Privacy policy

Last updated 2026-10-03. This policy covers the MCPortal service at https://mcportal.lol, which is run by Lawrence Lane.

Here's the short version. MCPortal stores your GitHub user ID and login, your room (layout, sources, saved items and clips), what you've read in it, a public profile, shares and follows only if you use them, and sign-in tokens. It doesn't store your email, your name or your GitHub password. It has no ads, trackers or analytics, and it doesn't sell or share your data.

What MCPortal stores

DataWhyHow long
Account: your GitHub numeric user ID and login, your role, how you joined (for example, by invite), and datesTo know who you are and whether you're allowed inUntil your account is deleted
Your room: its name, layout, the sources you add (feed addresses, subreddits, repos, searches), and settingsTo show you your roomUntil you change it or your account is deleted
People suggestions: the people your agent suggested following, with the one-line reason it wrote, and the ones you said "Not for me" toFor your People portal, and so your agent knows whom you passed on30 days for a suggestion, 90 for a pass. Only you see them; the people suggested never do
Saved items: the link, title, source, date and any note you addTo show your Saved portalUntil you remove them
Clips: quotes, parts of a conversation, notes, tables, images and links you ask your agent to keep, with any title, note and tagsTo show your Clips portal and find them again in later chatsUntil you delete them
Reading history: the links you've seen, opened or read in your room, with their titles, when, and how far you gotTo mark what's new and pick up where you left offThe latest 1,000 per account, until your account is deleted
Seen marks: which items in each portal you've already seen, stored as short one-way hashes of the items' idsTo mark what's new in each portalUntil you remove the portal or your account is deleted
Highlights: the picks your agent makes for the top of your room, in its own wordsTo lead your room with them24 hours, until replaced; expired ones are removed within a day
Pages sent to a new chat: the link, title and any passage you selected when you send a page from the reader to a new chatTo open it there7 days, at most 50; expired ones are removed within a day
Pinned results: if you ask your agent to pin results from another connected tool (for example, a list of issues), the titles, links, short summaries and details it copies in, and the request needed to refresh themTo show that portalUntil you remove the portal
Public profile and space (only if you create one): your handle, display name, bio, space title and colour, and the sources you choose to feature, which other signed-in MCPortal users can seeSo people can find youUntil you remove it; a handle you give up stays reserved for you for 30 days. If you delete your account, your handles stay reserved for 30 days, so nobody can pose as you, without saying whose they were
Shares: links and clips you choose to share, with your note, a copy of what you shared, and who it's for (your followers or everyone on MCPortal)To show them to the people you shared them withUntil you remove them
Follows, mutes and blocks: who you follow, mute and blockTo build your Following portal and keep blocked people apartUntil you change them. People see how many followers you have, never who
Listing: whether you chose to be findable by people with similar sources (off unless you turn it on)So find_people can suggest you, from your public profile, featured sources and posts shared with everyone, and so those posts (at most 3 a day) appear in the Lobby, and next to the same story in other people's rivers ("also shared by")Until you turn it off, which takes you out of suggestions at once
Space links: whose Space link you signed in through, and, if it brought a new account, that you joined through itSo your room offers to follow them once, and they hear once that you joinedUntil your room or theirs has said so (a block removes it at once)
Reports: what you reported, why, and whenSo admins can act on abuseDeleted 180 days after they're resolved. If you delete your account, reports you made no longer name you (and, once resolved, lose the reason you gave), and reports about you no longer name you
Sign-in tokens: stored only as one-way hashes, with the app that asked for them (for example, Claude). An app's registration records the name it gives, which for MCPortal on your own computer includes the computer's nameTo keep you signed inAccess tokens 1 hour; refresh tokens 30 days. An app registration nobody is signed in with is deleted after 180 days unused, and the ones only you used are deleted with your account
Invites and the admin audit log: who invited whom, accounts being created and deleted, and suspensions or reinstatements with a short reasonTo run invites and keep a record of admin actionsLog entries for a year at most (and only the newest 2,000). Invites nobody used lapse after 90 days. If you delete your account, its entries no longer say whose they were

Usage counters (for rate limits), admin sessions and sign-in attempts in progress are held in memory only and are gone when the server restarts. Your IP address is used for rate limiting in memory and isn't stored.

Signing in with GitHub

MCPortal uses GitHub to read your public user ID and login once, when you sign in. It then discards the GitHub token. MCPortal's sign-in does not read your private repositories or email.

What MCPortal sends to other sites

When your room loads, MCPortal's server fetches the feeds, articles and thumbnails you asked for. Those sites see the server's address, not yours. For some large pictures on WordPress sites, the server asks WordPress.com's image service (run by Automattic) for a smaller copy, so that service sees the picture's address too. Fetched content is cached in the server's memory for between two minutes and one day. Some public content is shared across accounts; docs page bodies are cached per account so searches reflect only that account's reads. It isn't written to the database. When you choose to open an original story or its discussion, your browser goes to that site directly, and that site's own privacy policy applies.

What you see in your room is also available to the agent you use it in, and that agent's privacy policy covers your conversations (in Claude, Anthropic's).

MCPortal on your own computer

You can also run MCPortal on your own computer (the Claude Code plugin, the desktop bundle, or from source). Until you sign in, it's in ghost mode: everything stays in ~/.mcportal on that computer, it fetches feeds and pages itself, and it sends nothing to this service.

If you sign in from it, your room, saved items, clips, reading history, seen marks, public profile, shares and follows are stored by this service exactly as the table above says, and the first sign-in adds that computer's portal to your account. MCPortal on your computer still fetches feeds, articles and pictures itself, so those sites see your computer's address rather than the server's. Its sign-in tokens are kept in a file on your computer that only your user can read. Signing out copies your portal back to the computer, ends that sign-in, and deletes the file. Your account page lists each signed-in computer by name, and you can revoke one from there, for example if you lose it.

What other people see

Nothing, unless you choose. With a public profile, you have a space: signed-in MCPortal users can open it to see your handle, name, bio, space title, the sources you chose to feature, your follower count, and the shares you made for them (your followers, or everyone). Your Space link (/@handle) shows only your handle to people who aren't signed in. Shares are never published to the open web. Admins can see reported shares and profiles, and can hide a share or suspend an account.

Logs

Server logs record which tool ran, whether it worked, how long it took, and a reference that lets one server's logs be read together. The reference is a keyed one-way hash of your account that changes every time the server restarts, so it can't be traced back to you. Logs don't record your user ID, your IP address, what you read or what you asked for. An error message can occasionally include the name of a site that failed to load. Separately, the hosting provider (Railway) keeps request logs, which include IP addresses and the pages requested, for a limited time.

Cookies

MCPortal uses cookies only to complete a GitHub sign-in (they last 10 minutes), to keep you signed in to your account page (1 hour), and to keep admins signed in to the admin page (8 hours). There are no tracking or advertising cookies.

Where it's stored

Data is stored in a Postgres database hosted by Railway in the United States. Only the operator can access it. When scheduled backups are added, this page will say how long they're kept.

Service providers

Your choices

Children

MCPortal isn't meant for anyone under 13, or under the minimum age for a GitHub account where you live.

Changes

If this policy changes, the date at the top changes too. Changes that affect what's stored or who can see it will be announced on this page before they take effect.

Contact

Questions or requests: mailto:lbeezr@icloud.com.