Privacy Policy MCP Server — mcp.aisuru.ai IT | EN

Privacy Policy — AIsuru MCP Servers

This page describes how the AIsuru MCP gateway (hereinafter "the Service") handles data for each enabled MCP server connector. The general Memori privacy policy is at memori.ai/en/privacy-policy: this page is a dedicated extension covering the MCP connectors.

Last updated: July 29, 2026 · Data Controller: Memori srl · Privacy contact: privacy@memori.ai

General model

An "MCP server" is a connector that lets an AIsuru agent interact with an external system (database, mail, calendar, API, etc.). The AIsuru gateway exposes such connectors to the user's agents, injects required credentials at runtime, and routes calls. For each connector listed below we declare:

Principles applying to all MCP connectors:

Active MCP servers

AIsuru Agent Link

Source: internal Memori gateway service · Type: exposes the agent as a standard MCP server

Exposes an AIsuru agent as a standard MCP server reachable by external applications (Claude, Cursor, other agents). Connected clients can converse with the agent and search its knowledge; the owner can also manage it remotely (builder tools).

Data retained by the gateway

Data NOT retained

Revocation

The owner can revoke tokens or disable the endpoint from the connector Dashboard at any time.

AIsuru Data Analysis

Source: npm package mcp-js-executor · Type: sandboxed JavaScript execution on JSON data

Lets the agent run JavaScript code in a sandbox over JSON data passed in the conversation. Useful for transformations, aggregations, calculations on data provided by the agent.

Data retained by the gateway

Data NOT retained

AIsuru MCP Server

Source: internal Memori HTTP server memori.ai · Type: AIsuru platform integration

Lets the agent query the AIsuru platform itself for internal orchestration tasks (memori lookup, sessions, etc.).

Data retained by the gateway

Data NOT retained

AIsuru Scheduler MCP Server

Source: internal Memori gateway service · Type: recurring task scheduler

Lets the agent schedule recurring tasks executed autonomously in the background (e.g., "every morning at 6 send me a summary of my emails"). Tasks are user-isolated.

Data retained by the gateway

Data NOT retained

Revocation

The user can delete scheduled tasks via the "cancel schedule" command in chat or via the gateway API.

AIsuru Vibe Coder

Source: internal Memori gateway service · Type: conversational agent building (functions, views, forms, connectors)

Lets the agent's owner build and modify it by talking: create functions and contents, activate connectors, generate views and forms backed by real data, define the application's governance rules. Modification actions are restricted to the verified owner/giver.

Data retained by the gateway

Data NOT retained

Revocation

The owner can disable views and endpoints from the connector Dashboard, or remove the Vibe Coder McpServer from the agent.

Bybit Trading

Source: OFFICIAL Bybit npm package bybit-official-trading-server · Type: crypto exchange (market data, account, orders) via V5 APIs

Lets the agent query real-time market data (even without credentials) and, with configured credentials, read balances/positions and manage orders. Orders always require the user's explicit confirmation. Supports the testnet and Bybit EU accounts.

Data retained by the gateway

Data NOT retained

Revocation

Remove the McpServer from the panel, or revoke the API key from Bybit (API Management). Restricting the key to the gateway's egress IPs is recommended.

ClickUp

Source: OFFICIAL ClickUp remote service mcp.clickup.com · Type: tasks, lists, docs, chat and time tracking

Lets the agent work with the user's ClickUp workspace (tasks, lists, folders, spaces, docs, comments, chat, time tracking). Each user connects with their own account via OAuth: the agent operates with their permissions. ClickUp exposes no deletion tools.

Data retained by the gateway

Data NOT retained

Revocation

From the connector Dashboard (remove the connected account), or from ClickUp → Settings → Apps by revoking the authorisation.

Cloudflare MCP Server

Source: official Cloudflare npm package @cloudflare/mcp-server-cloudflare (GitHub) · Type: Workers/KV/R2/D1 management

Lets the agent manage the user's Cloudflare resources (Workers, KV, R2, D1, Durable Objects, Queues, Workers AI, Workflows).

Data retained by the gateway

Data NOT retained

Revocation

To revoke: remove the API token from the MCP server panel, or revoke the token directly from your Cloudflare account.

Excel MCP Server

Source: PyPI package excel-mcp-server (haris-musa) · Type: spreadsheet creation/editing (.xlsx)

Lets the agent create and edit Excel files (cells, formulas, charts, tables, formatting). Files are processed in the gateway workspace. Available to authenticated users only.

Data collected by the gateway

Data NOT retained

Revocation

Files expire and are deleted automatically within 24 hours. There are no persistent credentials to revoke.

Fetch Url

Source: npm package @tokenizin/mcp-npx-fetch · Type: download content from public URLs

Lets the agent fetch content from a URL and convert it to text, HTML, JSON, or Markdown.

Data retained by the gateway

Data NOT retained

Firebird MCP Server

Source: npm package mcp-firebird (PuroDelphi) · Type: SQL queries on Firebird databases (including legacy line-of-business systems)

Lets the agent query via SQL and explore the schema of a Firebird database, connecting over the native Firebird protocol (no ODBC). A read-only user on dedicated views is recommended.

Data retained by the gateway

Data NOT retained

Revocation

The admin can remove the McpServer from the panel (clears the credentials) or revoke the Firebird user on the database.

Free Image Generator (Pollinations)

Source: internal Memori gateway using the public service pollinations.ai · Type: image/text/audio generation

Generates images, text, or audio via the free pollinations.ai API. Supports generation, editing, and image-to-image.

Data retained by the gateway

Data NOT retained

Ghost CMS

Source: npm package @fanyangmeng/ghost-mcp · Type: Ghost blog management (posts, pages, tags, members) via Admin API

Lets the agent create, edit and publish posts and pages, manage tags, members and settings of a Ghost CMS site. The agent asks for confirmation before publishing or deleting content.

Data retained by the gateway

Data NOT retained

Revocation

Remove the McpServer from the panel, or delete the Custom Integration in Ghost (Settings → Integrations), which invalidates the key.

Glacier

Source: remote service getglacier.ai (HTTP MCP) · Type: AI-native project management (Kanban board + docs)

Lets the agent read and write the user's Glacier workspace — projects, cards, docs, comments and suggestions — as a collaborator. Access reflects the permissions of the connected account.

Data retained by the gateway

Data NOT retained

Revocation

Remove the McpServer from the panel, or revoke the API key in Glacier (Account Settings → MCP API Key).

Google Workspace MCP Server

Source: PyPI package workspace-mcp (GitHub) · Type: Docs, Sheets, Slides, Drive, Calendar, Gmail

Lets the agent operate on the user's Google account on the user's own instructions: read and send email, manage Calendar events, find and read documents in Drive, create/read/modify Docs/Sheets/Slides.

Data retained by the gateway

OAuth scopes requested

The consent screen presented by Google always lists the permissions this installation actually requests, which may be a subset of the following:

The agent is never given the ability to delete email or to delete Drive files: neither gmail.modify nor the full drive scope is ever requested.

Data NOT retained

Use of Google user data with AI models

To carry out what the user asks in the conversation (for example "summarise the email that arrived today" or "what does this contract say"), the relevant content is passed to the language model behind the agent, for the sole purpose of producing the answer shown to that same user.

How Google user data is secured

Retention and deletion

The refresh token is retained until the user revokes it, and is deleted immediately when the Google account is disconnected or when the connector is removed from the agent. Google content is never retained beyond the request being served. A user may request deletion of their data at any time by writing to privacy@memori.ai or to support at ccare@memori.ai; we confirm the deletion in writing.

Google API Services User Data Policy compliance

Use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revocation

From the Service: "Disconnect Google" button on the agent page, or the "disconnect Google" command in chat. From Google: myaccount.google.com/permissions → remove authorization for "AIsuru".

Linear

Source: OFFICIAL Linear remote service mcp.linear.app · Type: issue tracking and project management

Lets the agent read and write issues, projects, cycles and comments of the connected Linear workspace, with the permissions of the configured credential.

Data retained by the gateway

Data NOT retained

Revocation

Remove the McpServer from the panel, or revoke the API key from Linear's settings.

MCP Persistence

Source: internal Memori gateway service (MongoDB) · Type: per-agent personal database

Personal MongoDB database for each agent, used by the agent itself to store memories, states, preferences, and structured data.

Data retained by the gateway

Data NOT retained

Revocation

The agent admin can reset an agent's database by deleting the linked Persistence McpServer.

Microsoft Dynamics 365

Source: npm package mcp-dataverse (codeurali) · Type: Microsoft Dynamics 365 / Dataverse via Web API v9.2

Lets the agent read and write Microsoft Dynamics 365 data (Sales, Customer Service, Field Service, Marketing, Project Operations) and any Power App built on Microsoft Dataverse. Authentication is application-level (Entra ID service principal, OAuth 2.0 Client Credentials): all users of the agent operate with the permissions of the security role assigned to the App in the Dataverse environment.

Data retained by the gateway

Data NOT retained

Revocation

The agent administrator can remove the McpServer from the panel (clears the credentials). Alternatively, the Client Secret can be revoked from the Azure portal (Microsoft Entra ID → App registrations → your app → Certificates & secrets), or the Application User can be removed from the environment in the Power Platform admin center.

Microsoft Loop

Source: npm package mcp-ms-loop · Type: Microsoft Loop (.loop / .fluid) files via Microsoft Graph

Lets the agent access Microsoft Loop files via Microsoft Graph API (OAuth 2.0 Client Credentials).

Data retained by the gateway

Data NOT retained

Microsoft SQL Server MCP

Source: npm package @donggyunryu/mcp-sql · Type: SQL queries + schema management on MS SQL Server / Azure SQL

Lets the agent run SQL queries and manage schema on a Microsoft SQL Server or Azure SQL database.

Data retained by the gateway

Data NOT retained

MongoDB MCP Server

Source: internal Memori HTTP server memori.ai · Type: MongoDB connection

Lets the agent operate on external MongoDB databases configured by the admin (read, write, aggregations).

Data retained by the gateway

Data NOT retained

Monday.com MCP Server

Source: official Monday.com npm package @mondaydotcomorg/monday-api-mcp (GitHub) · Type: Monday.com integration

Lets the agent interact with the user's Monday.com boards, items, columns, and workspaces.

Data retained by the gateway

Data NOT retained

MySQL MCP Server

Source: npm package @benborla29/mcp-server-mysql · Type: SQL queries on MySQL

Lets the agent inspect schema, run SQL queries, and (optionally) perform write operations on a MySQL database.

Data retained by the gateway

Data NOT retained

n8n Workflow Server

Source: npm package supergateway + external n8n workflow configured by the user · Type: MCP bridge to a self-hosted n8n workflow

Exposes one or more of the user's self-hosted n8n workflows to the agent as MCP tools, via a supergateway SSE bridge.

Data retained by the gateway

Data NOT retained

OAuth / API Connector

Source: generic connector developed by Memori (internal gateway) · Type: HTTP/REST integration with configurable authentication (static token or OAuth2)

Generic connector that exposes to the agent one or more HTTP/REST endpoints configured by the administrator (e.g. corporate APIs, catalogs, LMS such as Docebo, token-protected webhooks). The gateway composes the calls, injects authentication and routes the responses.

Data retained by the gateway

Data NOT retained

Revocation

The administrator can remove the McpServer from the panel (clears endpoints and credentials) or revoke/rotate the credentials (client secret, token) at the API provider.

Outlook MCP Server

Source: npm package @mcp-z/mcp-outlook · Type: Microsoft Outlook / Exchange via Microsoft Graph

Lets the agent manage the user's Outlook mailbox: read mail, search, download attachments (with text extraction from PDF/DOCX/XLSX, and visual recognition via AIsuru Vision for images/receipts), send mail, manage categories/labels.

Data retained by the gateway

OAuth scopes requested

Data NOT retained

Revocation

From the Service: "Disconnect" button on the Outlook agent page. From Microsoft: myaccount.microsoft.com → "Apps and services" → remove the AIsuru app authorization.

PostgreSQL MCP Server

Source: npm package @henkey/postgres-mcp-server (GitHub) · Type: PostgreSQL query and schema management

Lets the agent run SELECT/INSERT/UPDATE/DELETE queries, manage schema, indexes, RLS, users, and diagnose issues on a PostgreSQL database.

Data retained by the gateway

Data NOT retained

Salesforce MCP Server

Source: npm package @tsmztech/mcp-server-salesforce · Type: read / write on Salesforce

Lets the agent access the user's Salesforce data and features via OAuth 2.0 Client Credentials.

Data retained by the gateway

Data NOT retained

SharePoint MCP Server

Source: npm package developed by Memori @memori.ai/mcp-sharepoint · Type: SharePoint / Microsoft Graph

Lets the agent access SharePoint documents via Microsoft Graph API. Two modes: application (OAuth 2.0 Client Credentials: all users operate with the app's permissions) or corporate login (delegated OAuth: each user connects with their own Microsoft account and sees only what they can access).

Data retained by the gateway

Data NOT retained

Revocation

Corporate-login mode: from the connector Dashboard (remove the account) or from myaccount.microsoft.com. Application mode: revoke the Client Secret/certificate on Azure.

Wikipedia

Source: npm package @shelm/wikipedia-mcp-server · Type: search / read on Wikipedia (public)

Lets the agent query Wikipedia and use its public content.

Data retained by the gateway

Data NOT retained

Word MCP Server

Source: PyPI package docx-mcp-server (SecurityRonin) · Type: document creation/editing (.docx)

Lets the agent create and edit Word documents (paragraphs, tables, headers, tracked changes, comments), optionally starting from a company template. Files are processed in the gateway workspace. Available to authenticated users only.

Data collected by the gateway

Data NOT retained

Revocation

Files expire and are deleted automatically within 24 hours. There are no persistent credentials to revoke.

Work IQ (Microsoft 365)

Source: OFFICIAL Microsoft remote service workiq.svc.cloud.microsoft · Type: Microsoft 365 work intelligence (mail, calendar, Teams, documents, Copilot)

Lets the agent access the user's Microsoft 365 work data (email, events, Teams chats and channels, documents, people) and query Microsoft 365 Copilot in natural language. Each user connects with their own corporate account: the agent sees only what the user can see. Requires a Microsoft 365 Copilot license and tenant admin consent.

Data retained by the gateway

OAuth scopes requested

Data NOT retained

Revocation

From the connector Dashboard (remove the connected account), or from Microsoft: myaccount.microsoft.com → "Apps and services". The administrator can revoke admin consent from the App Registration in Entra ID.

Zapier MCP Server

Source: npm package supergateway + Zapier webhook configured by the user · Type: MCP bridge to Zapier automations

Exposes the user's Zapier automations to the agent as MCP tools, via a supergateway SSE bridge.

Data retained by the gateway

Data NOT retained

User rights

As a data subject, the user is entitled to:

To exercise these rights: privacy@memori.ai.

Updates

We will update this page whenever we add or remove an MCP server connector from the catalog, or when an existing connector changes the type of data processed or OAuth scopes requested.

Document published at mcp.aisuru.ai/en/privacy-policy. Italian version: mcp.aisuru.ai/it/privacy-policy.