What the iFixAi MCP connector collects, where it goes, and how long we keep it.
iFixAi is operated by LEGAL ENTITY NAME AND REGISTERED ADDRESS. Questions about this policy or your data: support@ifixai.ai.
| Data | Why |
|---|---|
| Email address, account id | To identify you and find your workspace. Supplied by your iFixAi sign-in, not by your AI client. |
| Workspace membership | To scope everything you do to your own organisation. |
| Agent endpoint details | The URL, headers and credential you register, so we can dial your agent. |
| Your agent description | The text you submit to author a fixture, and the fixture produced from it. |
| Inspection transcripts | The prompts we send your agent and the replies it returns. This is the evidence in your report. |
| Run and billing records | Run status, timing, grade, and credits quoted and settled. |
| Usage records | Which tools you call, when, from which AI client, and whether the call succeeded or was refused. Your account id is stored as a one-way hash and only the domain of your email is kept, never the address. It tells us which parts of the product work and which refusals people hit. |
We do not collect your AI client conversation. The connector receives only the arguments of the tool calls you approve. It has no access to the rest of your chat, your files, or your other connectors.
The credential you give us to reach your agent is stored server-side and never returned, not to your AI client, not to you, not in any report or error message. It is used for one thing: authenticating to the endpoint you registered. Headers that could smuggle a credential into a report are rejected at submission.
Running an inspection means your agent's replies are graded by a language model we don't operate. That is the one place your content leaves our systems.
| Processor | Receives | Purpose |
|---|---|---|
| OpenRouter | Inspection prompts and your agent's replies | Grading. Routed to the judge model named in your report. |
| Supabase | Account, workspace and run records | Authentication and database hosting. |
| Manufact (mcp-use) | Connector traffic in transit | Hosting the MCP server. |
| Resend | Your email address | Sign-in and service email. |
We do not sell your data, and we do not share it for advertising.
Grading is performed by a third-party model provider under their own terms. We do not control that provider's retention or training practices and do not claim on their behalf that your content is excluded from either. If your content must not leave your own infrastructure, iFixAi is not the right tool for it.
Account and run data is held in our Supabase project in the EU (Frankfurt, eu-central-1). Credentials are held in an encrypted secrets store, separate from the application database.
| Account and workspace | For as long as your account exists. |
| Reports and transcripts | Until you close your account, or until you ask us to delete them. They contain your agent's replies, so if you want a shorter window for a specific engagement, tell us and we'll agree one. |
| Registered credentials | Until you delete the connection or close your account. |
| Billing records | Kept after account closure for as long as accounting and tax law requires. |
| Usage records | 24 months, then deleted. |
You can ask us to show you, correct, export or delete your data. Email support@ifixai.ai and we'll respond within 7 days. If you're in the UK or EU, you also have the right to complain to your data protection authority.
Disconnecting the connector stops all future access immediately. It does not delete data already stored. Ask us if that's what you want.
If we change this policy materially we'll update this page and notify account holders by email before it takes effect.