Privacy

Last updated 2 July 2026

Palate is a hosted MCP server that feeds design intelligence to your AI builder. We keep this short and specific: below is exactly what we collect, what we do not, and how long we hold it. If a line here is ever contradicted by how the product behaves, the product is the bug, tell us and we will fix it.

What we collect

Account and billing. When you sign up we store your email address and, once you subscribe, the Stripe customer and subscription identifiers we need to run your plan. Card details are handled by Stripe; we never see or store them. Your API token is stored only as a salted SHA-256 hash, never in plaintext.

Tool-call logs. Every gated call your agent makes to a Palate tool is logged, and that log includes the arguments the agent sent. For the brief-matching tools (refs_match_brief, refs_for_business) those arguments contain the free-text brief your agent writes to describe the project. We redact token-shaped fields and cap length, but the brief text itself is stored. We use these logs to see which businesses and page types our agents are asked to build for, so we can source the references the library is missing. This is a real trade-off and we would rather state it plainly than hide it.

Analytics. The marketing site and dashboard use PostHog for product analytics (page views and, once you are signed in, which parts of the dashboard you use). This sets cookies. We do not sell this data.

Email we send you

Transactional email is part of running your account and is always sent: one-time sign-in codes (Palate is passwordless), quota warnings, billing receipts and security or terms notices.

Product updates are strictly opt-in. We only send them if you tick the box at sign-in or turn them on in Settings, we record when and where you consented, every update includes an unsubscribe link, and you can opt out any time in Settings. We never buy, sell or share email lists.

What we never see

Palate never sees your code, your repository, your files, or your local environment. The MCP server is read-only: it serves reference data to your agent and receives back only the tool arguments your agent chooses to send (a search query, a vertical, a slug, a brief). Nothing reaches Palate that your agent does not put in a tool call.

How long we keep it

Account and billing data live for as long as your account exists. Tool-call logs, including the brief text, are kept indefinitely to inform library coverage and sourcing. You can ask us to delete your logs at any time (see below), and deleting your account removes your account and billing records.

Who processes it

We rely on a small set of processors to run the service: Supabase (database, authentication, storage), Vercel (hosting), Stripe (payments), PostHog (analytics), and Resend (transactional email such as quota warnings). Each sees only the data it needs to do its job.

Your choices and takedown

Email hello@palatemcp.com to access, correct, or delete your personal data, to request that your tool-call logs be purged, or to raise any privacy concern. If you run a site we hold as a reference and want it removed, the same address is our takedown contact and we act on those requests.

Changes

If we change what we collect or how we use it, we update this page and its date. Material changes to how we handle tool-call logs will be called out here rather than buried.

Palate is a Jiffi company. See also our terms.