pluuug MCP

Privacy policy for pluuug MCP

Published: October 7, 2026

This notice describes the data processing performed by the pluuug MCP service at mcp.pluuug.com, operated by Toktokhan.dev, Inc. (주식회사 똑똑한개발자). It supplements the pluuug service privacy policy with the practices of this connection service. Contact: pluuug@pluuug.com.

1. Data we process and why

2. Recipients and service providers

RecipientData and purpose
pluuug APIYour API Key, request signature, and the parameters needed to validate the connection and read the requested records. The Secret Key is used to produce the signature rather than sent as a request parameter.
Your connected client, including OpenAI when you use ChatGPTOAuth connection tokens and the tool results needed to answer your request. OpenAI processes the information received by ChatGPT under the policies and settings applicable to your OpenAI account.
VercelHosts the gateway and handles incoming requests, runtime memory, and technical operational information. The application's compute region is configured as Singapore (sin1).
NeonHosts the PostgreSQL database that stores encrypted connection and OAuth records. The database region is configured as Singapore.

Using the connection can transmit data to OpenAI and infrastructure providers outside your country. The configured application and database regions do not guarantee the location of every provider's operational system. Provider practices are described in OpenAI's privacy policy, Vercel's privacy policy, and Neon's privacy policy. The gateway does not send business records to an additional model provider or use them to train a separate model.

3. Retention and deletion

DataRetention in the gateway
Key-entry flow, form state, and security cookieExpire after 10 minutes; a successfully used connection flow is consumed.
Authorization codeExpires after 5 minutes and can be exchanged once.
Access tokenExpires after 1 hour. Refreshing or revoking the connection invalidates the previous token.
Refresh tokenExpires after 30 days. Refresh rotates the token and starts a new 30-day period.
Encrypted API Key and Secret KeyThe connection record expires 30 days plus a 60-second cleanup buffer after it is issued or refreshed. A successful revocation request deletes the active connection's stored credentials and token records.
OAuth client registration metadataRetained while the registered client is used; the current implementation does not apply an automatic expiration to client-registration records. Contact support about removal.
Tool arguments and business resultsProcessed during the request. The gateway does not store a separate history of these arguments or results in its connection database. Original records remain in pluuug; results received by your client can be retained there under that client's settings.

Expired database records become unavailable at their expiration time. The application physically removes expired rows during the next database write, so expiry does not mean immediate physical erasure from an idle database. Infrastructure logs and database backups are managed separately under the providers' retention settings and policies; deleting active gateway records does not immediately erase every provider backup. Contact support for retention or deletion questions concerning those copies.

4. Your controls

5. Security

The public connection uses HTTPS. Stored credential and OAuth record payloads are encrypted; token lookup identifiers are hashed. Customer connections have separate tokens and credential records. The deployed tool policy permits read operations and blocks record mutations. These measures reduce unauthorized access but cannot eliminate all security risks.

6. Updates and contact

We will update the publication date when this notice changes. For questions about this notice or the pluuug MCP service, contact pluuug@pluuug.com or pluuug support.

한국어 안내

이 페이지는 pluuug MCP의 개인정보 처리 내용을 설명합니다. 연결 화면에서 받은 API Key·Secret Key와 연결 토큰은 암호화해 저장하며, 요청한 비즈니스 기록은 연결한 ChatGPT 등 클라이언트에 전달합니다. Vercel은 서버를, Neon은 연결 저장소를 제공하며 애플리케이션과 데이터베이스 리전은 싱가포르로 설정돼 있습니다.

접속 토큰은 1시간, 갱신 토큰은 30일, 키 저장 기록은 발급·갱신 후 30일과 60초의 버퍼 뒤 만료됩니다. 만료된 기록은 다음 DB 쓰기 시 물리적으로 정리하며, 정상적인 토큰 폐기 요청은 해당 연결의 활성 키·토큰을 삭제합니다. 클라이언트에서 연결을 제거할 때 폐기 요청을 보내지 않을 수 있습니다. pluuug에서 API Key를 폐기하면 API 접근을 중단할 수 있습니다. 원본 업무 기록, ChatGPT가 받은 응답, 제공업체 로그·백업의 보관은 각 서비스의 정책과 설정을 따릅니다.

열람·정정·삭제·처리 관련 문의는 pluuug@pluuug.com으로 보내주세요. 문의에 Secret Key나 연결 토큰을 포함하지 마세요. 회사의 기본 개인정보처리방침도 함께 확인할 수 있습니다.