Privacy policy
What the Ibis Gear connector receives, what it records, and for how long.
Applies to the MCP connector at https://mcp.ibis-gear.shop/mcp and
to these pages. It does not cover the https://ibis.net.ua online shop, which has its
own policy.
In short
The connector reads a public product catalogue. It never receives your Claude account, your identity or the rest of your conversation — only the search terms and product ids needed to answer the question in front of it. We keep a technical access log for 90 days and use it to keep the service working. We do not sell it, share it or use it for advertising.
Who is responsible
Ibis, operator of https://ibis.net.ua, is the controller for the data described here. Contact: ibisarms@pm.me.
What the connector receives
When Claude calls a tool on your behalf, the server receives only that call's arguments. In practice that is:
- Search terms you asked about — for example a brand, a category or a price ceiling.
- Product, category or brand identifiers taken from earlier results.
- The access token of the connecting client, and standard request metadata such as the IP address and user agent that reach any web server.
It does not receive your name, email, Claude account, payment details, files, or any part of the conversation other than the arguments of the call itself.
What we record
Each call is written to an access log holding: the time, the tool name, the arguments of that call, the responding status code, how long it took, a short summary of the result, any error message, and which client credential was used.
Because the arguments are stored, anything you type into a search reaches that log. Please do not put personal or confidential information into a product search — there is no reason to, and it would be recorded.
For clients that sign in, we also store the issued token as a SHA-256 hash rather than the token itself, along with its scopes, its expiry and whether it was revoked. A token's plaintext value is shown once at issue and never stored, so it cannot be recovered from our database.
Why we record it
- Keeping the service up. Diagnosing errors and finding which calls fail and why.
- Abuse and rate limiting. The per-credential limit is counted over this log; without it the limit could not be enforced.
- Improving the answers. Aggregate counts of which tools are used and which searches come back empty tell us what to fix in the catalogue coverage.
The lawful basis is our legitimate interest in operating a secure, working service.
How long we keep it
Access log entries are deleted after 90 days. Expired and revoked tokens are removed on the same cycle. Aggregate counts that identify no individual call may be kept longer.
Who else sees it
Nobody. The data stays on infrastructure operated by Ibis. We do not sell it, rent it, share it with advertisers, or use it to profile individuals. We do not use it to train machine-learning models.
Product images are served from our own storage over signed links that expire after about an hour. The pages you are reading carry no analytics, no cookies and no third-party scripts.
Your rights
You may ask what we hold about a given credential, ask for it to be deleted, or object to the processing described above. Write to ibisarms@pm.me and we will respond within 30 days.
Note that log entries carry no account identity — to find yours we need the client credential or the approximate time of the calls.
Children
The catalogue includes goods whose sale is age-restricted under Ukrainian law. The connector is not directed at children and is not intended for use by anyone under 18.
Changes
If this policy changes materially, the updated version appears here with a new date below before the change takes effect.