This policy describes how the GPH Intelligence MCP Server (https://gph-mcp-server.pages.dev/mcp) handles data. It covers the MCP service's data handling, not the contents of the underlying vendor directory.
When you call a tool, we receive the name of the tool you called and the query parameters you supply — service category, medical specialty, practice size, city, state, EHR system, budget range, and search filters — together with the identifiers of the providers returned and any provider profile you open, a derived "signal score" (0–3, reflecting how complete the query is), the number of results returned, and a timestamp. We also record the user-agent string of the calling software and, where your client supplies one, the MCP session identifier. If you send a legacy API key, we record only its access tier (otherwise the call is logged as "anonymous"). We receive your IP address from the network connection and use it only (a) for rate limiting and (b) as a transient input to a daily-rotating, non-reversible session-correlation value; your raw IP address is never written to either store.
To operate the service and return results; to enforce rate limits (100 calls per IP per day); and to produce aggregate demand analytics — which categories, specialties, and locations practices ask about, and how that demand arrives — that help us improve the directory and prioritize vendor coverage.
Usage records are stored in Cloudflare D1 (our hosting provider's own database) and mirrored to Airtable (our data processor) for review. Each record holds the non-identifying call metadata described above — tool, query arguments, user-agent, and the derived session identifier — and does not contain your IP address or any account identity. Your IP address is held only as a per-day rate-limit counter in Cloudflare KV, which expires automatically after 48 hours.
Individual usage records are retained for service-improvement analytics in Cloudflare D1 and Airtable for up to 24 months, after which they are deleted; aggregate, de-identified demand statistics derived from them may be kept indefinitely. Rate-limit counters expire automatically after 48 hours.
We use Cloudflare as our hosting and infrastructure provider (including the D1 database) and Airtable as a processor. We use aggregate, non-identifying demand insights to inform vendor and sponsor outreach. We do not sell or share the query or demand data.
No patient health information is requested or required — the tools accept only service category, specialty, location, and similar non-personal filters, so do not submit patient data through this service. We do not store your IP address as part of usage records, set cookies, or require account registration. The session identifier is an ephemeral, daily-rotating correlation value, not a persistent user ID.
We may update this policy; the current version is always at this URL.