SkyFi MCP Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how Skyfi, Inc. ("SkyFi", "we", "us") collects, uses, stores, and shares information when you use SkyFi's Model Context Protocol (MCP) server (the "Service"). It supplements the SkyFi Privacy Policy at skyfi.com, which governs your SkyFi account generally; for the Service, this policy controls where the two conflict. By using the Service — including by authorizing an AI agent or MCP client to act on your behalf — you agree to this policy. Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Information We Collect
- Account and identity data. When you sign in with your SkyFi (Firebase) credentials, we collect your email address and resolve your SkyFi user identifier and organization ("tenant") from the SkyFi platform.
- Authentication and authorization data. OAuth client registrations, authorization codes, access tokens, refresh tokens, and the scopes you grant. We also persist a Firebase refresh token so we can obtain fresh credentials to call SkyFi APIs on your behalf without forcing you to sign in repeatedly.
- Requests and content you submit. Place names you geocode, areas of interest and other geometries (e.g. WKT polygons), existing-image search, feasibility, and tasking parameters, saved AOIs, order and tasking instructions, and analytics requests.
- Order and transaction metadata. Orders placed through the Service, the fulfilling provider, prices, and references to deliverables. Payment processing occurs on the SkyFi platform; we do not collect or store your payment-card numbers.
- Usage and audit logs. Records of the tools you (or an agent you authorized) invoke — including the tool name, timestamp, the authorizing user and client, and request parameters — used for security, abuse prevention, and support.
- Technical data. IP address, request and connection metadata, and diagnostic and observability telemetry generated as the Service operates.
2. How We Use Information
We use the information above to:
- authenticate you and authorize the AI agents and MCP clients you approve;
- carry out the operations you (or an agent you authorized) request — existing-image search, AOI management, feasibility and tasking, ordering, deliverable delivery, and imagery analytics — by calling the SkyFi platform and its imagery providers;
- process and bill orders through the SkyFi platform;
- maintain your saved AOIs and order history;
- secure the Service, enforce rate limits, prevent abuse, and investigate incidents;
- operate, debug, monitor, and improve the Service; and
- comply with our legal obligations.
We do not sell your personal information, and we do not use it to train AI models.
3. Disclosure to AI Agents and MCP Clients — Please Read Carefully
The Service exists to let an AI agent or MCP client you authorize act on your behalf. Data you request through the Service — both the inputs you provide and the outputs a tool returns, including imagery, order details, and account information — is delivered to that client and to the model provider operating it (for example, the AI assistant you connected). We do not control how an authorized client or its provider uses, stores, or further shares that data; review their privacy terms before connecting. You may revoke an authorization at any time, though revocation does not undo disclosures already made.
4. How We Share Information
- SkyFi platform. The Service is an interface to your SkyFi account; we share data with the SkyFi platform APIs to perform your requests.
- Authentication provider. Google Firebase, for sign-in and identity verification.
- Imagery and tasking providers. Third-party satellite operators and data providers, as needed to fulfill the orders and tasking you request; their use of data is subject to their own terms.
- Infrastructure providers. Cloud hosting, database, object-storage (including Google Cloud Storage for deliverable and analytics files), and observability vendors that process data on our behalf under contract.
- Legal and safety. When required by law, or to protect the rights, safety, and integrity of the Service, our users, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
We do not sell personal information.
5. Data Storage and Security
Information is held in our managed databases (OAuth state, audit logs, saved-AOI and identity records), in ephemeral stores (such as rate-limit counters), and in cloud object storage (deliverables and analytics outputs), hosted on cloud infrastructure in the United States. We protect data in transit with TLS, sign and scope OAuth access tokens, require PKCE for the authorization flow, and apply access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention
- Authentication tokens. Access tokens are short-lived. Refresh tokens — including the stored Firebase refresh token — are kept until they expire or you revoke the authorization (through your MCP client, the Service's revocation endpoint, or by contacting us).
- Audit and usage logs. Retained for a limited period as needed for security, troubleshooting, and legal compliance, then deleted or anonymized.
- Saved AOIs. Kept until you delete them.
- Order records. Retained as part of your SkyFi account under the main SkyFi terms and applicable legal and financial-recordkeeping requirements.
We retain personal information only for as long as necessary for the purposes described in this policy or as required by law.
7. Your Rights and Choices
- Revoke any MCP client's authorization at any time.
- View, create, update, and delete your saved AOIs through the Service.
- Request access to, correction of, or deletion of your personal information, subject to legal limits, by contacting us. Account-level rights are handled under the main SkyFi Privacy Policy.
- Depending on where you live, you may have additional rights (for example, under the GDPR or CCPA); see the main SkyFi Privacy Policy for details.
8. International Users
The Service is operated from the United States. By using it, you understand that your information may be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
9. Children's Privacy
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them.
10. Changes to This Policy
We may update this policy from time to time. Material changes are reflected by updating the "Last updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this Privacy Policy, or requests regarding your information? Contact Skyfi, Inc. at [email protected].