Legal

Privacy Policy

Effective date: June 30, 2026

PreMan (“PreMan,” “we,” “us,” or “our”) is operated by Preman Inc. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website at preman.live, the hosted workspace at app.preman.live, our APIs, MCP tools, SDK, and related services (collectively, the “Services”). Use of the Services is also governed by our Terms of Service.

Information we collect

Account information. When you create an account, we collect your email address, password (stored in hashed form), and verification codes sent for signup, login, or password reset. We may also store your name or organization details if you provide them in settings or support requests.

Workspace and product data. When you use PreMan, we process data you submit to operate the product, including API endpoint definitions, OpenAPI and collection imports, MCP tool metadata, hosted MCP configuration, managed MCP server configs, verification contracts, agent session data, and audit or invocation records. This may include technical identifiers (URLs, HTTP methods, response status codes, latency) and limited request or response metadata needed for testing, conversion, runtime forwarding, and post-action verification. We do not intentionally collect end-user content from your upstream APIs beyond what is required to perform the action you requested.

Credentials and secrets. If you store upstream API credentials, OAuth tokens, or other secrets in PreMan's credentials vault, we encrypt them at rest and use them only to authenticate outbound calls you authorize. We do not return decrypted secret values in API responses, display them in the dashboard after entry, or log them.

API keys and tokens. We issue workspace API keys (for example, keys beginning with pm_live_) and scoped consumer tokens for hosted MCPs (for example, keys beginning with pm_hmcp_). We store only hashed or otherwise non-reversible representations of these keys and tokens, plus safe prefixes for lookup and revocation.

Billing information. If you subscribe to a paid plan, payment processing is handled by Stripe. We receive billing-related identifiers (such as customer ID, subscription status, and invoice metadata) from Stripe. We do not store full payment card numbers on our servers.

Usage, logs, and diagnostics. We collect standard server and application logs, including IP address, browser or client user agent, timestamps, API routes accessed, error messages, and performance metrics. Hosted MCP and managed MCP invocations generate audit logs (tool name, caller identity, status, timing) so you can review agent activity.

Communications. If you contact us, book a demo, or subscribe to product updates, we process the information you provide (such as email address and message content).

Cookies and similar technologies. Our web apps use cookies and local storage primarily for authentication sessions, preferences, and security. We do not use third-party advertising cookies on the core product surfaces described in this policy.

How we use information

We use personal information to:

  • Provide, maintain, and improve the Services, including API-to-MCP conversion and the hosted MCP runtime.
  • Authenticate users, API keys, and consumer tokens; enforce access controls and tool policy.
  • Forward authorized tool calls to your configured upstream APIs or managed MCP servers.
  • Run post-action verification checks and store verdicts and evidence when you enable those features.
  • Process subscriptions, meter usage, and send transactional emails (for example, OTP codes and billing notices).
  • Monitor reliability, prevent abuse, and investigate security incidents.
  • Respond to support requests and communicate about product changes.
  • Comply with legal obligations and enforce our agreements.

How we share information

We do not sell your personal information. We share information only in these circumstances:

  • Service providers that help us operate the Services under contractual confidentiality and security obligations, including cloud infrastructure (for example, Amazon Web Services), payment processing (Stripe), and transactional email delivery (for example, Resend).
  • Your upstream systems when you configure PreMan to call your APIs or third-party MCP servers on your behalf. You control what endpoints, credentials, and tools are enabled.
  • Integrations you enable, such as GitHub or Slack, according to the permissions you grant.
  • Legal and safety when required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).

Data retention

We retain account and workspace data for as long as your account is active or as needed to provide the Services. Audit and invocation logs are retained for a period that supports security review, billing disputes, and product functionality; you may be able to export or delete certain records from the workspace depending on your plan and settings.

When you delete your account or ask us to delete data, we delete or anonymize personal information within a reasonable period, except where we must retain limited records for legal compliance, fraud prevention, or backup integrity.

Security

We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS), encryption at rest for sensitive fields such as vault secrets, access controls, and audit logging. No method of transmission or storage is completely secure; please use strong passwords and protect your API keys and consumer tokens.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; and withdraw consent where processing is based on consent. You can update account details in workspace settings and revoke API keys or consumer tokens at any time.

To exercise privacy rights, contact us at alspencer@preman.live. We may need to verify your identity before fulfilling a request. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.

International transfers

PreMan is based in the United States. If you access the Services from other regions, your information may be processed in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers.

Children

The Services are not directed to children under 16, and we do not knowingly collect personal information from children. Contact us if you believe a child has provided personal information and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may be communicated by email or in-product notice where required by law.

Contact us

Questions about this Privacy Policy or our data practices:

Preman Inc. (PreMan)
Email: alspencer@preman.live

Legal terms: Terms of Service

Product documentation: Docs