Privacy Policy
RateSpot, Inc. (“RateSpot,” “we,” “us,” or “our”) · Last updated: August 30, 2026
This Privacy Policy describes how RateSpot collects, uses, discloses, and retains information in connection with the RateSpot MCP (Model Context Protocol) server available at https://mcp.ratespot.io/mcp and related APIs (collectively, the “Services”). The Services provide real-estate, property, and mortgage data tools to AI assistants and other software clients.
This policy applies only to the Services. It does not apply to third-party websites or applications that may link to or integrate with the Services.
If you have questions about our privacy practices, contact us at [email protected].
1. Information we collect
A. Information you provide to us
Account information. When you register for an account (at ratespot.io/ai-connect), we collect your name, email address, and username. We issue you an API key; the key is shown to you once, and we store only a cryptographic (SHA-256) hash of it — never the plaintext key.
Communications. If you contact us for support or other inquiries, we collect the contents of those communications and any contact information you provide.
Queries and tool parameters. To fulfill your requests, we process the parameters you submit through the Services — for example, property addresses, geographic locations, loan scenarios (amounts, LTV, credit score ranges), and natural-language queries. We do not ask for, and you should not submit, sensitive personal information (such as Social Security numbers, full credit reports, or government IDs) through the Services.
B. Information collected automatically
Identifiers.For each API request we record a client identifier: for registered users, your account ID; for unregistered (“anonymous”) callers, a truncated SHA-256 hash derived from your IP address and browser/client User-Agent string. We use this pseudonymous identifier for rate-limiting and abuse prevention; it is not designed to identify you personally.
Usage data. We record each tool invocation: the tool name, timestamp, and daily usage counts (in aggregate and per tool, per client). This powers quota enforcement, billing, and service transparency.
Log data. Our servers and network providers automatically record IP address, User-Agent, request paths, timestamps, and error information in rolling operational logs.
C. What we do not collect
- We do not store plaintext API keys.
- We do not use cookies or browser tracking technologies (the Services are server-to-server APIs).
- We do not collect payment card information on the Services.
- We do not knowingly collect information from children under 13 (see §10).
2. How we use your information
We use the information we collect to:
- Provide the Services — process your requests, fetch property and mortgage data, run calculations, and deliver results.
- Enforce quotas and billing — maintain per-client, per-tool usage counters so registered users can audit their usage and we can apply fair-use limits.
- Security and abuse prevention — authenticate API keys, rate-limit anonymous callers, and investigate misuse.
- Improve the Services — analyze anonymized routing data (see §3) to improve how our tool planner responds to future requests, and to operate and debug the Services.
- Communicate with you — send transactional messages you request (for example, delivering a report by email when you explicitly use the email tool), respond to support requests, and notify you of material changes to the Services or this policy.
- Comply with law — meet legal, regulatory, or contractual obligations, and protect the rights, property, and safety of RateSpot, our users, and others.
3. Routing data and retention-limited storage
When you use our natural-language tool-routing feature, your query text and the resulting tool plan may be stored to improve routing quality for all users. These records are not linked to your account identity. Their lifecycle:
- First 30 days: full record retained (query text, extracted parameters, generated reasoning) for debugging and quality feedback.
- After 30 days: query text, parameters, and reasoning are permanently erased; only non-textual structure (a mathematical embedding vector, the tool sequence, and quality scores) is retained.
- After 90 days: the record is deleted entirely.
This process runs automatically on a daily schedule.
4. How we disclose information
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes. We disclose information only as follows:
Service providers (processors). We engage third-party companies to perform services on our behalf, and they may process information strictly as needed to provide those services to us, under contractual obligations consistent with this policy:
| Category of provider | What may be shared | Purpose |
|---|---|---|
| Property & real-estate data providers | Property addresses, parcel identifiers, geographic locations | Retrieve property details, valuations, ownership and comparable data |
| Mortgage & financial data providers | Loan scenario parameters (amount, LTV, credit score ranges, location) | Retrieve rate quotes and loan product data |
| AI/LLM infrastructure providers | Natural-language queries and tool metadata | Tool routing, embeddings, and language-model processing |
| Email delivery providers | Recipient email address and message content you explicitly ask us to send | Transactional email delivery |
| Geocoding providers | Location strings | Convert addresses/places to coordinates |
| Cloud hosting & infrastructure providers | All Service data (in transit/at rest) | Hosting, compute, storage |
| Content delivery & network security providers | Request metadata (IP, headers) | TLS termination, DDoS protection, performance |
Legal and safety. We may access, preserve, and disclose information if we in good faith believe it is required or appropriate to comply with law, regulation, legal process, or governmental request; enforce our agreements; or protect the rights, property, or safety of RateSpot, our users, or others.
Business transfers. If RateSpot is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to this policy or notice to you as required by law.
Aggregated or de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably be linked to you for analytics, research, and service improvement.
5. Data retention
| Data | Retention |
|---|---|
| Account profile (name, email, username) | Until you delete your account |
| API key hash | Until key rotation or account deletion |
| Daily usage counters (aggregate + per-tool) | Approximately 25 hours (expires shortly after each UTC day) |
| Tool response caches | 5 minutes to 7 days, depending on data volatility |
| Routing records: raw text/parameters/reasoning | 30 days, then permanently anonymized |
| Routing records: anonymized structure | 90 days, then deleted |
| Operational server logs | Rolling short-term retention (days) |
We retain information only as long as necessary for the purposes described in this policy, or as required by law.
6. Your choices and rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your information, subject to legal exceptions;
- Object to or restrict certain processing;
- Not be discriminated against for exercising these rights.
To exercise any of these rights, email [email protected]. We will take reasonable steps to verify your identity (for example, by confirming control of your account email) before fulfilling a request, and will respond within the timeframe required by applicable law.
Note on anonymous and anonymized data. Pseudonymous usage counters (hashed identifiers) and fully anonymized routing records cannot reasonably be linked back to you; we therefore may be unable to locate or delete them in response to an individual request.
Marketing communications. We do not send marketing email from the Services. Any transactional email you receive (such as a report you explicitly requested) cannot be opted out of while using that feature.
Do Not Track. The Services do not respond to browser Do Not Track signals (they are server-to-server APIs), and we do not use third-party advertising trackers.
7. California residents
Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information:
- Categories collected: identifiers (name, email, IP-derived pseudonymous IDs), internet/network activity (usage logs), and commercial information (usage of paid tools).
- Sale or sharing: We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Disclosure for business purposes: We disclose the categories above to our service providers (§4) solely to operate the Services.
- Rights: access, correction, deletion, and non-discrimination — exercisable via [email protected].
8. Security
We maintain technical and organizational measures appropriate to the nature of the data we process, including: TLS encryption in transit; hashed (never plaintext) storage of API keys; authentication gating on paid-data tools with per-call audit logging; private, non-publicly-routable networks for our databases; and firewall-restricted internal service segments. No system is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
9. International data transfers
The Services are operated from the United States. If you access the Services from outside the U.S., you understand that your information will be transferred to, processed, and stored in the U.S., where data protection laws may differ from those in your jurisdiction.
10. Children’s privacy
The Services are intended for general business audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it promptly.
11. Third-party sites and services
The Services may interact with third-party websites, data sources, and applications (including the AI clients you use to reach us). Their privacy practices are governed by their own policies, which we encourage you to read. We are not responsible for third-party practices.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy at this URL and update the “Last updated” date. For material changes, we will provide additional notice (such as by email to registered users) as required by law. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
13. Contact us
RateSpot, Inc.
Email: [email protected] — privacy questions, access/correction/deletion requests, and security reports.