Privacy Policy
Effective August 17, 2026
What we collect
- Account data: the email address you subscribe with.
- Usage data: API request logs (endpoint, timestamp, API key, response status) and standard web server logs (IP address, user agent), used for operating the Service, rate limiting, metering, and abuse prevention.
- MCP connections: when you connect an AI client (for example Claude or Cursor) to our MCP server through OAuth, we store the client's registration, the access and refresh tokens we issue (hashed), the tier you chose, and — if you signed in with your API key — that key, mapped to those tokens so requests from the client can be billed to your subscription. Tokens expire (access 24 hours, refresh 90 days) and are deleted when you disconnect the client or revoke them.
- Payment data: handled entirely by Stripe. We never receive or store card numbers. Stripe's privacy policy: stripe.com/privacy.
What we don't do
- We do not sell or rent personal information.
- We do not use advertising trackers. The site sets no marketing cookies.
- We do not use your queries to build products for others.
Carrier data
Motor-carrier records in the Service (company names, DOT numbers, addresses, officers, safety data) come from public datasets published by FMCSA/US DOT and are processed as public business records, not as consumer data.
Service providers
We share data only with providers needed to run the Service: Stripe (payments), Cloudflare (network/DNS), and encrypted offsite backup storage. Each receives only what its function requires.
Retention
Account and billing records are kept for the life of the subscription plus the period required for tax and accounting. Usage logs are retained for operational and audit purposes.
Your rights
Email [email protected] to access, correct, or delete your account data. We respond within 30 days.
Changes
Updates will be posted here with a new effective date.
Contact
SYMBOLIQ LLC — [email protected]