How Kuickr handles your data — including when you connect it to ChatGPT, Codex, or another AI client over MCP.
Last updated: 31 July 2026
Kuickr is a hosting service that gives AI-authored and human-authored pages a permanent home at clean URLs. This policy covers kuickr.co and the Kuickr MCP server at https://kuickr.co/mcp.
When someone opens a tracked link, Kuickr derives a country code locally and then discards the source address. We store no raw IP, no full user agent, and no full referrer. A coarse device/browser family and referrer hostname may be retained.
Daily uniques use a link-scoped daily HMAC made from the link, connection address, and coarse browser family. The HMAC changes across links and days, so it is not a permanent visitor identifier. Sanitized raw click events have 90-day retention. Daily aggregates are permanent while the tracked link exists and contain counts rather than individual browsing histories.
Anyone can report a tracked link as spam, malware, phishing, or another safety concern. We rate-limit reports with an HMAC-derived connection key; no raw reporter IP is stored. Operators review reports and may resolve them or revoke the link. Revocation archives the link and its public slug stays unavailable for reuse.
mcp read/write or mcp_read read-only).When you connect Kuickr to an AI client, that client acts on your behalf through per-user OAuth. Access is limited to the scope you approve and to the pages and folders your account can reach. Public actions — publishing a Space, sharing a folder by link — happen only through explicit tools, and destructive actions (like deleting a folder) require explicit confirmation. We validate every request server-side, regardless of what a model supplies.
Pages are private by default. You control visibility: keep them private, share them as unlisted links, or publish them to public Spaces. Anything you publish or share by link may be viewed by anyone with the URL, and public pages may be indexed by search engines. Visibility is governed by Kuickr's access policy, not by model text.
We share data only with infrastructure providers needed to run the service (hosting, email delivery), and with AI clients you explicitly connect. We may disclose data if required by law.
We keep your content while your account is active. You can delete pages, folders, and Spaces at any time; deletion is irreversible. Deleting a Space removes its tracked links, reports, raw events, and aggregate rows. Archiving or operator-revoking one link leaves its slug burned and its safety record available to operators. You can revoke a connected client's access at any time, which invalidates its tokens. To delete your account and associated data, contact us at the address below.
You can access, export, correct, or delete your content from within Kuickr, revoke connected clients, and request account deletion. For requests you can't complete yourself, email us.
We use OAuth 2.1 with PKCE, per-user token scoping, and server-side authorization checks. Untrusted hosted HTML is served from a cookie-free, sandboxed origin. No system is perfectly secure, but we work to protect your data.
We may update this policy; we'll change the "last updated" date above and, for material changes, take reasonable steps to notify you.
Questions about privacy? Email [email protected].