Legal
Privacy
The short version: we never see your card details, we do not keep the content you send to the tools, and the usage we do record is metadata — which tool ran, whether it succeeded, how long it took, what it cost.
Effective 12 August 2026
Placeholder · mcw-business-plan · controller identity and rights contact
Before launch, name the data controller and its registered address, confirm which privacy regime applies, and give a dedicated address for rights requests if it is not the support address below. This page has been drafted from what the service actually records; it still needs review by a qualified adviser.
Payment details never reach us
Polar Software Inc. is our merchant of record. Checkout happens on their systems, they take the payment, and they hold the card or bank details. We receive the fact of a subscription and the identifiers that describe it — a customer id, a subscription id, a checkout id, a billing email, and the product and status Polar reports. Polar’s own privacy notice governs what they do with the rest.
What the service records when you call it
Every call writes one row to a usage ledger. That row holds which capability ran, whether it succeeded or was refused, how many tokens the call involved, an estimate of what it cost us, how long it took, how many findings came back, the credential that made the call, and which transport it arrived on.
It does not hold the files, the text, or the prompts you sent, and it does not hold the output the tool produced. That is a property of the schema, not a policy we apply afterwards: there is no column for content. We keep the ledger because a metered service has to be able to show a subscriber what they were billed for, and because it is how we find and fix failures.
What happens to the content you send
Content you send for a verifier to inspect is written into a bounded, per-call sandbox, read once, and discarded when the call ends. It is not written to the ledger and not retained after the response.
Where a generative agent runs on your own model — through MCP sampling or through a generation contract your client executes — the content goes to your model provider under your account, and your agreement with them governs it. Where the server falls back to running a model itself, the content goes to Anthropic under our account and is not used to train models.
Your credential and the one-shot secret
Provisioning stages the new credential’s secret so the success page can show it to you once. Reading it destroys it in the same database write that returns it, so a second request finds nothing. Any secret that is never claimed is deleted by a sweep within seven days. After either of those, no copy of the plaintext exists on our side.
What remains is the credential’s identifier, which is what the entitlement check and the usage rows key on.
A note on shared connectors
Some clients — the claude.ai connector among them — authenticate with one credential shared across an organisation. In that arrangement the usage rows attribute activity to the credential, so we cannot tell one of your users from another, and we do not try to. Individual machine-to-machine credentials give per-user attribution; that is the trade-off between the two.
Who else processes this
Four providers, each doing one job: Polar for payments and tax, Scalekit for issuing and verifying credentials, Google Cloud for running the service and storing the ledger, and Vercel for hosting this website. We add a processor only where it is needed to run the service, and we do not sell anything to anyone.
This website
The site is static and carries no advertising or analytics trackers, so browsing it does not require a cookie banner. Vercel records ordinary request logs to serve and protect the site.
The page you land on after checkout is deliberately excluded from search engines and sends no referrer, because its address briefly carries the reference that claims your credential. It clears that reference from the address bar as soon as it is used.
How long any of it is kept
Billing records are kept as long as tax and accounting rules require. The usage ledger is kept while the subscription is active and for a period afterwards so that billing questions can still be answered. Unclaimed credential secrets go within seven days, as described above.
Placeholder · mcw-business-plan · exact retention periods
State the concrete retention period for the usage ledger and for billing records, once the applicable regime is confirmed.
Your rights
You can ask what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Deletion has one honest limit: records we are required to keep for tax or accounting, and the ledger rows behind an invoice you have already been issued, cannot be removed while that obligation stands.
Email hello@hazeleyconsulting.com and we will respond. Requests about payment details themselves are best sent to Polar, since they are the ones who hold them.
Changes to this page
The effective date at the top changes when this page does. If a change materially widens what Jackdaws records, we will tell subscribers rather than rely on you noticing the date.