Privacy Policy
Effective June 10, 2026 · Last updated June 10, 2026
This Privacy Policy describes how ELEVETE LLC, a South Dakota limited liability company doing business as orionOmega (“orionOmega,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you visit our website or use the mcpMyAdmin platform, applications, APIs, and related services (collectively, the “Service”). It also explains your privacy rights and how to exercise them.
By using the Service, you acknowledge this Privacy Policy. This Policy is incorporated into our Terms of Service. If you do not agree, please do not use the Service.
- Scope; Our Role
- Information We Collect
- How We Use Information
- AI Clients & Connected Tools
- How We Disclose Information
- Cookies & Analytics
- Data Storage & Deletion
- Security
- U.S. State Privacy Rights
- EEA, UK & Swiss Users (GDPR)
- International Data Transfers
- Children’s Privacy
- Do Not Track & Opt-Out Signals
- Changes to This Policy
- Contact Us
1. Scope; Our Role
This Policy applies to personal information we process as a controller (or “business”) — for example, your account, billing, and website data. Content that you or your organization submit to the Service — such as connections, data sets, tool configurations, prompts, and files (“Customer Content”) — is processed on your behalf and at your direction; for Customer Content, we act primarily as a processor (or “service provider”). If you interact with the Service through an organization’s workspace, that organization controls its workspace and Customer Content; direct privacy requests concerning that data to the organization, and its privacy practices govern.
2. Information We Collect
2.1 Information you provide
- Account information: name, email address, password or OAuth credentials, organization name, role, and profile details. If you sign in through a third-party OAuth provider, we receive information that provider makes available (such as your name, email, and account identifier).
- Billing information: plan, seats, and transaction history. Payment card details are collected and processed directly by our payment processor (Stripe); we do not store full card numbers.
- Customer Content: database connections, data sets, prompts, tool configurations, audit records, and files you or your users submit to the Service.
- Communications: messages you send us, including support requests, feedback, and survey responses.
2.2 Information collected automatically
- Usage data: features used, tool invocations, API and MCP request metadata, seat activity, audit log events, timestamps, and performance data.
- Device and connection data: IP address, browser type, operating system, device identifiers, referring URLs, and pages viewed.
- Cookies and similar technologies: see Section 6.
2.3 Information from third parties
We may receive information from OAuth identity providers, payment processors (e.g., confirmation of payment status), analytics providers, and publicly available sources.
3. How We Use Information
We use personal information to:
- provide, operate, maintain, secure, and improve the Service, including authentication, database connectors, tool governance, audit logging, and seat management;
- process transactions, manage subscriptions and trials, and send transactional communications (receipts, renewal and trial-expiration notices, security alerts);
- respond to support requests and communicate with you about the Service, including service announcements and, where permitted, marketing (you may opt out of marketing at any time);
- monitor, detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
- analyze usage to understand and improve performance and develop new features, including through aggregated or de-identified data;
- comply with legal obligations and enforce our agreements and legal rights; and
- fulfill any other purpose disclosed to you when we collect it or with your consent.
We may create and use aggregated, anonymized, or de-identified data for any lawful purpose; we maintain such data in de-identified form and do not attempt to re-identify it.
4. AI Clients & Connected Tools
The Service is an MCP server that gives the AI clients you connect (such as Claude, ChatGPT, or Cursor) governed, read-only access to the databases, warehouses, data sets, and tools you configure. When you authorize a client, Customer Content it queries is transmitted to that third-party client at your direction, solely to provide the functionality you requested.
- We do not use your Customer Content to train AI models.
- The AI clients you connect are operated by third parties under their own terms and privacy policies; your use of those clients is governed by their terms.
- Query results and other data returned to a connected client are stored as part of your workspace data and treated as Customer Content.
- Do not submit personal information to connected clients beyond what is necessary; you are responsible for ensuring you have the right to submit any personal information contained in Customer Content.
5. How We Disclose Information
We do not sell personal information for money. We disclose personal information in the following circumstances:
- Service providers / processors: vendors who process data on our behalf under contractual confidentiality and data protection obligations, including cloud hosting and infrastructure providers (e.g., DigitalOcean and underlying cloud platforms), payment processing (Stripe), authentication (Clerk), email/communications providers, and analytics providers.
- Within your organization: workspace administrators can access workspace data, seat activity, and audit logs associated with their organization’s account.
- Legal compliance and protection: when we believe disclosure is reasonably necessary to comply with law, regulation, legal process, or governmental request; to enforce our Terms; to detect or prevent fraud, abuse, or security issues; or to protect the rights, property, or safety of the Company, our users, or others.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, your information may be transferred as part of that transaction, subject to reasonable confidentiality protections.
- With your consent or at your direction: including when you connect third-party MCP clients, tools, or integrations to your workspace — data shared with those third parties is governed by their own terms and privacy policies.
6. Cookies & Analytics
We use cookies and similar technologies (local storage) that are: (a) strictly necessary — authentication, session management, security, and load balancing; and (b) functional — remembering preferences.
For usage analytics we use a self-hosted deployment of Umami, an open-source, privacy-focused analytics tool that runs entirely on our own infrastructure. It is cookieless, does not use cross-site tracking or fingerprinting, and collects only aggregate page-view and usage statistics. Analytics data is processed on our own servers; it is never sold and never shared with any third-party analytics vendor.
You can control cookies through your browser settings (blocking strictly necessary cookies may impair the Service). We honor opt-out preference signals as described in Section 13.
7. Data Storage & Deletion
We keep personal information for as long as necessary to provide the Service, comply with legal obligations (e.g., tax and accounting), resolve disputes, enforce agreements, and maintain security and audit records. In general: account data is kept while your account is active; Customer Content is kept until deleted by you or until a reasonable period after account termination, after which it is deleted or de-identified in the ordinary course (backups may persist for a limited additional period before being overwritten); billing records are kept as required by law; and audit logs are kept per plan limits or legal requirements. How long we keep data varies based on data type, legal requirements, and legitimate business needs.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including OAuth-based access control, encryption in transit, role- and permission-based tool governance, and audit logging. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials, API keys, and tokens and for configuring your workspace permissions appropriately. If we learn of a breach affecting your personal information, we will notify you and regulators as required by applicable law.
9. U.S. State Privacy Rights
Depending on your state of residence (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia), you may have some or all of the following rights with respect to personal information we hold about you as a controller/business:
- Know/Access: confirm whether we process your personal information and access a copy of it;
- Correct: request correction of inaccurate personal information;
- Delete: request deletion of your personal information;
- Portability: obtain a portable copy of personal information you provided;
- Opt out: opt out of targeted advertising, “sale”/“sharing” of personal information, and certain profiling. We do not sell personal information for money; if our use of analytics or advertising cookies is deemed a “sale” or “sharing” under applicable law, you may opt out via our cookie controls, browser opt-out signals (Section 13), or by contacting us;
- Limit sensitive data: we do not use or disclose sensitive personal information for purposes requiring a right to limit;
- Non-discrimination: we will not discriminate against you for exercising your rights.
Exercising your rights
Submit requests by emailing helpdesk@orionomega.dev (Subject: “Privacy Request”) with your name, account email, state of residence, and the right you wish to exercise. We will verify your identity (typically by matching your request to account information and confirming control of the account email) and respond within the time required by applicable law (generally 45 days, extendable as permitted). Authorized agents may submit requests with proof of authorization; we may require you to verify your identity directly. If we decline a request, you may appeal by replying to our decision with “Appeal” in the subject line; if your appeal is denied, you may contact your state attorney general.
California notice: In the preceding 12 months we have collected the categories of personal information described in Section 2 (identifiers; commercial information; internet/electronic activity; professional information; and inferences, if any), sourced as described there, for the purposes in Section 3, and disclosed them for business purposes to the categories of recipients in Section 5. We do not sell personal information for money and do not knowingly sell or share the personal information of consumers under 16 years of age. We keep personal information as described in Section 7. California residents may exercise rights via the contact above, including through an opt-out preference signal.
Note for workspace users: if your data is held in an organization’s workspace as Customer Content, we may refer your request to that organization, as the controller of that data.
10. EEA, UK & Swiss Users (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, the following applies to personal data we process as controller:
10.1 Legal bases
- Contract: to provide the Service, manage accounts, and process payments;
- Legitimate interests: to secure and improve the Service, prevent fraud and abuse, and communicate with you about the Service, balanced against your rights;
- Consent: for non-essential cookies/analytics and marketing where required (you may withdraw consent at any time); and
- Legal obligation: to comply with applicable laws.
10.2 Your rights
You may have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests and to direct marketing), and the right to withdraw consent. Exercise these rights by contacting helpdesk@orionomega.dev. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concerns first.
10.3 Processor role
For Customer Content, we process personal data on documented instructions of the customer organization as processor. A data processing addendum (including Standard Contractual Clauses for international transfers) is available on request for business customers that require one.
11. International Data Transfers
We are based in the United States, and the Service is hosted on U.S.-based infrastructure. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the United States and other jurisdictions where we or our service providers operate, which may have different data protection laws than your jurisdiction. Where required, we use appropriate safeguards for such transfers, such as Standard Contractual Clauses or reliance on providers’ participation in recognized transfer frameworks.
12. Children’s Privacy
The Service is intended for business and professional use by adults and is not directed to anyone under 18. We do not knowingly collect personal information from children under 13 (or the higher minimum age required in your jurisdiction). If you believe a child has provided us personal information, contact helpdesk@orionomega.dev and we will delete it.
13. Do Not Track & Opt-Out Preference Signals
We honor browser-based opt-out preference signals, such as the Global Privacy Control (GPC), as a request to opt out of any “sale,” “sharing,” or targeted-advertising use of personal information associated with your browser, where required by applicable law. Because there is no common standard for legacy “Do Not Track” signals, we do not respond to DNT signals other than as described here.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated Policy on this page with a revised “Last Updated” date and, for material changes, provide additional notice where required by law (such as email or in-Service notice). Your continued use of the Service after an updated Policy takes effect constitutes acknowledgment of the updated Policy.
15. Contact Us
For privacy questions or to exercise your rights:
ELEVETE LLC dba orionOmega
Email:
helpdesk@orionomega.dev (Subject:
“Privacy Request”)