AI Code that Works · MCP Service

Privacy Notice

AI Code that Works, LLC · Last updated 2026-07-06

This Privacy Notice explains what personal information the AI Code that Works MCP service(the “Service”) collects, how we use it, who we share it with, how long we keep it, and your rights. It applies to the MCP service at mcp.aicodethatworks.com and the member/administrative surfaces — not to the aicodethatworks.com marketing site, which has its own privacy notice. The Service is offered to members in the United States and internationally, and this Notice includes the additional rights and disclosures that apply to members in the EEA, the UK, and Switzerland (see Sections 5, 9, and 11). Capitalized terms not defined here have the meaning given in the MCP Service Terms of Service.

1. Who we are

The controller of your information is AI Code that Works, LLC, a Texas, United States limited liability company, offering the Service to members in the United States and internationally. Postal address: AI Code that Works, LLC, 2303 Ranch Rd 620 S, Ste 160-240, Lakeway, TX 78734, USA. Contact: privacy@aicodethatworks.com.

EEA/UK representative and Data Protection Officer. We rely on the GDPR Art. 27(2) derogation for the appointment of an EEA/UK representative: our processing is occasional, does not include large-scale processing of special-category data, and is unlikely to result in a risk to your rights and freedoms — so no representative is appointed at our current scale. We have not appointed a Data Protection Officer, because our processing does not meet the GDPR Art. 37(1) thresholds (we are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring, and we do not process special-category data at scale). We will revisit both determinations if our processing scale or nature changes.

2. The two kinds of data — Member Data (stored) vs Member Context (transient)

The single most important thing to understand about this Service is that it treats two kinds of data very differently:

  • Member Data — stored.The records we keep to run your membership: your identity, your entitlement, your access-token records, your Terms-acceptance records, your usage records, and the AI-operation records described in Section 3. Described in Section 3.
  • Member Context — transient.The structured repository signals your editor or agent gathers and sends for an analysis command (assess, recommend, scan). We process these transiently to produce your result and do not persist your source code from them — only a derived, de-identified detected-stack summary remains (Section 3). Described in Section 4. One important exception: for the free-text ask command, the text you type into the question — and any additional repository context you submit with it — may be stored as part of the AI-operation record for that call (Section 3). Both may include a code excerpt or project details you chose to type or attach, so treat everything you send with an ask like anything else you choose to store with us, and scrub secrets before sending.

3. Member Data we store

We store the following about your MCP membership (the descriptions below reflect the actual data model):

  • Member identityyour account, tied to your AICTW/RevAStack sign-in identity, and your email address (the join key to your membership) — to identify you, resolve your entitlement, and let you sign in and recover access.
  • Entitlement / lifecycleyour membership tier (e.g. premium, churned, comped), your customer-platform (GoHighLevel) contact identifier, and provisioning/churn timestamps — to grant, maintain, and revoke your access based on your premium membership status.
  • Access-token recordsfor each token: a one-way hash of the token (never the plaintext), a short display prefix, an optional label, its status (active/revoked), and issued/last-used/revoked timestamps — to authenticate your calls, show you your token list, and revoke tokens. We never store your token in a form we can read; we cannot recover the original.
  • Terms-acceptance recordsthe version of the Terms you accepted, the timestamp, and — as an audit trail — the IP address and user-agent captured at acceptance — to record your agreement to the Terms (a legal and audit requirement) and detect fraudulent acceptance.
  • Usage recordsfor each command you run: the command name, a JSON summary of the detected stack/context for that call (a derived tech-label list, never raw source), the outcome (ok/error/denied), technical metadata, and a timestamp — to operate, secure, meter, debug, and improve the Service.
  • AI-operation recordsfor a command that calls our AI reasoning (e.g. ask, recommend), an operation record with the command, the model, cost/duration/status, and the normalized input to that call. For the free-text ask command, that normalized input may include the text of your question and any repository context you submitted with it (either may contain a code excerpt or project details you chose to type or attach); for the structured analysis commands it is the derived detected-stack summary, not raw source. Secret-shaped content is scrubbed at the boundary first — to operate, meter, debug, secure, and improve the AI reasoning, and to serve a cached answer to an equivalent question.
  • Bridge reference (if applicable)a forward reference linking your membership to a RevAStack Brand Kit / tenant, if and when that bridge is used — to connect your MCP membership to the wider RevAStack family where you have entitlement.

4. Member Context — how we process it; no model training

When you invoke a command that needs repository signals, your own editor or agent gathers and sends only what the command asks for. How we handle it depends on the command:

  • Structured analysis commands (assess, recommend, scan).We process the gathered signals transiently to produce your result and do not persist your source code from them — only a derived, de-identified detected-stack summary (a tech-label list — Section 3) is retained.
  • The free-text ask command.The text you type into the question — together with any repository context you submit alongside it — is stored as part of the AI-operation record for that call (Section 3), because either may include a code excerpt or project details you chose to type or attach, and we keep the normalized AI-call input to operate, meter, debug, and cache the answer. So the “we do not persist your source code” promise applies to the structured analysis commands, not to what you choose to send with an ask — scrub secrets first.

Across every command we:

  • reject or redact secret-shaped content at the boundary as a safety net — but you remain responsible for scrubbing secrets before your agent sends anything;
  • do not sell your Member Context; and
  • do not use your Member Context to train AI foundation models, and our AI subprocessors (Anthropic and OpenAI — Section 6) do not train their models on the content we send through their APIs under their standard API terms.

To produce a result, some commands send text to our AI subprocessors (Section 6): for the free-text ask command, your question and any repository context you supply (secret-scrubbed at the boundary first) may be shared with our AI service providers — OpenAI (embeddings used to find relevant AICTW content) and Anthropic (reasoning used to select content and answer) — and may be retained in the AI-operation record for that call (Section 3). Neither provider trains its models on that content under its standard API terms.

We may use aggregated, de-identified operational and usage data (which does not identify you or your project) to operate, secure, and improve the Service.

5. How we use Member Data

We use Member Data to: (a) provide, operate, and secure the Service; (b) authenticate you and manage your tokens; (c) provision, maintain, and revoke your access based on your membership; (d) record and enforce your Terms acceptance; (e) meter, debug, monitor, and improve the Service; (f) communicate with you about your membership and access (e.g. welcome, recovery, and lifecycle emails); (g) detect, prevent, and respond to fraud, abuse, security incidents, and violations of the Terms; and (h) comply with our legal obligations.

Legal bases (EEA, UK, and Switzerland)

If you are in the EEA, the UK, or Switzerland, we process your Member Data under the following legal bases (GDPR Art. 6(1); UK GDPR; FADP):

  • Performance of a contract (Art. 6(1)(b))providing, operating, and securing the Service; authenticating you and managing your tokens; provisioning, maintaining, and revoking your access; and communicating with you about your membership and access (uses (a), (b), (c), and (f)).
  • Legitimate interests (Art. 6(1)(f))metering, debugging, monitoring, and improving the Service; error tracking and session-replay-on-error; and detecting, preventing, and responding to fraud, abuse, and security incidents (uses (e), (g)). Our legitimate interest is operating a secure, reliable Service; we balance it against your rights, and the identifiers we associate with error data are limited (Section 8).
  • Consent (Art. 6(1)(a))optional analytics and marketing cookies/tags where consent is required (Section 8). You may withdraw a stored consent choice using the control described in Section 8 — clearing this site’s cookies/site data, which restores the banner so you can choose again; withdrawal does not affect processing already carried out.
  • Compliance with a legal obligation (Art. 6(1)(c))recording and enforcing your Terms acceptance and keeping the associated audit records, and responding to lawful requests (uses (d), (h)).

No special-category data; no significant automated decisions. We do not collect or process special-category (sensitive) personal data as defined by GDPR Art. 9 (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, or biometric/genetic data). The Service does not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22).

6. Who we share it with

We do not sell your personal information. We share Member Data only with:

  • Service providers (subprocessors) who help us run the Service under contract, and may process Member Data only to provide services to us. Our current subprocessors (this list is versioned; the “Last updated” date at the top of this Notice marks the current version):
    • Supabasehosting + database (your Member Data records).
    • Vercelapplication hosting + delivery for the MCP web surfaces.
    • GoHighLevelcustomer platform (membership/entitlement lifecycle).
    • Mailguntransactional email (welcome, recovery, lifecycle).
    • PostHogproduct analytics (Section 8).
    • Sentryerror monitoring + session replay (Section 8).
    • Google (Google Tag Manager / Google Analytics)tag management and analytics on the MCP web surfaces, loaded through Google Tag Manager subject to the consent model in Section 8. The Google Tag Manager container may also load marketing / advertising-attribution tags — including the Meta Pixel (Meta Platforms, Inc.) and the HYROS attribution script — which run only where you have granted the applicable marketing-cookie consent (Section 8); those recipients receive the browser-side pixel/attribution signals for measurement.
    • Google Workspace (Google LLC)the email service handling correspondence sent to our privacy@ / legal@ contacts, which may contain personal data you include in a request or message to us.
    • Anthropicthe AI reasoning provider that powers the Service’s ask answers and analysis. Anthropic processes the question/analysis text the Service sends to produce your result — for a free-text ask, that text may include any repository context you supplied (secret-scrubbed at the boundary), combined with your question. Anthropic does not train foundation models on that content under its standard API terms (Section 4).
    • OpenAIthe embeddings provider for content retrieval. OpenAI may receive your question/query text — including any repository context you supplied with an ask, combined with your question (secret-scrubbed at the boundary) — and AICTW content text to compute numeric embeddings used to find relevant AICTW content; under OpenAI’s API data-usage policy, data sent to the OpenAI API is not used to train or improve OpenAI models (Section 4).
  • Our affiliated RevAStack familywhere you have entitlement that bridges the two (Section 3).
  • Legal / safety recipientsto comply with law, respond to lawful requests, enforce the Terms, or protect our rights, users, or the public.
  • A successorin a merger, acquisition, financing, or sale of assets, subject to this notice.

7. Retention

We keep Member Data for as long as your membership is active and as needed for the purposes above. The categories below describe how we retain and delete each type; you can have your Member Data deleted at any time by making a verified deletion request. Deleting your account deletes your Member Data: the member record and the records keyed to it — entitlement, access-token records, Terms-acceptance records, and usage records — cascade-delete when the underlying account is deleted, so a verified deletion request purges each of those categories through that same mechanism. AI-operation records (Section 3) are stored platform-attributed for metering and abuse-prevention and are not keyed to your account, so they are not removed by the account-deletion cascade; on a verified deletion request we de-identify any such records we can associate with you.

  • Member identity + entitlementretained while your membership is active and, after cancellation, as an inactive record so we can handle re-activation, billing/entitlement disputes, and legal obligations. Cancellation marks your membership inactive and revokes your tokens; it does not by itself erase the record. To have this record deleted, make a verified deletion request (see above) — the deletion cascade purges it.
  • Access-token records (hash + display prefix + metadata only)retained while the token is active; a revoked or expired token’s record is kept as a security-audit trail and is deleted when your account is deleted (the deletion cascade — see above). (The plaintext token is never stored — Section 3.)
  • Terms-acceptance records (including the IP/user-agent audit trail)retained for the life of the account and for the applicable statute-of-limitations / contract-limitations period after it ends (to evidence your agreement), then deleted.
  • Usage recordskept as an operational/analytics record. Records keyed to your account are deleted when your account is deleted (the deletion cascade — see above); on a verified deletion request we de-identify any platform-attributed AI-operation records we can associate with you (Section 3).
  • Member Contextnot persisted (Section 4) for the structured analysis commands; only a de-identified usage summary (detected tech-stack labels, never source) remains (Section 3), handled as a usage record above. The exception is the free-text ask command, where your question and any repository context you send may be kept in the AI-operation record for that call (Sections 3 and 4).

We may retain information longer where a longer period is required to comply with law, resolve a dispute, or enforce our agreements.

8. Analytics, error monitoring, cookies, and consent

The MCP web surfaces (the landing, method, onboarding, recovery, and administrative pages) use cookies and similar technologies for analytics, marketing/measurement tags, and error monitoring, governed by consent and built on Google Consent Mode v2:

  • Geo-scoped default posture, then your choice.The default that applies before you interact is scoped to your region: in the EEA, the UK, and Switzerland, nothing analytics or marketing fires when you land (a consent-first, opt-in default); everywhere else, analytics and measurement may fire on landing (an opt-out default) until you decline. When you land, a cookie-consent banner(Accept all · Reject all · Manage preferences) lets you grant or deny the analytics and marketing categories; your choice is remembered on this device. To change a remembered choice, clear this site’s cookies/site data in your browser, which restores the banner on your next visit so you can choose again.
  • Global Privacy Control (GPC).When you have not yet made a banner choice, a browser GPC signal forces a denied default posture — in every region, regardless of the default above. Once you have made a banner choice, that returning-member decision (grant or deny) takes precedence over the GPC-driven default.

The categories used on the MCP surfaces:

  • Analytics / product analytics — PostHog and Google Analytics (via Google Tag Manager).Helps us understand how members use the Service so we can operate and improve it. Gated by your analytics-consent choice (subject to the geo-scoped default above).
  • Marketing / measurement tags — via Google Tag Manager.Any marketing or conversion-measurement tags load through GTM and fire only where you have granted marketing consent. Adding or changing a tag is a tag-manager configuration change, not a change to the Service code.
  • Error monitoring and session replay — Sentry.We use Sentry to capture errors and keep the Service reliable and secure. Error tracking is necessary to operate the Service; Sentry boots with session-replay disabled and starts session-mode replay only after analytics consent is granted (it re-enters buffer mode on withdrawal). Sentry’s default privacy masking (masking text, inputs, and media) keeps captured session-replay data free of your identifiers, and the browser identifiers we associate are limited to a hashed user ID and an anonymous session ID. Server-side error diagnostics for a failed request may additionally include your account user ID (an opaque identifier) in the error context so we can trace and fix the fault; we do not attach your name, email, or other raw identity to Sentry.

Sign-in, invitation, and password-reset pages follow the same region-scoped default as the rest of the Service: in the EEA/UK/CH nothing analytics or marketing fires before you interact with the banner; everywhere else analytics/measurement may fire on landing until you decline. Sentry error monitoring (never a marketing pixel) is present on these pages because it is necessary to operate the Service.

9. International transfers

AI Code that Works, LLC is based in the United States, and your Member Data is stored and processed in the United States (and in other countries where our subprocessors in Section 6 operate). If you are in the EEA, the UK, or Switzerland, transferring your Member Data to the United States and other countries means transferring it outside your home region.

Where we transfer Member Data out of the EEA, the UK, or Switzerland to a US-based subprocessor or another country that has not received an adequacy decision, we rely on appropriate safeguards required by law. Transfers to our US subprocessors rest on Standard-Contractual-Clause-backed data processing agreements (with the UK International Data Transfer Addendum for UK transfers, and the Swiss addendum for Swiss transfers), and, where the subprocessor is certified, on the EU–U.S. Data Privacy Framework (and its UK Extension and Swiss–U.S. framework, as applicable) — together with any additional measures required. You may request a copy of the relevant safeguards by contacting us at the address in Section 1.

10. Security

We protect Member Data with measures appropriate to its sensitivity — for example, storing access tokens only as one-way hashes (never plaintext), serving member content only through private storage and short-lived signed URLs, scrubbing secret-shaped content at the Service boundary, and restricting access to authorized personnel. No system is perfectly secure, and you are responsible for keeping your Access Token secret (Terms §5).

11. Your rights

United States. Depending on the US state you live in, you may have rights to access, correct, delete, or port your personal information, to opt out of the sale or sharing of personal information and of targeted advertising, and to withdraw the analytics consent (Section 8). We do not sell or share your personal information, and we do not use it for targeted advertising on the MCP surfaces.

EEA, UK, and Switzerland. If you are in the EEA, the UK, or Switzerland, you have the rights to: access your personal data; rectification of inaccurate data; erasure(“right to be forgotten”); restriction of processing; data portability; objection to processing carried out on the legitimate-interest basis (Section 5); and, where processing is based on consent (Section 8), the right to withdraw consent at any time without affecting processing already carried out. To exercise any of these, contact us at privacy@aicodethatworks.com (Section 1).

How we handle a request. We verify your request by matching it to the email address tied to your member account before acting. We respond within one month of receiving a GDPR/UK/Swiss request (extendable by up to two further months where permitted by law for complex or numerous requests, with notice to you) and within 45 days of receiving a request under applicable US state laws (extendable once as those laws permit, with notice). If we decline a US-state request, you may appeal by replying to our response. You will not be discriminated against for exercising a right.

Right to complain to a supervisory authority. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your own local data protection supervisory authority (in the EEA, the DPA of your country of residence, work, or the place of the alleged infringement; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner) — although we would appreciate the chance to address your concern first.

12. Children

The Service is for business/professional use and is not directed to children under 16 (or the applicable age), and we do not knowingly collect their information.

13. Changes to this notice

We may update this notice; we will update the “Last updated” date and, for material changes, take additional steps required by law. Your continued use after a change means you accept the updated notice.

14. Contact

Questions or requests: privacy@aicodethatworks.com. Postal: AI Code that Works, LLC, 2303 Ranch Rd 620 S, Ste 160-240, Lakeway, TX 78734, USA.

We use cookies

We use cookies and similar technologies to keep this site working, measure how it performs, and (with your permission) personalise ads. Choose your preferences below.