FlexReport Finance — Privacy Policy

Effective date: August 3, 2026

This policy describes how FlexReport Finance ("FlexReport", "we") handles your information when you use the FlexReport MCP connector (https://mcp.flexreportfinapi.com/mcp), the FlexReport API, and the FlexReport web application.

What we collect

What the MCP connector itself does NOT store

The MCP connector is a stateless proxy. It holds no user database, stores no credentials or tokens at rest, and forwards your OAuth bearer token to the FlexReport backend on each call, where authorization, plan, and quota are enforced.

How we use your information

Third parties we share data with

Queries sent to OpenAI are processed through its API, which does not use the data to train OpenAI's models. We do not sell your personal information.

Data retention

Your choices and rights

Security

Transport is TLS-encrypted end to end. Authentication uses OAuth 2.0 (authorization code + PKCE); the MCP connector validates tokens against the backend's public keys and never sees your password. By connecting to FlexReport, you grant Claude or your own agents access to your FlexReport account: they can query data, generate reports, and create or delete your scheduled tasks. FlexReport runs entirely on our infrastructure and never accesses your device, files, or network.

Children

The service is not directed to individuals under 18, and we do not knowingly collect their data.

Changes to this policy

We will post any changes to this page and update the effective date. Material changes will be announced by email.

Contact

Please direct all questions and support to support@flexreportfinapi.com. We will respond within one business day.