Privacy Policy
Last updated: June 18, 2026
1. Scope
This policy describes how medprice.ai handles information collected through the medprice.ai website and the hosted MCP (Model Context Protocol) server at mcp.medprice.ai (together, the “Service”).
2. Information collected on the website
If you submit the “Get early access” or “Request a hospital dataset” forms, we collect the information you enter — your email address, and, for hospital requests, the hospital name and optionally your role and reason for the request. This information is sent via email to our team to follow up with you and is not written to an application database.
The website also uses Google Analytics to understand site traffic (e.g., pages visited, browser and device information). This data is collected and processed by Google under its own privacy practices.
3. What the MCP server logs
Each call to the get_hospital_procedure_cost tool writes a structured log entry containing the procedure code and code type you queried, along with request duration and, on error, error details. These logs are used only for debugging and reliability monitoring.
4. Whether prompts are stored
No. The MCP server only receives the structured tool-call parameters your AI assistant sends (e.g., a procedure code and code type) — it does not have access to, and does not log or store, your conversation or prompts with that assistant. We do not maintain a history of past queries tied to any person or client.
5. Whether IP addresses are retained
Our application code does not record or store IP addresses. The Service is hosted on Google Cloud Run, which automatically captures connection metadata — including IP address — as part of its standard infrastructure-level request logging. This logging is generated by the hosting platform, not by our application code, and is subject to the log retention described below.
6. How long logs are kept
We have not configured a custom log export or retention period, so application and infrastructure logs are kept according to Google Cloud Logging’s default retention window, currently 30 days, after which they are automatically deleted.
7. How we use information
Email addresses submitted through our forms are used only to respond to your request — for example, to follow up on early access or a hospital dataset request. We do not sell your information or share it with third parties for marketing purposes.
8. Third parties we use
- Resend — delivers the emails generated by our website forms.
- Google Analytics — website traffic analytics.
- Google Cloud Platform — hosting and infrastructure logging for the website, MCP server, and backend.
9. Changes to this policy
We may update this policy from time to time. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
10. Contact
Questions about this policy can be sent to [email protected].