Search Results :

×

miniOrange Privacy Policy for Secure MCP Server

This policy outlines how our Secure MCP Server collects, stores, processes, and protects your authorized data connections between your AI assistant and your WordPress environment.

Last updated: June 9, 2026

As a security Company, miniOrange aims to provide secure and resilient solutions to all our Customers and make sure we provide the products and services which are thoroughly tested with all the necessary requirements from various marketplaces where miniOrange Solutions exist like WordPress, Drupal, Joomla, Atlassian, Shopify, etc.

We also focus on ensuring that our customers get the best support and services throughout their miniOrange product experience. Our team is always on the standby to help and fulfill your requirements in the best possible way.


1. Overview

This Privacy Policy ("Policy") explains how Xecurify Inc. ("Xecurify", "miniOrange", "we", "us"), collect, store, use, disclose, and otherwise process the information relating to individuals ("Personal Data") and to learn about your rights and choices regarding our processing of your Personal Data in the course of our business. In this Privacy Policy, "Xecurify," "mini Orange" "we," "our," and "us" each mean Xecurify and the applicable Xecurify affiliate(s) involved in the processing activity.

2. Information We Process

2.1 Account connection data (stored)

• The WordPress site URL you connect to.

• OAuth tokens issued by your WordPress site (access and refresh tokens) that allow the Service to act on your behalf. These tokens are encrypted at rest and are never stored or logged in plaintext.

• Connection metadata: an internal connection identifier, the registering AI client's identifier, connection status, and created / last-used timestamps.

2.2 Authorization state (transient)

• Short-lived OAuth authorization codes, PKCE values, sign-in sessions, and the access and refresh tokens the Service issues to your AI assistant. These are held in a cache with short expiries, and opaque secrets are stored only as one-way hashes.

2.3 MCP tools (transient, not retained)

• A site's list of available tools may be cached for up to 60 seconds for performance.

2.4 Operational data

• Server logs containing the site URL, connection identifiers, timestamps, and request outcomes (no tokens and no tool-call contents).

• IP addresses, used transiently for rate limiting and abuse prevention.

We do NOT collect: your AI assistant chat history; payment card data; health information; government-issued identifiers; or any personal data beyond what is described above.

3. How We Use Information

• To establish and maintain your authorized connection between your AI assistant and your WordPress site.

• To forward the tool requests you initiate and return their results.

• To secure the Service, including authentication, encryption, rate limiting, and abuse and fraud prevention.

• To operate, debug, monitor, and improve the reliability of the Service.

We do not sell your personal data, and we do not use it for advertising or for training AI models.

4. Sharing and Recipients

Your WordPress site: requests and tokens flow to the site URL you connect, which is your own system.

Your AI assistant platform (for example, OpenAI or Anthropic): the MCP client you connect from. Their handling of your data is governed by their own policies.

Infrastructure sub-processors: we use third-party cloud providers to host and operate the Service (cloud hosting, a managed database, and a managed cache). They process data only to provide hosting to us under contract. A current list of sub-processors is available on request at info@xecurify.com.

Legal and safety: we may disclose information where required by law or to protect the rights, property, or the safety of our users or the public.

5. Data Retention

We retain personal information we collect from you only as long as necessary to fulfill the services requested and comply with legal obligations, resolve disputes, or enforce agreements.

6. Your Rights and Choices

You can change your Xecurify information at any time by editing your account, or by closing your account. You can also ask us for additional information we may have about your account. You have a right to (1) access, modify, correct, or delete your personal information controlled by Xecurify regarding your account, and (2) close your account. You can also contact us for any account information which is not readily accessible to you.

7. Security

We protect all data in transit using Transport Layer Security (TLS) and encrypt stored access tokens at rest using advanced cryptographic standards, complemented by secure one-way hashing for critical credentials. System access is strictly governed by the principle of least privilege-bounded by the authorizing user's permissions-and enforced through robust proof-key mechanisms for code exchanges.

8. International Data Transfers

The Service is operated from the United States, and your information is processed there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States. Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.

9. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us, and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with a new "Last updated" date. Your continued use of the Service after an update constitutes acceptance of the revised policy.

Contact Us

If you would like to contact us with questions or concerns about our privacy policies and practices, you may contact us via any of the following methods:

Email: info@xecurify.com

Phone: +1 978 658 9387

Form: Contact Us / Visit miniOrange

Hello there!

Need Help? We are right here!

support