Skip to main content

Privacy And Security

The GameDiscoverCo Pro MCP server is read-only. It provides authenticated access to GameDiscoverCo analytics data and does not allow MCP clients to modify your account, billing, or customer records.

Security Model

  • The production endpoint uses HTTPS.
  • Authenticated MCP connections use OAuth.
  • The MCP endpoint validates browser Origin headers.
  • Public tools are annotated as read-only and idempotent.
  • The MCP server does not expose MCP resources.

Personal Data

GameDiscoverCo stores the email address associated with your paid GameDiscoverCo Pro account. Authentication uses Google Firebase, which stores passwords securely.

For the MCP server, we store request metadata including IP address, Firebase user ID, and the tool called. This metadata is retained for 7 days for anti-abuse and security reasons.

OAuth Tokens

Your MCP client receives an OAuth access token after login. Access tokens expire after 60 days. Refresh tokens are not currently issued, so re-authenticate when your client asks you to reconnect.

Public Privacy Policy

Read the full GameDiscoverCo privacy policy at:

https://gamediscover.co/privacy-policy

Support

For privacy or security questions, email contact@gamediscover.co.