← Back to documentation
Privacy Policy
Headai MCP Server — operated by Headai Ltd.
Last updated: June 2026
What data we collect
The Headai MCP Server is a proxy between your MCP client and Headai's Core Engine. We process:
- API key — provided by you during connection setup. Used to authenticate requests to the Headai Core Engine. To keep your connection working across server restarts, the key is cached in server-side session storage (Redis) for up to 24 hours after your last activity, after which it expires automatically. It is never written to logs and never shared with third parties.
- Request payloads — text, search parameters, and graph URLs you send to the tools. Forwarded to the Headai Core Engine for processing; not retained by the MCP server.
- Server logs — session IDs and timestamps for operational monitoring. No request content is logged.
- Usage statistics — aggregated, non-content telemetry for service operation: which tool was called, which client platform made the call (e.g. Claude, ChatGPT, Copilot), session counts, and a count of distinct API keys. No request text, results, or personal data is included. Retained for up to 90 days.
How we use your data
- To process your tool requests via the Headai Core Engine
- To keep your session connected across server restarts
- To monitor server health, usage volume, and diagnose errors
- We do not sell, share, or use your data for advertising, and we do not build behavioral profiles of users
Data processing by Headai Core Engine
Text submitted to tools like headai_text_to_graph and headai_text_to_keywords is processed by Headai's AI engine (Graphmind). By default, input text may be temporarily stored for processing. Knowledge graphs and analysis results — including skill profiles built from CV or career text you choose to submit (Digital Twin) — are stored under your API key and can be listed or deleted via the API. Recipients of this data are Headai Ltd. systems only.
Data retention
- Session credentials cached on the MCP server expire automatically 24 hours after last activity
- Aggregated usage statistics are retained for up to 90 days
- Results (graphs, scorecards, signals, Digital Twin profiles) stored on the Headai Core Engine are retained under your API key until you delete them
- Server logs are retained for up to 30 days
Your rights
You can request access to, correction of, or deletion of your data by contacting info@headai.com. Under GDPR, you have the right to data portability and the right to lodge a complaint with a supervisory authority.
Contact
Headai Ltd.
Email: info@headai.com
Website: headai.com
This privacy policy applies specifically to the Headai MCP Server at mcp.headai.dev.