Privacy Policy

This policy explains what personal data P.J Technology LLC (“we”, “us”) collects when you use pascalyin.com, the account console at account.pascalyin.com, the MCP servers at mcp.pascalyin.com, and the email newsletter at news.pascalyin.com; why we collect it; how long we keep it; and your rights.

We collect as little as we can. We do not sell or rent personal data, we do not use it for advertising, and there are no third-party analytics or tracking scripts on any of these sites.

1. Reading the website (pascalyin.com)

  • No account, no cookies. Reading the site needs no sign-in and sets no cookies. Your choice of light/dark theme is stored only in your own browser (localStorage).
  • Server logs. Like any web server, ours records each request: IP address, time, page requested, browser user agent and referrer. We use these logs to keep the site running and to count daily visits (we keep only daily totals). Raw logs are deleted after 14 days.

2. Email newsletter (news.pascalyin.com)

  • What we keep: your email address, the name if you give one, which list you joined, and when you subscribed and confirmed.
  • Double opt-in: nothing is sent until you click the confirmation link we email you.
  • Unsubscribe any time with the link at the bottom of every email; your address is then removed from the list.
  • Opens and clicks are counted only in total, never per person. We do not record your IP address when you subscribe.
  • Manage or delete your subscription data yourself from the link in any newsletter.
  • The newsletter software (Listmonk) runs on our own server; emails are delivered by Postmark (see §6).

3. Your account (account.pascalyin.com)

You need an account only to use the MCP servers.

  • Sign-in with an email code: we store your email address. The 6-digit code is stored only as a one-way hash, expires after 10 minutes and works once.
  • Sign-in with Google: Google shares your email address, name and profile picture with us, and a Google account ID. We never see your Google password.
  • Cookies: one session cookie keeps you signed in; during Google sign-in a short-lived cookie protects the redirect. Both are strictly necessary; there are no other cookies.
  • API keys you create are stored only as a one-way hash; we show the full key once, when created.
  • Connected apps: when you let an AI client (for example ChatGPT, Claude or Cursor) use your account, we record which client you authorised and when.

4. Using the MCP servers

  • Inputs and results are not stored. What you send to a tool and what it returns are processed in memory and never written to disk or a database. To prevent a double charge when a client retries, a one-way fingerprint of the request is kept for up to 60 seconds.
  • Usage records. For each call we record: which tool, when, whether it succeeded, how long it took, and the credits charged. You can see these on your Usage page. They are needed for billing, limits and abuse prevention.
  • IP addresses are used in memory to rate-limit sign-in and requests (for example, a few code requests per minute) and appear in server logs (§1).

5. Payments, trial and refunds

Payments are handled by Stripe. We never see or store your card number. We keep your Stripe customer ID, what you bought, amounts, dates and refunds, because tax and accounting law requires it.

  • Free trial card: if you save a card for the trial credits, the card is saved at Stripe. We keep only Stripe’s card fingerprint (an identifier Stripe derives from the card, not the number) so each card gets one trial.
  • Before you pay you confirm the terms of immediate access and the 14-day withdrawal right; we keep a record of that confirmation (which purchase, when, which policy version).
  • Withdrawals and refunds: we keep what was refunded, when, and the credits taken back.
  • Plan status: whether you have a monthly plan, when its paid period ends, and whether it is set to end.

6. Service providers

We use a small number of providers, each only for the purpose listed:

ProviderPurposeLocation
DigitalOceanHosting our servers (website, account, MCP, newsletter)United States
Postmark (ActiveCampaign)Delivering sign-in, receipt and newsletter emailsUnited States
Google“Continue with Google” sign-in, only if you choose itUnited States
CloudflareDNS (turning our domain names into server addresses)Global
StripePayments, saved cards for the trialUnited States

Postmark keeps copies of sent emails for up to 45 days for delivery troubleshooting.

7. How long we keep data

DataKept for
Account (email, name, sign-in methods, API keys, connected apps)Until you delete your account
Usage recordsAs long as the law requires, then deleted or aggregated
Payment and credit recordsAs long as tax and accounting law requires
Newsletter subscriptionUntil you unsubscribe
Server logs14 days
Encrypted backups14 days

8. Your rights

You can ask us to show you, correct, export or delete your personal data, and to stop sending you email. Deleting your account removes your email, name, sign-in methods, API keys and connected apps; payment records that law requires us to keep are kept but no longer used.

If you are in the EU/EEA or UK, you also have the right to object and to complain to your data protection authority. We rely on: performing our contract with you (account, MCP service, payments), your consent (newsletter), our legitimate interest in keeping the service secure (logs, rate limits), and legal obligations (tax records).

If you are in California: we do not sell or share personal information, and we do not use sensitive personal information to infer anything about you.

To exercise any of these rights, email yinpj001@gmail.com. We reply within 30 days.

9. International transfers

Our servers and most providers are in the United States. If you use the service from elsewhere, your data is transferred there.

10. Children

The service is not meant for children under 16, and we do not knowingly collect their data.

11. Security

Connections use HTTPS. Sign-in codes and API keys are stored only as hashes; backups are encrypted; access to servers is restricted to the owner.

12. Changes

If we change this policy, we update the date at the top; for significant changes we email account holders before they take effect.

13. Contact

P.J Technology LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA, yinpj001@gmail.com