Last updated: October 2, 2026
What personal information Maps MCP ("we", "us") collects when you use mapsmcp.com, the Maps MCP API and dashboard, and published reports; how we use it; who we share it with; and the choices you have. We don't sell personal information, and our pages carry no advertising or analytics trackers.
Your email address and full name, and your workspace's name. If you create child workspaces, the owner email address you give for each one.
The optional details you give when signing up: company, role, what you're building, industry, and how you heard about us. We also record when you agreed to the Terms of Service, and the IP address and browser user agent your signup came from.
When we send you a sign-in link or you start a dashboard session, we store the time, the IP address and browser user agent involved, and a hashed copy of the link or session token. API keys are stored only as SHA-256 hashes plus a short prefix so you can tell them apart, along with when each key was last used.
For each metered tool call we record the workspace, the tool name, whether it was a standard or premium call, the number of units, the time, and an error message if the call failed. These records don't include the arguments you passed. On paid plans, Stripe collects your payment details directly, and we never see or store your card number. We store your Stripe customer and subscription IDs, your plan, whether a payment method is on file, and references to your checkout sessions. The billing email we give Stripe is your account email.
The datasets, records, files, shapes, reports, and other content you upload or create, plus workspace settings such as stored secrets (for example a third-party API key), webhook endpoints, and scheduled workflows. This content can include personal information about other people, such as addresses in a contact or donor list. You control that information, and we process it on your behalf to provide the service. If your information is in a Maps MCP customer's workspace, please contact that customer; we will help them respond.
The subject, message, priority, and any context you attach to a ticket, plus the replies and the email address of each person who writes one. Tickets are shared with our team by default. If you mark a ticket private, our support tools hide it from our team.
Our email provider reports delivery events for the emails we send, such as delivered, bounced, and marked-as-spam, and opens and clicks where those are reported. We store these events with the recipient's address.
Our servers and hosting providers keep operational logs, which can include IP addresses, the URLs and endpoints requested, timestamps, and error details. Some entries include the email address involved in a signup or sign-in, or the coordinates sent to a drive-time tool.
mapsmcp_session: set when you sign in to the dashboard with an email link, and keeps you signed in for up to 30 days. It is HttpOnly, so page scripts can't read it, and it is sent only over HTTPS.__cf_bm: set by Cloudflare, which protects our site from automated abuse, to help tell people from bots. It expires after 30 minutes.We don't use advertising or analytics cookies or run third-party tracking scripts. Public report pages and some dashboard and documentation pages load open-source map code and fonts from public content-delivery networks (unpkg.com, esm.sh, cdn.redoc.ly, and demotiles.maplibre.org), and reports whose owner chose a Mapbox basemap load map tiles from Mapbox. As with any web content, those services receive your IP address and browser details.
If you try the address demo on our homepage without signing in, the address you type is sent to the U.S. Census Bureau's geocoder, the result is kept in server memory for up to 24 hours so repeat lookups are fast, and your IP address is logged and used to rate-limit requests.
Where laws such as the GDPR apply, we rely on performing our contract with you; our legitimate interests in running, securing, and improving the service and in telling business users about it; your consent where we ask for it; and our legal obligations.
We share personal information with the service providers below, who help us run Maps MCP, and with destinations you direct us to. We don't sell personal information or share it for targeted advertising.
describe_report, interpret_hotspot, compare_versions_narrative, nl_query, characterize_place, suggest_neighborhood_polygon, auto_caption, and generate_district_brief). Only when you call one of these tools do we send Anthropic what it needs, such as your question, report titles and descriptions, place names, and summary statistics from your data.lookup_district_for_address, bulk_match_addresses, and other address-based tools, so the addresses you submit are sent to it. Our queries to its data API contain only geography and table codes.geo_isochrone, evaluate_site). Receives the coordinates and travel settings of each request. Also serves basemap tiles to people viewing reports whose owners chose a Mapbox basemap.We also share information in these cases:
To build system data, our servers also download public datasets from government and research publishers. Those requests don't include your personal information.
When you publish a report, anyone with its link can see it and download its images and underlying data. It can be embedded on other websites, cached by content-delivery networks and browsers, and indexed by search engines. Copies may linger in caches after you unpublish or delete it, and people who already downloaded it may keep their copies. Don't publish personal information unless you intend it to be public. Privacy locks (lock_dataset, lock_report) help prevent accidental publication.
list_admin_access_log tool.No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.
export_workspace tool, or a single dataset with export_dataset. For account information that the export doesn't include, such as your signup details or usage records, email us.mapsmcp_session cookie to keep you signed in.Send any of these requests to [email protected].
Maps MCP is not directed to anyone under 18, and we don't knowingly collect personal information from children. If you believe a child has given us personal information, email us and we will delete it.
We store and process data in the United States. Some providers handle data elsewhere: Cloudflare serves traffic from data centers around the world, and openrouteservice, used only if you choose it, is in Germany. If you use Maps MCP from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live.
We will post any changes on this page and update the date at the top. For material changes we will also tell you by email or with a notice on the site before they take effect.
Questions or requests about privacy: [email protected].