Privacy Policy
Last updated: July 12, 2026
Toolport is a local-first MCP gateway. This policy explains what data we do and don't collect across the Toolport desktop app, the marketing site at toolport.app, and the hosted Toolport Teams service. Toolport is operated by South Forge AI ("we", "us"). Questions: support@toolport.app.
The short version
The Toolport desktop app and its gateway run entirely on your machine. Your MCP server credentials (API keys and OAuth tokens) are stored in your operating system's keychain and are never sent to us. The app has no account and, on its own, sends us nothing: no telemetry, no phone-home. The one exception is hosted Teams. If you sign into a Team, the gateway reports aggregate usage (call counts and tokens saved per shared server, never the contents) so your team dashboard works. Otherwise we only receive data when you use our website.
The desktop app and gateway
- Credentials stay local. Keys and tokens for the MCP servers you connect live in your OS keychain (macOS Keychain, Windows Credential Manager, or the Linux Secret Service) and are injected at runtime. They never leave your device.
- No telemetry from the app on its own. The desktop app and local gateway don't collect usage analytics or send your servers, tools, or call contents to us. The one exception is hosted Teams: if you sign into a Team, the gateway reports aggregate counts (calls made and tokens saved per shared server, never the contents) so your team dashboard works. Diagnostics you export are shown to you first and sent only if you choose to.
- Activity stays on your device. Toolport keeps recent local logs so its Activity views work: a rolling audit log (about 5,000 entries), discovery traces (~500), inspector history (~50), and a savings log (~2,000), plus a running savings total. These live in your Toolport data folder, are never sent to us, and you can export them from the app or delete them from that folder.
- Updates. To check for new versions, the app requests a small release manifest from GitHub. That request is subject to GitHub's own privacy practices.
The website (toolport.app)
- Analytics and advertising measurement. We use Cloudflare Web Analytics and PostHog to understand aggregate traffic and which pages are useful. When we run an X ad campaign, we may use X's Pixel to measure ad clicks and completed team signups. We do not send X your team configuration, tool calls, API keys, or other credentials, and we do not sell this data.
- Contact / lead forms. If you submit an email through a form (for example, a Teams inquiry), we store it to reply to you and may send it to ourselves by email.
Hosted Toolport Teams
If you create or join a hosted Teams account, we store what's needed to run it:
- Account identity: your email address and, if you sign in with GitHub or Google, the identifier and basic profile that provider returns.
- Team data: team and membership records, roles, seat count, and the team's shared MCP server configuration. Server secrets are stripped before that configuration is stored, so members' API keys never leave their own machines.
- Billing state: subscription and seat status. Card details are handled by Stripe; we never see or store them.
- Session: a login cookie so you stay signed in.
- Usage stats: for the team dashboard we record aggregate call counts and tokens saved per shared server, not the content of your calls. We keep them for your team's reporting and remove them when the team or account is deleted. Self-hosted Teams keeps all of this on your own server.
Sub-processors
Hosted Teams and the website rely on a small set of providers, each handling only what their function requires:
- Neon: hosted Postgres database (account and team records).
- Resend: transactional email (magic-link sign-in).
- Stripe: payment processing.
- GitHub and Google: optional OAuth sign-in.
- Cloudflare: website hosting and analytics.
- PostHog: product/website analytics.
- X: advertising conversion measurement when an X campaign is active.
Retention
We keep hosted Teams account and team data while your account is active. You can delete your account yourself from your profile in the Teams dashboard, or email support@toolport.app, and we delete it (subject to any records we're legally required to keep, such as billing history).
Your rights
From your profile settings in the Teams dashboard you can export your account data or delete your account at any time. You can also request access, export, or deletion of the personal data we hold about you by emailing support@toolport.app. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor those requests.
Children
Toolport is a developer tool and is not directed to children under 16. We do not knowingly collect their data.
Changes
We'll update this page and the date above when this policy changes. Material changes to the hosted service will be communicated by email where appropriate.
Contact: support@toolport.app