CloudKit MCP

Privacy Policy

Last updated: August 25, 2026

What we collect

  • Google account info: your email address and Google account ID, used only to sign you in and to associate your registered CloudKit containers with your account.
  • CloudKit credentials: the container ID, key ID, and private key you submit when registering a container. The private key is encrypted at rest (AES-256-GCM) and is only decrypted in memory to sign requests to Apple's CloudKit API on your behalf.
  • Usage metadata: which MCP tools are called, how many times, and when each token was last used. We do not log the contents of your CloudKit queries or the record data returned.

How we use it

Solely to operate the CloudKit MCP service: authenticating you, signing CloudKit API requests with your credentials, and showing you your own containers and usage in the dashboard. We do not sell, rent, or share your data with third parties, and we do not use it for advertising.

Third-party services

  • Google — authentication (Sign in with Google)
  • Apple CloudKit — the container you register is yours; we only relay requests to it
  • Vercel — application hosting
  • Neon (Postgres) — encrypted data storage

Data retention and deletion

Your registered containers and their encrypted credentials are kept until you ask us to delete them. To delete your data, email sawyerliam28@gmail.com from the Google account you signed in with.

Security

All traffic is served over HTTPS. CloudKit private keys are encrypted at rest with AES-256-GCM using a server-side master key never exposed to the application beyond the request that needs it.

Contact

Questions about this policy: sawyerliam28@gmail.com