Privacy Policy

RateSpot, Inc. (“RateSpot,” “we,” “us,” or “our”) · Last updated: August 30, 2026

This Privacy Policy describes how RateSpot collects, uses, discloses, and retains information in connection with the RateSpot MCP (Model Context Protocol) server available at https://mcp.ratespot.io/mcp and related APIs (collectively, the “Services”). The Services provide real-estate, property, and mortgage data tools to AI assistants and other software clients.

This policy applies only to the Services. It does not apply to third-party websites or applications that may link to or integrate with the Services.

If you have questions about our privacy practices, contact us at [email protected].

1. Information we collect

A. Information you provide to us

Account information. When you register for an account (at ratespot.io/ai-connect), we collect your name, email address, and username. We issue you an API key; the key is shown to you once, and we store only a cryptographic (SHA-256) hash of it — never the plaintext key.

Communications. If you contact us for support or other inquiries, we collect the contents of those communications and any contact information you provide.

Queries and tool parameters. To fulfill your requests, we process the parameters you submit through the Services — for example, property addresses, geographic locations, loan scenarios (amounts, LTV, credit score ranges), and natural-language queries. We do not ask for, and you should not submit, sensitive personal information (such as Social Security numbers, full credit reports, or government IDs) through the Services.

B. Information collected automatically

Identifiers.For each API request we record a client identifier: for registered users, your account ID; for unregistered (“anonymous”) callers, a truncated SHA-256 hash derived from your IP address and browser/client User-Agent string. We use this pseudonymous identifier for rate-limiting and abuse prevention; it is not designed to identify you personally.

Usage data. We record each tool invocation: the tool name, timestamp, and daily usage counts (in aggregate and per tool, per client). This powers quota enforcement, billing, and service transparency.

Log data. Our servers and network providers automatically record IP address, User-Agent, request paths, timestamps, and error information in rolling operational logs.

C. What we do not collect

2. How we use your information

We use the information we collect to:

3. Routing data and retention-limited storage

When you use our natural-language tool-routing feature, your query text and the resulting tool plan may be stored to improve routing quality for all users. These records are not linked to your account identity. Their lifecycle:

This process runs automatically on a daily schedule.

4. How we disclose information

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes. We disclose information only as follows:

Service providers (processors). We engage third-party companies to perform services on our behalf, and they may process information strictly as needed to provide those services to us, under contractual obligations consistent with this policy:

Category of providerWhat may be sharedPurpose
Property & real-estate data providersProperty addresses, parcel identifiers, geographic locationsRetrieve property details, valuations, ownership and comparable data
Mortgage & financial data providersLoan scenario parameters (amount, LTV, credit score ranges, location)Retrieve rate quotes and loan product data
AI/LLM infrastructure providersNatural-language queries and tool metadataTool routing, embeddings, and language-model processing
Email delivery providersRecipient email address and message content you explicitly ask us to sendTransactional email delivery
Geocoding providersLocation stringsConvert addresses/places to coordinates
Cloud hosting & infrastructure providersAll Service data (in transit/at rest)Hosting, compute, storage
Content delivery & network security providersRequest metadata (IP, headers)TLS termination, DDoS protection, performance

Legal and safety. We may access, preserve, and disclose information if we in good faith believe it is required or appropriate to comply with law, regulation, legal process, or governmental request; enforce our agreements; or protect the rights, property, or safety of RateSpot, our users, or others.

Business transfers. If RateSpot is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to this policy or notice to you as required by law.

Aggregated or de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably be linked to you for analytics, research, and service improvement.

5. Data retention

DataRetention
Account profile (name, email, username)Until you delete your account
API key hashUntil key rotation or account deletion
Daily usage counters (aggregate + per-tool)Approximately 25 hours (expires shortly after each UTC day)
Tool response caches5 minutes to 7 days, depending on data volatility
Routing records: raw text/parameters/reasoning30 days, then permanently anonymized
Routing records: anonymized structure90 days, then deleted
Operational server logsRolling short-term retention (days)

We retain information only as long as necessary for the purposes described in this policy, or as required by law.

6. Your choices and rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email [email protected]. We will take reasonable steps to verify your identity (for example, by confirming control of your account email) before fulfilling a request, and will respond within the timeframe required by applicable law.

Note on anonymous and anonymized data. Pseudonymous usage counters (hashed identifiers) and fully anonymized routing records cannot reasonably be linked back to you; we therefore may be unable to locate or delete them in response to an individual request.

Marketing communications. We do not send marketing email from the Services. Any transactional email you receive (such as a report you explicitly requested) cannot be opted out of while using that feature.

Do Not Track. The Services do not respond to browser Do Not Track signals (they are server-to-server APIs), and we do not use third-party advertising trackers.

7. California residents

Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information:

8. Security

We maintain technical and organizational measures appropriate to the nature of the data we process, including: TLS encryption in transit; hashed (never plaintext) storage of API keys; authentication gating on paid-data tools with per-call audit logging; private, non-publicly-routable networks for our databases; and firewall-restricted internal service segments. No system is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.

9. International data transfers

The Services are operated from the United States. If you access the Services from outside the U.S., you understand that your information will be transferred to, processed, and stored in the U.S., where data protection laws may differ from those in your jurisdiction.

10. Children’s privacy

The Services are intended for general business audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it promptly.

11. Third-party sites and services

The Services may interact with third-party websites, data sources, and applications (including the AI clients you use to reach us). Their privacy practices are governed by their own policies, which we encourage you to read. We are not responsible for third-party practices.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy at this URL and update the “Last updated” date. For material changes, we will provide additional notice (such as by email to registered users) as required by law. Continued use of the Services after the effective date constitutes acceptance of the updated policy.

13. Contact us

RateSpot, Inc.
Email: [email protected] — privacy questions, access/correction/deletion requests, and security reports.