Privacy Policy
Last Updated: September 6, 2026 • Effective Date: September 6, 2026
Privacy First & Zero Cross-Tenant Leakage: NC operates a hosted,
multi-tenant Model Context Protocol (MCP) gateway designed to connect user-authorized AI
agents to their own explicit host machines. We never sell your personal data, inspect
private command payloads for training, or share machine inventories across tenants.
1. Overview & Scope
This Privacy Policy describes how NC ("we", "our", or "us"), accessible
via https://nodecommand.app and https://mcp.nodecommand.app, collects, uses, and
safeguards information when you register an account, enroll physical or virtual host
machines, and integrate external AI clients (such as OpenAI ChatGPT, Anthropic Claude,
OpenCode, or Cursor).
2. Information We Collect
-
Account & Identity Data: When you register or sign in via our federated
identity providers (Google, GitHub, GitLab, or Discord), we receive your primary email
address, public profile name, and unique provider subject identifier. We do not access
your third-party repositories, cloud drives, or private messaging channels. If you
register via email, your password is encrypted using salted
scrypt hashes and
is never stored in plaintext.
-
Host Machine Telemetry: When you enroll a device running the NC Agent
(Windows, Linux, or macOS), we collect canonical hardware metadata including OS platform,
architecture, hostname, agent daemon version, and liveness status (heartbeat timestamps).
-
Cryptographic Device Keys: During enrollment, devices bind an asymmetric
Ed25519 public key thumbprint. Private keys remain exclusively on your local host machines
and never leave your environment.
-
Operations & Audit Logs: We log command execution timestamps, tool
invocation identifiers, durations, and exit statuses to provide real-time dashboard
telemetry and security audits. On-demand log content (
log_read) is
transiently streamed and is not retained in our database.
3. How We Use Your Information
-
To authenticate your identity and isolate your enrolled machines within your dedicated
Workspace (Tenant).
-
To verify OAuth 2.0 authorization codes and issue cryptographically signed Bearer tokens
for your selected AI MCP clients.
-
To route authorized JSON-RPC operations strictly to your own enrolled hosts with
fail-closed security policies.
-
To deliver automatic over-the-air (OTA) agent security updates when enabled by your host
policy.
-
To detect and prevent unauthorized cross-tenant probing, credential reuse, and system
misuse.
4. Multi-Tenant Isolation & Zero AI Training
NC enforces strict multi-tenant boundary isolation at the database, gateway, and transport
layers:
-
External AI callers can only discover or execute tools on machines belonging to the
authenticated tenant. Probing other machine IDs returns an opaque
CLIENT_NOT_FOUND response.
-
We do not use your command outputs, filesystem content, or prompts to train machine
learning or AI models.
All tool execution payloads belong exclusively to you.
5. Third-Party Integrations & Sharing
We do not sell, rent, or trade your personal information. Data is shared exclusively under
the following strict conditions:
-
Authorized AI Clients: When you grant OAuth consent to an AI assistant
(such as ChatGPT or Claude), tool invocation payloads are communicated over TLS to execute
commands on your authorized machines.
-
Federated OAuth Providers: Identity verification tokens are exchanged
strictly to validate your login credentials with Google, GitHub, GitLab, or Discord.
-
Legal Requirements: We may disclose information only if required by valid
law enforcement requests or applicable court orders.
6. Data Retention & Erasure
You maintain full control over your infrastructure data:
- You can revoke connected AI clients (OAuth grants) at any time from your dashboard.
-
You can forget (uninstall) host machines from your tenant, which purges their device
credentials and retained central telemetry.
-
Account closure requests permanently delete your user profile, memberships, and associated
tenant records.
7. Data Retention Matrix
We keep each data category only as long as its purpose requires:
- Account & identity: account lifetime.
- OAuth identities: while linked; removed on disconnect.
- Hosts & enrollment: while the host belongs to your workspace.
- Audit trail: plan retention (Free 7 days, Dev 30 days, Cluster 90 days).
- Usage ledger: billing retention while subscribed.
- Support tickets: support policy duration.
- Billing records: as required by financial law.
- Security logs: security retention for abuse prevention.
- Diagnostics bundles: short retention, only when you attach them.
8. Subprocessors
We use a minimal set of service providers, each only for its purpose:
- Hosting provider: runs the NC control plane and dashboard.
- Payment provider: processes subscriptions (see Terms).
- OAuth identity providers (Google, GitHub, GitLab, Discord): login only.
9. Security Safeguards
All communication between browsers, AI connectors, the NC Control Plane, and edge host
daemons is encrypted using TLS 1.3. Device authorizations utilize 60-second bounded Ed25519
digital signatures, preventing replay attacks and clock skew manipulations.
10. Contact Us
If you have any questions, privacy inquiries, or data deletion requests regarding this
Privacy Policy, please contact our team:
Contact:
GitHub Issues
(privacy requests: in-dashboard support)
Official Domain:
https://nodecommand.app •
https://mcp.nodecommand.app