Privacy at a Glance: We collect minimal data necessary to provide our service. Our marketing website uses Umami Analytics (privacy-focused, no personal data) and PostHog for anonymous button click tracking. Our application uses PostHog for product analytics. Your data is processed on Google Cloud Platform servers in the United States. Important: When members use our MCP service, your Ghost blog content is transmitted to third-party AI systems (such as Claude or ChatGPT), which have their own data handling policies. You have full control over your data and can request deletion at any time.
ToastMCP ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at toastmcp.com and our application at app.toastmcp.com (collectively, the "Service").
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
ToastMCP is operated as a sole proprietorship. For any privacy-related inquiries, please contact us at enrico@toastmcp.com.
We collect information that you voluntarily provide when using our Service:
When you use our Service, we automatically collect certain information:
| Data Type | Marketing Website (toastmcp.com) | Application (app.toastmcp.com) |
|---|---|---|
| Analytics Provider | Umami Analytics + PostHog | PostHog |
| Personal Data Collected | Anonymous button click events only | Anonymous usage events, feature interactions |
| IP Addresses | Anonymized by PostHog | Anonymized |
| Cookies | PostHog cookies for analytics | Session cookies only |
We receive information from third-party services:
When you connect your Ghost blog, we access and store:
This data is used solely to provide MCP access to your members and enforce your Ghost paywall tiers. We act as a data processor on your behalf for this member data.
We use collected information for the following purposes:
Important: This section explains how your Ghost blog content flows through our system to third-party AI assistants when members use the MCP endpoint.
When a member uses their API key to access your Ghost blog through our MCP endpoint:
Through the MCP endpoint, the following blog content may be transmitted to AI systems:
We do NOT transmit: Ghost admin credentials, member personal information, payment details, or analytics data.
Once your content is transmitted to a third-party AI system, it is subject to that provider's data handling policies:
| AI Provider | Data Retention | Training Use | Privacy Policy |
|---|---|---|---|
| Anthropic (Claude) | Varies by plan | Opt-out available | anthropic.com/privacy |
| OpenAI (ChatGPT) | Varies by plan | Opt-out available | openai.com/privacy |
| Other Providers | Varies | Varies | Check provider's policy |
We strongly recommend that you:
ToastMCP acts as a conduit for content transmission. We:
For users in the European Economic Area (EEA), we process personal data based on the following legal grounds:
We share data with third-party service providers who assist in operating our Service:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting | All service data | United States |
| Firebase (Google) | Authentication, Firestore database | Account data, user data | United States |
| LemonSqueezy | Payment processing | Billing information | United States |
| Mailgun | Email delivery | Email addresses, email content | United States |
| PostHog | Product analytics (app only) | Anonymous usage data | United States/EU |
| Umami | Website analytics | No personal data | EU |
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, privacy, safety, or property.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change.
We may share your information for other purposes with your explicit consent.
Important: Your data is processed and stored on Google Cloud Platform servers located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.
For transfers from the EEA, we rely on:
We retain your data for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
Regardless of your location, you have the right to:
If you are in the European Economic Area, you also have the right to:
California residents have additional rights under the California Consumer Privacy Act:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
To exercise any of these rights, please contact us at enrico@toastmcp.com. We will respond to your request within 30 days (or sooner if required by applicable law).
For verification purposes, we may ask you to confirm your identity before processing your request.
We implement appropriate technical and organizational measures to protect your personal data:
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Our marketing website uses two analytics tools:
Our application uses:
PostHog collects anonymous usage data to help us improve the product. You can opt out of PostHog tracking in your account settings.
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at enrico@toastmcp.com.
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
Our website uses privacy-respecting analytics tools. Umami does not track individual users. PostHog is used for anonymous button click tracking only and does not track personal information on the marketing website.
As a ToastMCP user who connects a Ghost blog, you act as the data controller for your Ghost members' data, and ToastMCP acts as a data processor. We process your members' data only according to your instructions and for the purpose of providing the Service.
For enterprise customers requiring a formal Data Processing Agreement (DPA), please contact us at enrico@toastmcp.com.
We may update this Privacy Policy periodically. We will notify you of material changes by:
Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about our data practices, please contact us:
Email: enrico@toastmcp.com
Website: https://toastmcp.com
We aim to respond to all privacy-related inquiries within 30 days.
If you are located in the European Economic Area and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.