How chamelAIn handles persona content when you use MCP and third-party AI clients.
MCP data flow
When you authorize MCP or create an MCP Access Key, this is the path your persona content can take:
- chamelAIn — stores your personas and serves them through our hosted MCP server.
- Hosted MCP (Render) — returns persona instructions, configuration, and metadata to clients that present a valid access token.
- Your MCP client (for example, Cursor) — receives that content when you or the client invoke MCP tools such as `list_personas` or `get_persona`.
- Your AI provider (for example, Anthropic or OpenAI) — may process that content when configured in your client, under your account and terms.
chamelAIn does not choose or operate your MCP client or AI provider. We cannot control how those third parties store, log, secure, or use your content (including for model training).
What chamelAIn subprocessors handle
Our Privacy Policy lists providers that run the chamelAIn service on our behalf (for example Supabase, Vercel, Render, and PostHog when enabled). Standard contractual safeguards may apply to those transfers as described in the policy.
User-configured MCP clients and AI providers are not chamelAIn subprocessors. When you connect Cursor or another client, you direct persona content to recipients outside our control.
Regional note (analytics vs MCP)
chamelAIn uses IP-based geo detection only to decide whether product analytics requires opt-in before running (see our Cookie Policy). MCP authorization is not geo-gated — the same data-flow disclosure applies wherever you authorize MCP.
Your controls
- Revoke MCP access — Settings → Security → MCP Access Keys. Revoked keys stop working immediately.
- Export or delete account data — Settings → Security (export JSON, delete account).
- Publishing visibility — Org-catalog and marketplace publishes make instructions readable per visibility rules; confirm dialogs describe who can read each version.
Publishing and visibility
- Org catalog — workspace members with access can read published instructions and configuration.
- General marketplace — anyone who can view the public listing can read that version's instructions and configuration.
What we do not claim
- We do not claim that persona content never leaves chamelAIn when you use MCP.
- We do not claim that third-party AI providers will refrain from training on your content unless verified for your specific provider and account settings.
- We do not guarantee that downstream providers offer the same data-protection standards as your home jurisdiction.
Review your MCP client and AI provider terms before sharing sensitive instructions.
Related policies
- Privacy Policy — collection, use, retention, and your rights.
- Terms of Service — AI and MCP disclaimer.
- Connect Cursor via MCP — setup and data-handling summary.