Privacy Policy
Last updated: July 4, 2026
This policy covers ToolHost's own surfaces: this website (toolhost.online), the documentation site (docs.toolhost.online), the developer portal used to sign up and provision API keys (app.toolhost.online), and the hosted gateway console. It is written plainly because ToolHost is an early-stage product — we'd rather be clear about what we actually do than paper over gaps with boilerplate.
What ToolHost is
The ToolHost gateway is a self-hosted piece of infrastructure. When you run a gateway, it sits between your AI agents (Claude, or any other MCP-speaking client) and the MCP backend servers you configure it to talk to. The gateway operator — you — controls the backends it connects to and the data those backends handle. ToolHost does not see or store the content of tool calls made through a self-hosted gateway deployment unless you explicitly configure it to send telemetry or audit data to a ToolHost-operated service.
What we collect
- Account data. If you sign up through the developer portal (app.toolhost.online), we collect the email address and authentication details needed to create your account and issue API keys.
- Gateway configuration and audit logs you choose to store with us. If you use ToolHost's hosted console or hosted audit-log storage, the policy, backend configuration, and call-level audit records (principal, tool name, timestamp, allow/deny decision) you generate live in that instance. Tool call arguments and responses are redacted by default unless you explicitly enable capture mode for debugging.
- Basic site analytics. Standard web server logs (IP address, user agent, page requested) for toolhost.online and docs.toolhost.online, used only for operating and securing the sites.
What we don't do
We do not sell personal data. We do not share account data or audit logs with third parties except where necessary to operate the service (e.g., our infrastructure providers) or where required by law.
Data retention and deletion
You can request deletion of your developer-portal account and associated API keys at any time. For self-hosted gateway deployments, data retention is entirely under your control — ToolHost has no access to delete or retain data it never received.
No certifications, yet
ToolHost is an early-stage product. We do not currently hold SOC 2, ISO 27001, or other formal compliance certifications, and we won't claim them until they're actually in place. If your organization requires specific compliance guarantees before adopting ToolHost, please reach out and we'll tell you plainly where things stand.
Changes to this policy
As the product evolves, this policy will too. We'll update the "last updated" date above when we make material changes.
Contact
Questions about this policy or a data request: privacy@toolhost.online