Privacy Policy
This Privacy Policy applies to mcp-bridge, the Integration Broker operated by 911 IT.
Last updated: 2026-06-15
This Privacy Policy describes how 911 Computer Repair Corp., doing business as 911 IT ("911 IT", "we", "us") collects, uses, and protects information in connection with the mcp-bridge service. By using the service, you agree to the practices described here.
Data We Collect
We collect and process the following categories of data to operate the service:
- OAuth tokens: authorization credentials issued by QuickBooks Online and other connected platforms, stored to maintain your active integrations.
- Audit logs: timestamped records of API calls, data synchronization events, and administrative actions performed through the service.
- User metadata: account identifiers, email addresses, organizational identifiers (such as QuickBooks realm IDs), and feature preferences associated with your account.
We do not collect payment card data or sensitive personal financial information beyond what is necessary to facilitate authorized integrations.
Third Parties
We share data with third-party service providers only as required to operate the service: Intuit (for QuickBooks Online integration). Data shared is limited to what is necessary to fulfill the integration function. We do not sell your personal data to third parties.
Clients consuming the MCP server may forward broker-returned data to LLM providers (including Anthropic) of their own choosing. mcp-bridge itself never sends data to any LLM provider.
Each third party is governed by its own privacy policy. We encourage you to review the privacy practices of Intuit and any other third parties whose services you use in conjunction with mcp-bridge.
Data Retention
We retain OAuth tokens for the duration of your active integration. Audit logs are retained for a minimum of ninety (90) days and may be retained longer where required by applicable law or contractual obligation. User metadata is retained for as long as your account is active and for a reasonable period following account closure to comply with legal obligations.
You may request deletion of your data at any time by contacting us at the address below.
Encryption at Rest
OAuth tokens and credentials are encrypted at rest at the application layer; all data is protected by strict access controls and industry-standard safeguards.
Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data. To exercise these rights, contact us using the information below. We will respond to verifiable requests within thirty (30) days.
Contact Us
For privacy-related inquiries, data deletion requests, or questions about this policy, contact us at: support@911it.com.
911 IT, South Jordan, Utah, USA.