Privacy

Privacy Policy

Effective September 16, 2026. This policy describes the hosted ReMCP service at remcp.delio24.com. A self-hosted deployment is operated by its own administrator and may have different practices.

What ReMCP does

ReMCP authenticates an MCP client, identifies computers you have paired, and relays authorized tool calls between that client and the selected computer. Device agents connect outbound to the ReMCP service.

Account and Google Sign-In data

Authentication is provided by Firebase Authentication. If you choose Google Sign-In, Firebase may provide ReMCP with your Firebase user identifier, email address and display name. ReMCP uses this information only to authenticate you, keep your devices separated from other accounts, and administer your ReMCP account. ReMCP does not request Gmail, Google Drive, Google Calendar or other Google API data.

Device and security metadata

ReMCP stores device identifiers, device names and basic platform metadata, one-way hashes of device credentials, pairing records, OAuth client metadata, and one-way hashes of refresh credentials. Pairing codes are short-lived and single-use. Raw device credentials are returned to the paired device and are not stored in plaintext by the service.

Files, commands and tool results

When you use an MCP tool, its request and response may pass through the ReMCP relay. This can include filenames, file contents, command output and process information that you explicitly ask the paired computer to process. ReMCP does not intentionally retain those tool payloads as product data. Operational security logs may retain limited metadata such as timestamps, status codes and errors.

How data is used and shared

Data is used to provide authentication, device pairing, OAuth authorization, request routing, abuse prevention, security and reliability. ReMCP does not sell personal information and does not serve advertising. Data may be processed by infrastructure and authentication providers only as needed to operate the service, including Firebase/Google for authentication.

Retention and control

Device records remain until revoked or removed. OAuth grants remain until revoked, expired or rotated. Security and operational metadata may be retained for a limited period appropriate to troubleshooting and abuse prevention. You can revoke a paired device from the ReMCP workspace. Requests concerning account data or deletion can be made through the support channel identified on the Support page or in the app listing.

Security and international processing

ReMCP uses TLS for network transport, hashes reusable credentials before storage, and scopes device access to the authenticated account. Internet services may process data in more than one country depending on infrastructure and authentication providers. See the Security page for the current security model.

Children

ReMCP is a developer and systems-administration tool and is not directed to children under 13.

Changes

Material changes to this policy will be published at this URL with an updated effective date.