[ PRIVACY ]
Mavicade privacy policy
Owner/legal review fields: Effective date and Mavicade LLC's registered business address must be confirmed before public publication. This operational draft otherwise describes the service as implemented.
What this policy covers
Mavicade provides tenant-authorized application features, a central Model Context Protocol (MCP) connection, and, when a tenant enables it, a native AI assistant. This policy explains the information Mavicade processes through those features.
Information used for sign-in and access
When an administrator signs in to Mavicade, or an invited user enrolls for an integration, Mavicade processes identity information needed to authenticate and authorize that person. Google enrollment uses the account's stable Google subject, issuer, verified email status, and email address. Mavicade stores the resulting user, external-identity, tenant-access, invitation, consent, OAuth client, grant, and permission records needed to enforce access. Authentication cookies and short-lived OAuth tokens are used to maintain signed-in sessions and connected applications.
Access is tenant-specific. A connected application receives only the tenant binding and permissions approved for that user and client. Tool authorization is checked again when a Tool is invoked.
Tenant and application information
Mavicade stores information that tenant administrators and applications provide to operate the service. Depending on the enabled features, this can include tenant settings, commerce and marketplace records, collection and product identifiers, Agent Profile configuration and editorial guidance, and administrative audit records.
The Agent Profile is durable tenant application data. Approved Agent Profile guidance and bounded sourcing context may be included in a Tool result or native AI request when they are needed for the requested task.
MCP Tools
When a connected client such as ChatGPT invokes a Mavicade Tool, it sends the selected Tool arguments and an OAuth access token to Mavicade. Mavicade uses the token's tenant binding and the current tenant, client, and user permissions to decide whether the Tool may run. Tool results can include tenant commerce data and marketplace data needed to answer the request. Mavicade keeps correlation and diagnostic identifiers in internal logs rather than ordinary model-visible Tool results.
Marketplace lookups can contact third-party marketplace providers such as eBay. Mavicade records bounded operational API-usage and quota-accounting metadata for those calls, even though the Tools do not create, update, or publish tenant marketplace resources.
Native AI and OpenRouter
Native AI is available only when the tenant has enabled it and configured an allowed model, privacy requirements, limits, and budgets. For an authorized request, Mavicade may send the user's current request, bounded system context, approved Tool schemas and results, and conversation context needed for that execution to OpenRouter and the selected downstream model provider.
Mavicade currently requires zero-data-retention-capable routing for the controlled native AI path and asks OpenRouter to deny provider data collection. Those controls describe Mavicade's configured requests and admission rules; processing by OpenRouter and a selected model provider also remains subject to their applicable terms and technical behavior.
Usage, cost, and operational records
Mavicade stores native AI execution metadata needed for authorization, limits, accounting, troubleshooting, and audit. This includes execution and tenant identifiers, client and user authorization identifiers, gateway and model identifiers, provider request identifiers, status and failure category, timestamps and duration, model-turn and Tool-call counts, token counts, provider-reported cost, correlation identifiers, and budget reservation and settlement state.
In the implemented native AI audit path, Mavicade intentionally does not persist the user's prompt, the model's response, a conversation transcript, serialized Tool arguments, serialized Tool results, or a duplicate of Agent Profile prose. Normal tenant records used by a Tool, including Agent Profile content, remain stored as application data. Mavicade also retains security and operational logs that contain bounded metadata, not request or response bodies from the reviewed native AI path.
Third parties
Mavicade uses service providers to operate hosting, authentication, connected-client, marketplace, and AI functionality. Relevant providers can include Microsoft Azure, Google, OpenAI/ChatGPT, OpenRouter, the selected model provider, and eBay. Information is sent to a provider only for the enabled feature and requested operation. Each provider processes information under its own terms and privacy practices.
Disconnecting, revocation, and deletion requests
A user can disconnect Mavicade in the connected client. A tenant administrator can revoke an individual's tenant access or disable the tenant's Mavicade app. Mavicade administrators can also revoke the corresponding OAuth resource grant. Revocation prevents future authorization or Tool use once any already-issued short-lived token expires; it does not erase audit, accounting, or tenant business records that Mavicade must retain to operate or document the service.
For an access, correction, deletion, privacy, or retention question, use the Mavicade support page or email info@mavicade.com. Requests are evaluated against the identity of the requester, the tenant's instructions, operational requirements, and applicable law.
Retention and changes
Mavicade retains each category only for the period needed for the service, security, accounting, audit, tenant instructions, and applicable legal obligations. Owner/legal review field: publish the approved category-specific retention schedule and subprocessor details before public submission. Material changes to this policy will be reflected on this page with the approved effective date.