TerminaLink privacy notice

Effective date: 22 September 2026.

Tall Tree Digital operates TerminaLink. This notice covers the website, account dashboard, MCP relay and local service. For access, correction or deletion requests, email support@terminalinkmcp.com with the subject Privacy request.

What we process and why

  • Account identity: the sign-in provider's subject identifier and any supplied name, email and profile-picture URL. These establish the account identity. The dashboard displays name and email, not the picture.
  • Device records: device ID, chosen name, operating system, architecture, pairing dates and hashed credentials. These connect and authorize the computers you choose. Current connection state and local-service-reported version are held in memory.
  • Authentication records: hashed browser-session tokens, CSRF values, temporary sign-in state and pairing approvals. These protect account access.
  • Usage: tool-call totals and the UTC monthly window, used to display usage and enforce the Free allowance.
  • Billing: Stripe customer and subscription identifiers, subscription status, paid-period end and checkout retry identifiers. Stripe collects payment details and billing address for payment and tax handling. TerminaLink does not receive full payment-card details.
  • Tool traffic: commands, requested file contents, diagnostic results and process output, used to perform and return the operations you request.
  • Support correspondence and minimal operational metadata, used to answer requests, diagnose failures and protect the service.

Website and browser storage

The information website has no advertising or analytics trackers, account form or payment form. Fonts and assets are served with the page. Copy buttons write the displayed text only after you select them; the site does not read your clipboard. Normal web requests disclose network address, requested path, time and HTTP result to the serving infrastructure.

The account dashboard uses necessary authentication cookies. Browser sessions expire after 12 hours. The dashboard has no advertising or analytics trackers. Do not put secrets or personal information in page URLs.

Commands, files and local data

Commands and output pass through the relay in memory. The relay does not intentionally persist them as command history. The local service buffers output locally for session reads. A command can itself write files or send information to other systems. Content returned to ChatGPT is also processed by OpenAI under its own policies.

The local service writes local connection/status logs and security receipts. Receipts contain metadata such as workspace, scope, policy state, time and result, not intentional copies of raw commands or output. Local diagnostics can contain usernames, device names and paths. Review and redact them before sharing.

Recipients and service providers

Account sign-in is handled by the configured identity provider. Stripe handles payments. OpenAI processes content you return to ChatGPT. Hosting, network, backup and email providers process the data needed to operate their part of the service. Authorized Tall Tree Digital staff can access records needed for support, operations or security. We do not sell personal information or use terminal content for advertising.

External providers apply their own privacy and legal retention rules. Processing can occur in the countries where those providers operate. Contact support@terminalinkmcp.com for provider and data-location information relevant to your account.

Retention

  • Operational and security logs: a rolling maximum of 30 days for minimal metadata. Request bodies, authorization headers and terminal content must not be included in these logs.
  • Encrypted account-state backups: a rolling maximum of 30 days. Deleted records can remain in a restricted backup until it expires. Account deletions must be reapplied before a restored system is reopened.
  • Support correspondence: deleted within 12 months after the request is resolved, or earlier when no longer needed. Accidentally received credentials are removed and you are asked to rotate them.
  • Account and device records: retained while needed for your account until revoked or deleted. The usage store replaces the prior monthly window when a new call is recorded. Expired temporary authentication and pairing records are pruned during state changes.

A specific legal obligation or security incident can require limited records to be held longer. Such holds are restricted to the relevant records and purpose. Payment providers can retain financial records under their own obligations. Local agent logs remain on your computer until you remove them; the hosted retention schedule does not manage your local files.

Your controls and requests

Use the dashboard to revoke a device or delete an account. terminalink unpair revokes the current device. terminalink delete-account --yes removes relay account data and clears credentials on that computer. An active subscription must end first. Deletion removes live account/profile, device, session, pending authorization and usage records. It also closes the linked Stripe customer after confirming that no active subscription remains.

Account deletion does not remove your identity-provider account, ChatGPT conversations, local files or agent installation. Use terminalink uninstall --purge to remove local TerminaLink configuration and logs. Revocation and deletion cannot undo commands that already ran.

Email support@terminalinkmcp.com to request access, correction or deletion, or to ask a privacy question. We verify control through the existing account where possible. Do not send passwords, tokens or identity documents with your initial request. We handle requests under applicable law and explain any records that cannot be removed or are controlled by another provider.