonymous identity itself. Creating an account before then keeps your documents and stops that clock.

With an account, your documents stay until you remove them, except on the Free plan, where a document may be removed 30 days after it was uploaded and we email you before that happens.

Four kinds of record about your use of the service outlast your documents, and none of them holds any part of one. We keep your searches, which hold the words you typed and not the passages we returned. We keep a count of what your organisation used, which holds no words at all. If you have paid us, we keep the record of what you paid and when. And we keep the ledger of what our own model calls cost us.

Closing your account, or letting the 48 hours run out, takes the first of those with it: your searches go, with your documents and everything taken from them. It does not delete the organisation's own record, and nothing here does. What is left of that record is identifiers, the dates it was created and closed, and the counts — no name of a person, no email address, no filename, and no word of a document or of a search. Three things stay beyond that record. The record of what you paid, for as long as tax law requires us to hold it. Stripe holds a copy of that record too: the payer's email address, and a billing address where Stripe asked for one. Nothing here deletes Stripe's copy. The ledger, which is token counts and amounts of money, and which never carries a word of a document or of a search. And one thing that was not on that list: your email address, if you created an account. It sits with Supabase, our sign-in provider, and no deletion here reaches it — we remove it by hand when you ask. An identity created without an account never carried an address, and goes with everything else.

Your rights and how to use them

To erase your documents yourself: open your account page, find Danger zone, and use Delete all documents. It takes effect the moment you confirm it, and waits for nobody here.

To close your account entirely: use Request account deletion on the same page, which opens an email to us. That one is not automatic — a person acts on it, within 30 days.

You can also ask us for a copy of what we hold about you, for a correction to it, for it in a portable form, or to object to our processing it. Write to [email protected] and we will answer within 30 days.

If you think we have handled your data badly, tell us first if you are willing to. Either way, you can complain to the data protection authority of the country you live in.

Cookies and local storage

This site sets no cookies. There is no analytics, no tag manager and no third-party script on any page of it.

Nothing on these pages comes from anywhere but us. The fonts are served from this domain rather than from Google, so loading a page tells no third party that you were here.

The app at https://app.docs2mcp.com keeps your sign-in session in your browser's localStorage. That is not a cookie and is never sent to us on its own, but it is data stored on your device, and clearing your browser storage signs you out.

The waitlist

These pages used to carry a waitlist form. The form and the endpoint behind it were removed in August 2026, and nothing on this site asks for your email address now. The Cloudflare D1 table the form wrote to was checked after it came down and held no addresses at all.

If you believe you gave us an address that way, write to [email protected] and we will look and remove it.

How to contact us

Write to [email protected]. That is the address for every request on this page, for a question about anything on it, and for anything here you think is wrong. It is the only address we ask you to use for this, and it reaches Bojan Gasparovic in Spain.

Changes

We may change this policy. The date at the top of this page is the date it last changed, and the version on this page is the version that applies.

Where a change materially affects your rights, we will email the address on your account before it takes effect. If you use the service without an account, check this page.