Privacy Policy

Effective date: July 15, 2026 · Version 1.4

1. Who we are

Get An Expert ("we", "us") provides the get-an-expert-mcp software and the api at this domain. We act as the data controller for the data described below. Contact: .

2. What this policy covers

The get-an-expert-mcp MCP server you install in your coding tool, the Get An Expert API it talks to, and this website.

3. What we collect

We collect four things, and only these:

  • The session summary you explicitly sendwhen you ask for expert help: your stated goal, what was tried, error messages, a short summary of the stuck session, your tech stack, and your OS account name, so the expert knows who they're helping — the same identity our on-machine agent already shows a live expert. Set the GET_AN_EXPERT_CUSTOMER_NAME environment variable, or just ask your agent to use a different name, to override it. Secret redaction runs on your machine before this is transmitted, and again on our servers when it arrives.
  • Live chat messages and relayed session activity once you escalate to an expert — described in full in section 5. Both flows start only after your explicit consent and stop the instant the chat ends.
  • A random install ID (a UUID generated on your machine) used for rate limiting and to let you delete your data. It is not linked to your name, email, or any account.
  • Minimal request metadata (IP-derived rate-limit counters and standard server logs) for security and abuse prevention. Payload bodies are not written to logs.

What we never collect: your source files or repository contents; your full conversation transcript; environment variables, API keys, or other secrets; anything in the background or without your explicit per-request consent. The software sends zero bytes to us until you say yes to a specific request.

4. How and when collection happens

Only when you explicitly agree to send a specific request. There is no passive or background collection of any kind.

5. Live expert chat & session relay

When you escalate to a human expert, you consent once, up front, to two additional flows — both start only after your explicit "proceed" and both stop the instant the chat ends:

  • Chat messages you and the expert exchange in the chat terminal. The chat is human-to-human: no AI model ever reads it. The only automation touching it is secret redaction, which runs on your machine before sending and again on our servers — in both directions, expert messages included.
  • Relayed session activity: the prompts you type to your coding agent, the agent's replies, the commands it runs with their output, and the file edits it makes, so the expert can watch real attempts. This relay is active only while the chat is open, a 🟢 LIVE indicator shows in your session, and you can pause it (/pause) or end everything (/end) at any moment. Either side ending the chat is a hard stop: our servers refuse any further relayed event.

Chat messages and relayed events are stored with the request they belong to: they share its 30-day auto-deletion and are removed by its private deletion link.

6. Why we use it, and our legal basis

  • Sharing your session summary with a human expert who reviews it and writes your response — consent (GDPR Art. 6(1)(a)), given per request.
  • Service security, rate limiting, and abuse prevention — legitimate interest (GDPR Art. 6(1)(f)) in keeping the service available and safe.

Providing your data is never required — if you decline, the tool simply doesn't send anything and your session continues unaffected. You can withdraw consent for stored data at any time by deleting it (section 9).

7. Human review

Your session summary is reviewed by a human expert at Get An Expert, who writes the response you receive. We do not use your data to generate automated responses, we never permit it to be used for model training, and no decision with legal or similarly significant effect is made about you (GDPR Art. 22 does not apply). The live expert chat and relayed session events are never processed by any AI model.

8. Who we share data with

We use two subprocessors, strictly to run the service: Vercel (hosting) and Upstash (storage). Your summary is visible to the vetted expert who answers it. We do not sell your data, do not share it for advertising, and do not allow anyone to train models on it. Because we do not sell or share personal information as defined by the CCPA/CPRA, no "Do Not Sell or Share" mechanism is needed.

9. International transfers

Data is processed in the United States. For transfers from the EU/UK, we rely on our subprocessors' safeguards — Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework — under each provider's data processing agreement.

10. Retention and deletion

  • Session summaries, thread messages, and expert responses auto-delete 30 days after the request was submitted.
  • Every request comes with a private deletion link — use it to delete the request and its entire thread immediately, no account or email needed.
  • Rate-limit counters expire within 24 hours.
  • The install ID lives on your machine; uninstalling the software removes it.

11. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, the right to withdraw consent at any time, and the right to lodge a complaint with your supervisory authority. Under the CCPA/CPRA you have the right to know, delete, and correct, and the right not to be discriminated against for exercising your rights. To exercise any of these, use your deletion link or email . We respond within 30 days (GDPR) / 45 days (CCPA).

12. Security

TLS for all data in transit, encryption at rest with our storage provider, client-side secret redaction before transmission plus a second server-side redaction pass (for summaries and every thread message), deletion and thread tokens stored only as hashes, and access limited to what operating the service requires.

13. Children

The service is for developers and is not directed at children under 16. We do not knowingly collect data from children.

14. Changes

We'll post any changes here with a new effective date and version number. Material changes will also be noted in the software's release notes before they take effect.

← Back to home