Stienhardt diamond MCP server: privacy notice (2026-09-08) What we collect about MCP users: nothing. The MCP tools are stateless and unauthenticated. They set no cookies, store no requests, and build no profiles. Measured outbound links: the /go redirect records one click event containing the declared source, medium, campaign, content label, and destination path. It does not record an IP address, cookie, account, identity, or free-form search phrase in Stienhardt's analytics dataset. The tagged destination URL is then returned as an immediate redirect. What a request contains: the tool name and its arguments, for example a diamond term, a carat weight and shape, a grading lab and report number, or a search phrase. Purpose: to answer that request. Where it goes: the education tools are answered from data bundled in the server. The live inventory tools (search_inventory, get_product) read Stienhardt's public Shopify UCP catalog. Shopify receives the search phrase or product id. Loose-diamond stock is not verified by this tool; those searches return public catalog listings flagged availability_verified false plus a storefront browsing link, without any stock-service request. No shopper identity is forwarded. Store privacy policy: https://stienhardt.com/policies/privacy-policy. Cloudflare, which hosts this server, may keep standard operational logs (IP address, timestamps) under its own policy. Retention: MCP request content is not retained. Outbound click events expire after 90 days and are used only for aggregate campaign measurement. Third parties: Cloudflare (hosting and click storage), Shopify (catalog reads). Your controls: the click data cannot be tied to an identity because Stienhardt does not store one in the dataset; stop using measured outbound links to stop sending click events. Contact: jgalperin@stienhardt.com Source code: https://github.com/JacobiusMakes/diamond-mcp