Privacy Policy

Last updated: 2026-05-11 Effective date: TODO Operator: TODO legal entity Contact: privacy@xataco.com

Service operator: TODO: legal entity name, e.g. "PlayLife OÜ" or "Xata & Co LLC" ("we", "us", "the Service")

Service URL: https://www.xataco.com

MCP endpoint: https://mcp.xataco.com/mcp

Contact: privacy@xataco.com (general inbox: general@xataco.com)

1. Who we are

Co-Founder: Strategy Layer Engine is a remote MCP (Model Context Protocol) service that runs MBB-style strategic-consulting engagements inside the AI client of your choice (Claude, ChatGPT, Cursor, Codex, VS Code, and any other MCP-compatible client). We are operated by TODO: legal entity, registered address, jurisdiction.

For GDPR purposes, we act as the data controller for account data and as a data processor for the analysis inputs you submit through tool calls.

2. What data we collect and store

2.1 Account data (when you register or sign in)

We collect and store the following data in our user database (hosted on Google Cloud Platform) for the lifetime of your account:

DataSourceWhy we need itStored where
Email addressYou (registration form or Google sign-in)Account identity, transactional emailsUser database (GCP)
Password hash (bcrypt, salted)You — we never store plaintextEmail/password sign-inUser database (GCP)
Google account identifier (google_sub)Google OAuth"Continue with Google" sign-inUser database (GCP)
Email verification status & timestampSystemBlock unverified accountsUser database (GCP)
Subscription tier (free / paid / subscription)SystemRate limiting and billingUser database (GCP)

The user database is encrypted at rest. Access is restricted to authorised personnel listed in §8. Your email address is the only personally-identifying piece of data we require to operate the Service — we do not ask for your full name, phone number, address, payment card directly (payment is delegated to TODO: Stripe / billing provider when launched), or any government identifier.

2.2 Engagement data (what you submit to tools)

When you call a tool, you supply business context — for example a company name, an investment thesis, a person's bio, a LinkedIn URL, or financial data you've copied in. This content is:

We do not train any model on your engagement data.

2.3 Operational logs

DataRetentionPurpose
runs.db — run_id, tool name, timestamps, status, client_idTODO 90 daysEngagement history & rate limiting
actions.db — Daily Loop trackingTODO 90 daysSubscription-tier feature
Web server access logs (IP, user agent, path, status)30 daysSecurity, abuse detection
OAuth tokens & session cookiesSession lifetime + grace periodAuthentication

2.4 Information we do NOT collect

3. Lawful bases (GDPR, Art. 6)

ProcessingLawful basis
Running engagements you requestContract performance (Art. 6(1)(b))
Verification emailsContract performance
Security logs, abuse detectionLegitimate interest (Art. 6(1)(f))
Marketing emails (only if you opt in)Consent (Art. 6(1)(a))

4. Sub-processors

We share data with the following sub-processors only to the minimum extent required to deliver the Service:

Sub-processorData sharedPurposeRegion
Anthropic, PBC (Claude API)Engagement inputs + intermediate promptsLLM inferenceUS
Google Cloud PlatformAll hosted data (server, databases)Hosting & computeTODO region
Resend, Inc.Email address, verification tokenTransactional emailUS
Google LLC (OAuth)OAuth sub identifier, email"Continue with Google" sign-inUS
Notion Labs, Inc.Engagement output files (only if you enable Notion export)Public-page exportUS

A current list is maintained on this page. We will give 30 days' notice in this document before adding a new sub-processor.

5. International transfers

Data may be transferred outside the European Economic Area (primarily to the United States). We rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework adequacy decision.

6. Retention

DataRetention
Account record (email, password hash, tier)Until you delete your account, plus 30 days for backups
Engagement data (research/<run_id>/, strategies/<run_id>/)TODO 90 days after engagement completion, then permanently deleted
Engagement metadata in runs.dbTODO 12 months for analytics & support, then anonymised
Server logs30 days
Notion exportsUntil you delete the Notion page; we no longer hold the content after Notion has it

7. Your rights (GDPR / UK GDPR / CCPA)

You have the right to:

  1. Access — request a copy of personal data we hold about you;
  2. Rectification — correct inaccurate data;
  3. Erasure ("right to be forgotten") — delete your account and engagement data;
  4. Portability — receive your data in a machine-readable format (JSON);
  5. Object to processing for legitimate-interest grounds;
  6. Restrict processing while a complaint is investigated;
  7. Withdraw consent at any time (where consent is the basis);
  8. Lodge a complaint with your supervisory authority (e.g. the Estonian Data Protection Inspectorate, the UK ICO, or your local DPA).

To exercise any right, email privacy@xataco.com. We respond within 30 days.

8. Security

9. Cookies

We use only strictly necessary cookies:

CookiePurposeDuration
Session cookie (OAuth flow)Keep you logged in during sign-inSession
CSRF tokenProtect against cross-site request forgerySession

We do not use advertising, analytics, or third-party tracking cookies on the marketing site or the MCP server.

10. Children

The Service is not intended for children under 16. We do not knowingly collect data from children under 16. If you believe a child has registered, contact privacy@xataco.com and we will delete the account.

11. Automated decision-making

The Service uses LLM-generated analysis as the core product. The output is advisory — it is not legally binding and should not be the sole basis of decisions with legal or significant similar effects on you. You always retain human oversight over actions taken on the analysis.

12. Changes to this policy

We will update this document when the data we collect, the sub-processors we use, or the retention periods change. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced by:

13. Contact

ReasonContact
Privacy questions, data requestsprivacy@xataco.com
General supportsupport@xataco.com
Security disclosuressecurity@xataco.com
PostalTODO registered legal address