# Privacy Policy | Sealgate

Sealgate privacy policy.

Source: https://sealgate.ai/privacy-policy

---

[Back to home](https://sealgate.ai/)

# Privacy Policy

Last updated: 22 July 2026

## Introduction

Sealgate ("Sealgate", "we", "our", or "us"), the common trading name of GPU-EVM LTD, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Sealgate MCP Secure Layer .

Sealgate is a security layer for AI agents. When you connect a Model Context Protocol (MCP) server to Sealgate, Sealgate exposes that server's tools to your AI agent through our secure layer, while enforcing security policies, assigning risk scores to agent actions, and producing audit records. This policy describes what that means for your data.

## Deployment models

Sealgate offers the MCP Secure Layer in two deployment models, and you choose which one you connect to :

### Self-Hosted / VPC (On-Premise)

Sealgate runs entirely within your own infrastructure. Your data, including all tool-call traffic, metadata, and all logs (audit logs and session logs), stays within your environment. We have zero access to it: no phone-home, no telemetry, no data collection whatsoever. The sections below describing data we collect and subprocessors we use do not apply to Self-Hosted deployments.

Hosted SaaS (Sealgate Cloud). Sealgate operates the secure layer on your behalf in our cloud environment. The data practices described below apply.

Unless stated otherwise, the remaining sections describe the Hosted SaaS deployment only.

## What passes through the secure layer, and what we keep

This is the most important part of this policy, so we state it plainly.

When your agent invokes a tool on a connected MCP server, the request and the response pass through the Sealgate secure layer in real time so that we can evaluate them against your security policies. This is the pass-through traffic: the actual content of tool calls (for example, the body of a file read, the text of a message, or the arguments and results of a tool).

We do not persist tool-call content. The content of the requests and responses that flow through the secure layer is processed transiently in memory to enforce policy and is not written to durable storage. When we detect a potentially dangerous action, this transient tool-call content may be analysed by AI to generate a summary explaining why the action is dangerous (see Security Analysis and AI below). Only that summary is retained as part of the audit record; the underlying tool-call content is not.

What we do retain is metadata and audit logs , such as:

- Which tool was called, on which connected MCP server, and when
- The identity of the user and agent that made the call
- The policy decision (allow, deny, or ask-for-approval) and the risk score assigned
- Session information (session identifiers, call counts, timing)
- Error and diagnostic events We retain this metadata so that we can provide audit trails, security analytics, and the runtime enforcement that is the core purpose of the service. We do not reconstruct tool-call content from metadata, and metadata is designed to describe that an action happened and how it was judged , not to store the underlying payload.

## Information We Collect (Hosted SaaS)

### Account Information

When you register, we collect your name, email address, and authentication credentials.

### Connection Configuration

To operate the secure layer we store the configuration of the MCP servers you connect, such as server names, endpoints, the tools they expose, and the security policies you define. To display connected servers we may perform a logo lookup based on the server's domain.

### Metadata and Audit Logs

As described above, we collect tool-call metadata, policy decisions, risk scores, and audit logs and session logs. We do not retain tool-call content.

### Usage Data

Information about how you interact with our platform, including access times, features used, and pages viewed.

### Technical Data

IP addresses, browser type, device information, and similar technical data, used to operate and secure the service.

## How We Use Information

- To provide, maintain, and operate the secure layer and enforce your security policies
- To generate audit trails, risk scores, and security analytics
- To communicate with you about updates, security alerts, and support
- To detect, prevent, and address technical issues and security threats
- To improve the service
- To comply with legal obligations

## Security Analysis and AI

Part of Sealgate's function is to assess the risk that a connected tool poses. Where this assessment uses third-party large language model providers (currently OpenAI and Google Gemini, see our [Subprocessors](https://sealgate.ai/subprocessors) page), the AI evaluates the behaviour of a tool and its potential side effects, based on the tool's own description. In routine operation this assessment relies on the tool's description, not on your data.

There is one exception. When Sealgate detects a potentially dangerous action, the transient tool-call content involved may be sent to these providers so the AI can generate a summary explaining why the action is dangerous. This happens only for actions flagged as dangerous, the content is processed transiently to produce that summary, and only the resulting summary is retained as part of the audit record. Outside of these cases, tool-call content and your usage are not sent to these providers.

We do not train AI models on your data. Data that passes through Sealgate is never stored or used for model training, fine-tuning, or any other machine-learning purpose, by us or by our subprocessors. We exist to protect your data, not to monetize it.

## Data Sharing

We do not sell your personal information. We may share data with:

- Service providers (subprocessors): Third-party vendors who help us operate the service, listed on our [Subprocessors](https://sealgate.ai/subprocessors) page. We maintain data-processing agreements with each and provide 30 days' notice before adding or replacing one.
- Connected services you choose: When you connect an MCP server and instruct your agent to use it, tool-call traffic necessarily flows between your agent and that server through the secure layer. Those connected servers and their operators are controlled by you, not by Sealgate, and their handling of data is governed by their own terms and policies.
- Legal requirements: When required by law or to protect our rights.
- Business transfers: In connection with a merger, acquisition, or sale of assets.

## Data Retention

We retain account information and connection configuration for as long as your account is active.

We distinguish two kinds of logs, with different default retention periods:

- Debug logs (operational and diagnostic records used to troubleshoot the service) are kept for up to 30 days by default.
- Security and audit logs (including audit logs and session logs, and the metadata that supports audit and security functions) are kept for up to 4 months by default. These are default maximums that apply while your account is active, and you can configure a shorter retention period for either category to suit your own requirements. When your account is closed these ceilings no longer apply: we delete your account information, connection configuration, and all associated logs within 7 days, regardless of how much of their retention period remains. Tool-call content is not retained at any point (see above).

The only exception is data we must preserve in connection with a legal claim or an ongoing security investigation, or that we are required to keep by law. We limit any such retention to what is strictly necessary for that purpose.

## Regulatory Compliance

We are committed to complying with applicable data protection laws, including the UK GDPR, the EU GDPR, and the California Consumer Privacy Act as amended by the CPRA. Our practices are built around the principles those laws set out: collecting only what we need, using it only for the purposes described in this policy, and keeping it only for as long as those purposes require.

We review this policy and the practices behind it periodically, and whenever we make a material change to how the service handles data, so that both stay aligned with our obligations as they evolve. We work with our customers to support their own compliance programs, including by entering into data processing agreements and by helping them respond to requests from individuals whose data we process on their behalf. We cooperate with supervisory authorities where required.

## Your Rights

Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing. If you are in the United Kingdom or the European Economic Area, these rights arise under the UK GDPR and the EU GDPR, and you also have the right to lodge a complaint with your local supervisory authority.

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law.

To exercise any of these rights, contact us using the details below. Where we process personal data on behalf of a customer, we will refer your request to that customer and support them in responding.

## Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and regular security assessments.

## International Transfers

Your data may be transferred to and processed in countries outside your jurisdiction. Where it is, we rely on appropriate safeguards, including Standard Contractual Clauses and the UK International Data Transfer Agreement.

## Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and revising the "Last updated" date.

## Contact Us

Sealgate (GPU-EVM LTD)
3rd Floor, 86–90 Paul Street
London EC2A 4NE
United Kingdom

Email: [privacy@sealgate.ai](mailto:privacy@sealgate.ai)
