Legal

Privacy Policy

How VI MCP handles data when it connects Autodesk Revit to ChatGPT, Claude, or another Model Context Protocol client.

Effective:
October 8, 2026
Publisher:
Andrii Hutsaliuk (VI MCP)

This policy applies to the VI MCP website, Autodesk Revit add-in, cloud gateway, billing service, and MCP server. Andrii Hutsaliuk (VI MCP) is the publisher and controller of the personal data described here. Autodesk, OpenAI, Anthropic, and other services you choose have their own privacy practices.

Privacy at a glance

Website

No advertising trackers are used. We use Microsoft Clarity analytics, which sets cookies, to understand how visitors use the site.

Revit model

Your complete model file stays on your computer. Only data needed for a tool call is transmitted.

AI choice

VI MCP does not include an AI model. You decide whether to connect ChatGPT, Claude, or another MCP client.

Data we process

Website data

Standard server records may include IP address, browser and device type, requested URL, timestamp, and security events. We do not use these records for advertising or cross-site profiling. We use Microsoft Clarity to record aggregated usage, heatmaps and session replays (clicks, scrolls and mouse movement, with text you type masked). Clarity sets first-party cookies (_clck, _clsk) and processes this data under the Microsoft Privacy Statement. You can opt out by blocking cookies for this site.

Installation data

A one-way device fingerprint, generated locally from Windows and hardware identifiers; machine name; device ID; Revit version; add-in version; connection status; token identifiers; token usage time; and IP address. The underlying hardware identifiers and Windows SID are combined and hashed locally rather than sent separately.

Revit tool data

Tool names, arguments, results, and diagnostic metadata necessary to perform a request. Depending on the tool you ask the AI client to use, results can contain element IDs, names, parameters, geometry, images, project information, paths, or Revit user and worksharing information. The complete RVT file is not uploaded automatically. When the AI client searches the tool catalogue, we also process the short task descriptions it searches for, such as "tag untagged doors in active view", to rank matching tools.

Billing data

Subscription dates and status, plan, price, currency, payment status, and the payment provider's invoice ID. Card or bank credentials are entered on the payment provider's page and are not received or stored by VI MCP.

Marketplace & support

If Autodesk provides purchaser or download information, it may include your name and email address. If you contact us, we process your contact details, message, and any files or diagnostics you choose to provide. Please do not send model files or access tokens unless specifically requested through a secure channel.

ChatGPT, Claude, and other MCP clients

You connect VI MCP to an AI client yourself. The client decides when to call a tool, sends the tool request to our MCP endpoint, and receives the requested result. Because the AI client needs that result to answer you, prompts, tool arguments, and tool results may become part of the conversation stored by your chosen provider.

  1. 01 · YOU

    Choose a client and request an action.

  2. 02 · VI MCP

    Relays the scoped tool call to your live Revit session.

  3. 03 · AI CLIENT

    Receives the tool result and uses it in your conversation.

Important: VI MCP does not independently send your data to OpenAI or Anthropic and does not control how your chosen AI service retains or uses conversations. Those practices depend on your provider, account type, workspace settings, and any data-control choices you make. Review the OpenAI Privacy Policy and Anthropic Privacy Policy before connecting confidential models. Other MCP clients are governed by their respective policies.

The only AI service VI MCP calls itself is Voyage AI's embedding service, which ranks catalogue tools against the client's search descriptions. It receives those short descriptions and our own tool documentation, never data from your Revit model.

Why we use data

  • Provide the service: authenticate an installation, connect an MCP client to the correct Revit session, execute requested tools, and return results.
  • Manage access and billing: start the trial, verify entitlement, process a selected plan, and maintain payment records.
  • Protect users and the service: detect invalid or abusive access, enforce token scopes, investigate failures, and prevent repeated trial registration.
  • Support and improve reliability: diagnose compatibility and performance problems and answer support requests.
  • Comply with law: maintain records or respond to valid legal requests where required.

Where data-protection law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in security and service reliability, compliance with legal obligations, and consent where we specifically ask for it.

Who receives data

We do not sell personal data or share it for cross-context behavioural advertising. We disclose data only as needed to the following recipients:

  • Infrastructure providers, including cloud hosting, databases, networking, and security services that operate the VI MCP service under contractual confidentiality and data-protection obligations. Our servers and databases run on Railway in its EU West region (Amsterdam, Netherlands).
  • Grafana Labs (Grafana Cloud), our monitoring service, which receives operational logs, traces, and performance metrics from our servers in its EU region. Access tokens are removed before anything is sent.
  • Voyage AI, which receives the short tool-search descriptions described above to rank catalogue tools. It does not receive Revit model data.
  • Monobank, when you choose a paid plan, to create and confirm the payment. Its hosted payment page handles your payment credentials.
  • Autodesk, as the independent operator of the Autodesk Marketplace and where needed for distribution, entitlement, support, or compliance.
  • Your chosen AI provider or MCP client, such as OpenAI or Anthropic, at your direction and subject to your account and that provider's terms.
  • Authorities or professional advisers, only when reasonably necessary to comply with law, protect rights and safety, or establish and defend legal claims.

We require service providers acting for us to use appropriate safeguards and to protect the data consistently with this policy. AI providers and Autodesk may act independently under their own terms when you use their services.

Retention and deletion

Model files
Not stored by VI MCP cloud services. Files you export remain in the folder you selected.
Tool payloads
Processed in transit to fulfil the request. We do not maintain a cloud database of complete tool results or conversation content.
Query caches
Query metadata expires from the server after 2 hours. Detailed query rows are cached in your Windows temporary folder and deleted when the add-in closes. If a crash leaves a cache behind, it is eligible for cleanup the next time the add-in starts; caches older than 2 hours are treated as abandoned.
Pairing and access
Pairing codes expire after 15 minutes. Standard access tokens expire after 365 days; URL-based tokens expire after 30 days. The server stores only a one-way hash of the token secret. Token and revocation records may remain with the installation record for security and audit purposes.
Account and billing
Installation, entitlement, and invoice records are kept while your account or subscription is active and afterward only as needed for fraud prevention, accounting, tax, dispute handling, or other legal obligations.
Logs and support
Operational and security logs and traces are kept for up to 30 days in our monitoring service and up to 90 days in our hosting platform's service logs, then deleted automatically. Aggregated performance metrics, which contain no request content, may be kept longer. Support correspondence is retained until the request is resolved and then as needed to document the resolution.

When a retention period ends, data is deleted or de-identified. Backups and records required by law may remain until their normal expiry, with access restricted to the applicable purpose.

Your choices and rights

  • You can stop data flow at any time by disconnecting the add-in, removing VI MCP from the AI client, or uninstalling the add-in.
  • You can revoke an access token and clear locally saved settings. Removing the connection from ChatGPT, Claude, or another client does not automatically delete conversations already stored by that provider.
  • You may request access, correction, deletion, restriction, portability, or objection where applicable, and may withdraw consent without affecting earlier lawful processing.
  • You may complain to your local data-protection authority if you believe your rights have not been respected.

Data request

Email support@vi-mcp.cloud with enough information for us to identify your installation or transaction. Do not include your access token or Revit model. We may need to verify the request and will respond within 30 days, unless applicable law permits more time.

Security

We use encrypted transport, scoped credentials, access controls, tenant-separated caches, one-way token hashing, rate limiting, and monitoring. On your computer, the access token is encrypted for the current Windows user. Tool scopes and confirmation controls reduce unintended write actions. No system is completely secure, so use the least access needed, review write actions, and avoid exposing confidential model data to an AI service unless its terms and workspace controls meet your requirements.

International transfers

Our providers and the AI service you choose may process data in countries other than yours. Where required, we use contractual or other lawful transfer safeguards. Your AI provider's privacy notice describes its locations and transfer mechanisms.

Children

VI MCP is a professional tool and is not directed to children. We do not knowingly collect personal data from children below the age at which they may lawfully consent to data processing in their country.

Changes to this policy

We may update this policy when the product, providers, or legal requirements change. We will post the revised version here and change the effective date. If a change materially affects how we use personal data, we will provide additional notice where required.

Contact

For privacy questions, consent withdrawal, or deletion requests, contact the publisher and data controller:

Andrii Hutsaliuk (VI MCP)
Email: support@vi-mcp.cloud

Autodesk and Revit are trademarks of Autodesk, Inc. ChatGPT is a trademark of OpenAI. Claude is a trademark of Anthropic. VI MCP is an independent product and is not endorsed by Autodesk, OpenAI, or Anthropic.