Privacy and session storage
The service uses your Fantacycling password only during browser sign-in. It does not save passwords, upstream bearer tokens or stats cookies to its database.
Your MCP client holds encrypted service credentials containing your Fantacycling session and sends them with requests. The service decrypts the session in memory to contact Fantacycling. A server administrator with runtime access could capture those credentials; this is not protection against a malicious administrator.
The database holds OAuth client metadata, including client secrets where required, random connection identifiers, refresh-token digests and revocation records. Account connection state is temporarily held in memory for up to ten minutes, and login-code session state for up to two minutes.
The service does not log passwords, authorization headers, request bodies or private tool responses. Infrastructure may retain operational request metadata such as IP addresses and paths. ChatGPT or Claude processes tool responses under that provider's own policies.
Disconnect using your client's OAuth revocation support. Reconnecting creates a new session; upstream expiration requires another browser sign-in.
Back