Arc & Ledger MCP Server Privacy Policy
Last updated: July 26, 2026
This policy covers both public remote MCP endpoints operated by Arc & Ledger Accounting: https://mcp.arcandledger.com/mcp and the directory edition at https://mcp.arcandledger.com/directory/mcp. The endpoints require no Arc & Ledger account or authentication. Their tools are read-only. The directory edition contains only educational tax-reference and estimation tools, with no service, booking, payment, upload, or purchase link.
1. What data we collect
Your AI assistant sends only the tool inputs needed to answer a request. Examples include an IRS notice code, filing status, tax year, country, dates, and estimated dollar figures. Some tools accept a short label such as a form name or state. The MCP server has no account-registration or document-upload function. Do not send a Social Security number, ITIN, EIN, tax account number, bank information, password, document, or other identifying data. None of those items is needed to use the directory edition.
2. How we use it
Tool inputs are processed in memory only to validate the request, calculate or retrieve the requested general information, and return the result to your AI assistant. Arc & Ledger does not use MCP inputs or outputs for advertising, profiling, model training, lead generation, or automated decisions about a person.
3. Application logging and rate limits
The MCP application writes no tool-call input, tool-call output, tool name, or per-call analytics log. Observability logging is disabled for the Worker. To limit abuse, the server temporarily uses the network address supplied by the infrastructure as a rate-limit key. That key is used only in an in-memory counter and Cloudflare's native rate-limit service. Arc & Ledger does not write the key to application storage or pair it with the request body.
4. Service provider, sharing, and sale
Cloudflare processes the network request as our hosting and security provider. It may process ordinary network metadata under its own terms and privacy commitments. Arc & Ledger does not send MCP tool inputs to advertising, analytics, or data-broker services. We do not sell personal information or MCP tool inputs. We do not disclose them for cross-context behavioral advertising.
The full /mcp endpoint may return an optional first-party link to a separate website page. Following any link is your choice and is a separate browser request governed by our main website privacy policy and, where applicable, the destination provider's policy. The directory edition does not return service, booking, payment, or upload links.
5. Data retention
Arc & Ledger does not retain tool inputs or outputs after the request is answered and does not create a user history or tax record. The application has no database or file store for MCP requests. Temporary rate-limit state is not an activity history and is not retained by Arc & Ledger as an application record. Cloudflare may retain limited infrastructure and security metadata according to its own retention rules.
Children
The service is intended for adults handling their own or their business's US tax questions and is not directed to children under 13.
Changes
If this policy changes, we will update the date above and post the revised version at this URL.
Contact
Questions about this policy or the MCP server can be sent to info@arcandledger.com. Arc & Ledger Accounting, 5183 Overland Avenue, Suite B, Culver City, CA 90230.
The tools provide general information, not tax advice. Using them does not create a practitioner-client relationship. Arc & Ledger is led by an Enrolled Agent who is enrolled to practice before the IRS. The Enrolled Agent credential is issued by the U.S. Department of the Treasury.