Privacy Policy
This Privacy Policy explains what data ionexai.com ("we", "us") collects when you use ionexai-mcp, our read-only Model Context Protocol (MCP) server, and how we handle it. ionexai-mcp exposes derived market-intelligence data. We keep the personal data we collect to the minimum needed to operate the service.
What we collect
We collect only two categories of data:
1. Account and contact data. When you request an API key, we collect your email address. We use it to issue and manage your key, send billing and account notices, and respond to support requests. It is the only identifying personal data we ask for.
2. Usage logs. Each authenticated call to the service is logged. A log record contains:
- the API key identifier (not the key itself),
- the tool name invoked,
- the queried identifier (such as a ticker or entity name), where the tool takes one,
- a timestamp,
- a success/failure flag, and
- request latency.
We use these logs for billing, quota and rate-limit enforcement, and abuse and fraud detection (including detecting bulk-extraction patterns). We do not log anything beyond the fields listed above, and usage logs are never used for advertising or sold.
How API keys are stored
API keys are stored as salted hashes, never in plaintext. We cannot recover a lost key; we can only revoke it and issue a replacement. Keep your key confidential — anyone holding it can make calls billed to your account.
What we do NOT do
- We do not sell, rent, or trade your personal data.
- We do not serve advertising.
- We do not embed third-party trackers, analytics beacons, or advertising pixels in the service.
- We do not build behavioral profiles of you for marketing.
Data sources
The market-intelligence data returned by ionexai-mcp is derived and aggregated from public sources — including SEC EDGAR, FINRA, the U.S. Treasury, FRED, and exchange data processed into aggregates. This is information about companies, securities, and markets, not personal data about you. We do not redistribute raw real-time quotes.
Service providers
We rely on a small number of infrastructure and payment providers to host the service and process billing. These providers may process your email and billing information solely to perform services for us, under their own terms, and are not permitted to use it for their own purposes.
Data retention
We retain your account data for as long as your account is active. We retain usage logs for as long as needed for billing, quota enforcement, abuse detection, and applicable record-keeping, after which they are deleted or aggregated into non-identifying statistics. On account closure we delete or anonymize your personal data except where we must retain records to meet a legal or accounting obligation.
Security
We use hashed key storage, encrypted transport, per-key rate limits, and access controls to protect the service. No system is perfectly secure, but we take reasonable measures appropriate to the limited data we hold.
Your choices
You may request access to, correction of, or deletion of your personal data, and you may close your account at any time by contacting us. Closing your account revokes your keys and stops further data collection.
Children
The service is not directed to, and may not be used by, anyone under 18.
Changes to this policy
We may update this policy as the service evolves. Material changes will be posted here with a revised effective date. Continued use after an update constitutes acceptance of the revised policy.
Contact
Questions or requests about this policy or your data: support@ionexai.com.