Privacy Policy
Effective: September 26, 2026
This Privacy Policy explains what information ADVOCATE MCP LLC collects through Advocate, how we use it, and the choices you have.
1. Who We Are
Advocate is operated by ADVOCATE MCP LLC, a company based in Texas (“Advocate,” “we,” “us,” or “our”). This Privacy Policy explains what personal information we collect through the Advocate service (the “Service”), how we use it, who we share it with, and the choices you have. It applies to our websites and the Service, and it does not apply to the practices of third parties that we do not own or control.
2. What We Collect
We collect only the information we need to operate the Service. Today, that consists of the following.
Account email addresses. When you sign in, we collect the email address you use to receive a magic sign-in link. We use this address to authenticate you and to communicate with you about your account and the Service.
Request-access form submissions. When you ask for access to the Service, we collect the business name and contact email address you provide and, if you choose to include it, your business website URL.
Quote requests. When you choose to send a quote request, we store the service requirements and contact details you provide, your permission to share them with the named business, and the request’s notification status. Do not include medical details, payment-card information, passwords, or verification codes.
Quote activity. We record form loads, submission outcomes, timestamps, and repeat checks for operational reporting. These analytics identify the business and request, without including your contact details or the text of your request. They distinguish our public form from an MCP tool call; they do not establish which person or AI system used it.
Crawler-detection logs. When an automated client or AI crawler requests one of our pages, we record a one-way hashed version of the requester’s IP address, the user-agent string it sends, a timestamp, and the slug (page identifier) of the business profile that was visited. These crawler-detection records contain a hashed IP address, rather than the raw IP address.
Service and security records. We record tool names, request identifiers, timestamps, response times, outcomes, and client software or agent identifiers when supplied, to operate and protect the Service. Some records use a hashed IP address; rate-limit records and application security logs may contain an IP address. Client-supplied identifiers do not verify the identity of a person or AI system.
Billing information. We do not collect payment card details directly. Stripe handles payment information for Advocate subscriptions purchased through our website. We store the associated Stripe customer identifier and plan and billing status to manage access to the Service.
Connected calendars and bookings. If you connect Google Calendar or Microsoft Outlook, we receive an account identifier, calendar names, identifiers, timezones and permissions, and calendar availability and event data needed to check for conflicts and verify bookings. We store encrypted access and refresh credentials, your selected calendar and booking settings, and booking records, including customer contact details and provider event identifiers.
3. How We Use It
We use the information we collect to operate, provide, maintain, and improve the Service; to deliver magic sign-in links and authenticate you; to receive and process access requests and communicate with you about them and about your account; to publish and maintain the business profile you ask us to create; and to understand which AI systems are indexing, crawling, or otherwise interacting with business profiles so that we can measure and report on that activity. We also use information as needed to protect the security and integrity of the Service, to investigate and prevent misuse, and to comply with our legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising.
We use connected calendar data to show available appointment times, create and verify bookings, and recover interrupted booking operations. Customers and AI assistants using our booking features receive available appointment times, not the contents of unrelated calendar events. Our use and transfer of information received from Google Calendar APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements.
4. Sharing and Subprocessors
When a customer books a connected calendar, we send the appointment time and the customer’s submitted name, email address and phone number to Google or Microsoft for the business’s selected calendar. People with access to that calendar may be able to read those details under the calendar’s sharing permissions. Advocate does not add meeting attendees when creating these events.
When you send a quote request, we share its service requirements and contact details with the business you selected so it can respond. Notifications use the business’s configured route through Resend for email or Twilio or Amazon Web Services for SMS. A provider’s acceptance of a notification does not establish that the business has read or responded to it.
Apart from sharing a request with the business you selected, we share information with the service providers (“subprocessors”) that help us operate the Service, and only to the extent they need it to provide their services to us. These providers include Neon, which provides our database hosting; Vercel, which provides application hosting and compute; Resend, which delivers our email, including magic sign-in links and access-request notifications; Stripe, which provides payment processing for website subscriptions; and Cloudflare, which provides content delivery and protection against denial-of-service attacks.
We may also disclose information when we believe in good faith that doing so is required by law or legal process, or is reasonably necessary to enforce our terms or to protect the rights, safety, or property of Advocate, our users, or others.
5. Retention
Revoking calendar access does not automatically delete stored connection and booking records or events already created in Google or Microsoft. Those provider events follow the calendar provider’s retention and sharing settings. Contact us to request deletion of data held by Advocate; removing a provider event is a separate action.
Quote requests and their delivery records are retained to support follow-up, prevent duplicate notifications, and investigate delivery problems. Quote requests, delivery records, and operational activity records do not currently expire automatically. The 30-day reporting window shown to business owners does not delete older records. You can request deletion using the contact information below.
Rate-limit records become eligible for automatic cleanup once their stored counting window is more than 25 hours old. Cleanup runs intermittently during requests and may fail or be delayed; this is not a guarantee of deletion within 25 hours. This cleanup does not delete application security logs.
We keep personal information for as long as it is needed for the purposes described in this policy. Account information is retained while your account is active. Request-access submissions are retained for a reasonable period for our business purposes, such as evaluating and following up on access requests. Crawler-detection logs, which contain a hashed IP address and request metadata, are retained as individual records and used for aggregate analytics and security reporting. We may retain information for longer where we are required to do so by law or where it is necessary to resolve disputes or enforce our agreements.
6. Your Rights
You can revoke Advocate’s calendar access through your Google or Microsoft account’s connected-app settings. Revocation prevents further access once the provider invalidates the grant and can prevent Advocate from completing pending bookings. You can also pause new bookings in Advocate’s calendar settings.
Depending on where you live, you may have rights over your personal information, such as the right to access, correct, or delete it. To make any of these requests, contact us at support@advocatemcp.com, and we will respond consistent with applicable law. We may need to verify your identity before acting on a request.
7. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this policy and, where appropriate, provide additional notice. Your continued use of the Service after an updated policy takes effect constitutes your acceptance of the changes.
8. Contact
If you have any questions about this Privacy Policy or how we handle your information, or if you would like to make a privacy request, contact us at support@advocatemcp.com.