60fps MCP Privacy Policy
Last updated: 29 July 2026
This policy covers the 60fps MCP server at mcp.60fps.design, which lets AI tools search the 60fps library. It does not cover general browsing of 60fps.design.
60fps is operated as a sole proprietorship from Bengaluru, India, and is the data controller for the information described here. Contact: admin@60fps.design.
We do not sell data, we do not run advertising, and we do not build profiles for anyone else.
The short version
To run a paid service we need to check that your license key is valid, stop one key being shared across a crowd, and see which searches come back empty so the library can be improved. That is the whole reason any data is kept.
We store your email address, your license key, hashed IP addresses, and the searches your AI tool sends us. We do not store your conversations with that AI tool, and we do not train any machine learning model on your data.
What we collect
Your license key. The MCP is for PRO subscribers, so every request carries a key. We store it so we can check it without asking Gumroad each time. Your key works on both the website and the MCP.
Your email address and subscription status. These come from Gumroad when we verify your key, along with a purchase ID, product ID, and your subscription dates. We keep them to tell whether your subscription is active, and to see which subscribers actually use the MCP. Payment is handled by Gumroad and we never see your card details.
IP addresses. Your IP is used for a moment to apply rate limits, then discarded. For longer term counts we keep only a short one-way hash of it, never the address. IP addresses also appear in our hosting provider's request logs, and in a short line we write when a request fails to authenticate.
Device fingerprints. A PRO license works on two devices. To count them we derive a one-way hash from characteristics of your connection and a secret we hold. It tells one device apart from another without identifying you, and it cannot be reversed. Connections made through an app connector are not counted this way.
Searches sent to the MCP. When your AI tool searches the library, the search text is stored. This is the signal that shows which searches return nothing, which is how gaps get found and filled. We keep your most recent 50 searches, and the most recent 1,000 across everyone.
Usage counts. Which tools were called, how often, and whether a search found anything. These are attached to a hash of your license key, not to your name or email.
OAuth connections. If you connect through an app such as Claude or ChatGPT, we store what that app sends us when it registers, and we store access and refresh tokens only as one-way hashes. We never keep a usable copy of a token.
What we do not collect, and what we do not do
We do not store your conversations with Claude, ChatGPT, Cursor or any other AI tool. The MCP receives one search or one shot identifier at a time and nothing else from the conversation.
We do not train, fine tune, test or evaluate any machine learning model on your searches, your usage, or anything else you send us.
We do not receive card details. Gumroad handles payment.
We do not read files, code, or anything else from your computer.
We do not touch your AI tool's memory, chat history, or saved files.
mcp.60fps.design sets no cookies and does no tracking. There is nothing to opt out of.
Why we are allowed to hold it
Where data protection law such as the UK or EU GDPR applies, our lawful bases are:
Performance of a contract, for the licence check, the device cap, and delivering the service you have paid for.
Legitimate interests, for rate limiting, spotting abuse, and the usage counts and stored searches that tell us which parts of the library are missing. We keep this to the minimum that answers the question, which is why IP addresses are hashed and licence keys are reduced to a hash before being attached to usage.
Legal obligation, where we are required to keep or produce records.
How long we keep it
License checks are kept for 30 days and refreshed whenever you use the MCP. A rejected key is remembered for 60 seconds so a broken setup does not hammer Gumroad.
Rate limiting counters live for 60 seconds.
Device fingerprints stay until the device has been idle long enough for its slot to be reclaimed, which takes 15 minutes.
OAuth access tokens expire after 1 hour. Refresh tokens last 30 days, and the registration an app creates lasts 90 days. Removing the connector in your tool deletes all of them at once.
Searches, hashed IP addresses and day by day usage are kept for 90 days, then deleted.
Running totals per license, such as how many searches you have made, are kept while your subscription is active.
Hosting request logs are held by Vercel under their own retention policy, not ours.
Who else handles your data
We use a few providers, only for the purposes below, and we share your data with nobody else.
Gumroad issues license keys and processes payment. When we check a key, we send that key to Gumroad.
Upstash hosts the database described above.
Vercel hosts the MCP server. Their request logs record the IP address, user agent and path of each request. The lines we write ourselves record an IP address and a shortened user agent, and never a license key.
Where your data is processed
60fps is operated from India. Requests to the MCP are received at an edge location near you and processed on servers in the United States, and the database and hosting providers above operate their own infrastructure across several countries.
If you are in the UK, EU or another region whose law restricts international transfers, this means your data leaves that region. We rely on the transfer safeguards our providers put in place, and we keep what crosses borders to the minimum described in this policy.
The AI tool you connect
When you connect the MCP, your tool sends us a search and receives interaction references back. What your tool then does with that response is governed by its own privacy policy, not ours. Anthropic, OpenAI and others each publish their own.
Connecting with OAuth means your key is entered on our page and is never written into a configuration file on your computer. Connecting with a header means your key sits in that tool's config file, where you control it.
Your choices
Disconnect at any time. Remove the connector in your AI tool and its access ends immediately. If you set it up with a header, delete the entry from your config.
Cancel at any time. Cancel in Gumroad. Access continues to the end of the period you have paid for, then stops.
Ask for your data, or ask us to delete it. Email admin@60fps.design from the address you subscribed with and we will reply within 30 days. Deleting your data ends MCP access, because the license check is the reason the data exists.
If you are in the UK, EU, or another region with similar law, you have rights of access, correction, deletion, restriction, objection and portability, and you may complain to your local data protection authority.
Security
Everything is served over HTTPS. Tokens are stored as one-way hashes, and IP addresses used for analytics are hashed before storage. Access to the production database is limited to the people who operate 60fps.
No system is perfect. If you find a security problem, email admin@60fps.design and we will respond quickly. If a breach affects your personal data and the law requires us to tell you, we will, and we will notify the relevant authority within the time the law allows.
Children
60fps is a professional design tool and is not directed at children under 13. We do not knowingly collect their data.
If 60fps changes hands
If 60fps is ever sold or transferred, the data described here would move with it, and whoever takes it on would be bound by this policy until they tell you otherwise.
Changes
If this policy changes in a way that matters, we will say so here and update the date at the top.
Contact
admin@60fps.design