Data.gov MCPOrganization workspace

Privacy Policy — Data.gov MCP Server (by BLEN)

Last updated: 2026-10-08

This policy describes how the BLEN-hosted Data.gov MCP Server (the Service, operated by BLEN, Inc.) handles information when accessed through its browser portal, Gemini Enterprise, or another MCP client. Self-hosted deployments are governed by their operators' policies.

The Service provides authenticated, read-only access to supported National Park Service (NPS), Federal Election Commission (OpenFEC), and Government Publishing Office (GovInfo) APIs. An organization administrator supplies the agency API key, and authorized members share that organization's connection.

Information we receive

How information is used

We use this information to sign users in, enforce organization membership and consent, return requested agency data, manage credentials, prevent abuse, diagnose failures, and respond to support and privacy requests. BLEN does not sell personal information, build advertising profiles from connector use, or train AI models on submitted code, queries, or results. The Service does not itself run a language model.

Tool arguments and public agency records can contain personal information. Submit only information appropriate for the requested public-data query. Do not send confidential records or sensitive personal information through the tools.

Cookies and authentication

The browser portal uses cookies necessary for sign-in, session continuity, and security. Browser sessions are configured with a seven-day lifetime and may be renewed through use. MCP clients receive separate OAuth tokens after explicit consent: access tokens have a 15-minute lifetime and refresh tokens have a 30-day lifetime, subject to rotation and revocation. Expiry limits authorization; it is not a promise that every corresponding database record is immediately erased.

No advertising cookies or browser analytics beacons are embedded by this application. Google's sign-in pages and your MCP client have their own cookie and privacy practices.

Information sent to other services

Google processes sign-in requests. Railway hosts the application and PostgreSQL database and processes hosting and network information. Better Auth runs within this Service; it is not a separate hosted identity service in this deployment.

The search_api and describe_schema tools search bundled documentation locally. During execute, the server sends the selected query parameters, identifiers, and filters to the supported government API, along with the organization's agency key in the X-Api-Key header. Saving a key validates it with an NPS request. The complete JavaScript body runs in a sandbox on our server and is not sent to the agency APIs.

The application does not intentionally forward your Google credentials, MCP bearer token, inbound IP address, or user identity to agency APIs. Outbound requests use the hosting network address. Information you put in query parameters is sent to the selected agency. Results are returned to your MCP client, whose storage and AI processing are governed by its own policies. Hosting, Google, and upstream providers also process information under their applicable policies.

We may disclose information where required by law or necessary to address abuse, security incidents, or threats to the Service.

Storage and retention

Account, membership, consent, and audit records have no application-wide scheduled deletion period. Contact BLEN for access or deletion requests. We may retain information needed for security, legal obligations, or resolving disputes, and will explain applicable limits when handling a request.

Your controls

Disconnect the connector in your MCP client to stop future calls and use its controls for client-side history. Disconnecting or signing out does not by itself delete server-side records or every OAuth grant. Ask your organization administrator or BLEN to remove membership and revoke access where needed. Owners and admins can remove the organization's stored agency key; this prevents subsequent agency requests using that stored key but does not revoke the key at its issuing agency.

For questions, access requests, or deletion requests concerning BLEN-held information, contact opensource@blencorp.com. Provide your organization and enough context to identify the relevant account or interaction, but do not send credentials. Self-hosted users should contact their deployment operator.

Security

The hosted Service uses HTTPS, membership checks, explicit OAuth consent, PKCE, encrypted agency credentials, request limits, and fixed upstream destinations. JavaScript runs in a fresh sandbox process without direct network, filesystem, environment, or subprocess access. Limits and isolation reduce risk; they do not guarantee protection against every incident. Report vulnerabilities privately to opensource@blencorp.com.

Changes and contact

Updates will be published on this page with a revised date. Privacy questions and requests: opensource@blencorp.com. See also the Terms of Service and BLEN contact page.