Effective July 31, 2026
Privacy Policy
This policy explains the categories of personal data HostedStatic, operated by Last Frontier Media, handles when authorized users manage a client website through ChatGPT or another supported MCP client.
Information we handle
- Account and access information. Email address, optional display name, account status, website memberships and roles, account-activation time, and—only for limited legacy or reviewer accounts—a salted password verifier. Standard client accounts use passwordless email sign-in. We do not store plain-text passwords.
- Website and change information. Website identity, repository and deployment identifiers, permitted file paths, source content that an authorized user asks the service to read or change, change summaries, preview and publication status, and related GitHub pull-request information.
- Tool and security records. State-changing tool requests and responses, OAuth client and authorization records, deployment events, and audit records. Read-only website lookups are not stored in the detailed tool-call history. HostedStatic redacts known secrets from its tool logs and stores issued HostedStatic access tokens only as hashes.
- Connection information. Agency administrators may connect an approved Vercel project. That can provide a Vercel user identifier or email and narrow OAuth credentials used to verify deployments and provide temporary private-preview access. The credentials are encrypted at rest. Client users are not asked for Vercel or GitHub passwords or personal API tokens.
- Sign-in and support information. One-time email sign-in tokens are stored only as hashes. Sign-in IP addresses and email addresses are transformed into hashes for short-lived abuse controls. We also receive information you choose to send when requesting support.
Where the information comes from
We receive information from you, your organization or account manager, the MCP client you choose to use (such as ChatGPT), and the GitHub and Vercel accounts connected to the website. HostedStatic acts only on the website and permissions assigned to your account.
How we use information
We use this information to authenticate users, enforce website-specific permissions, read requested site files, prepare and revise private previews, publish changes after explicit approval, show change status, prevent abuse, diagnose failures, provide support, and meet legal obligations. We do not use client website content to build advertising profiles.
Who receives information
We disclose information only as needed to operate the service:
- Cloudflare provides application hosting, database, queue, security, and email infrastructure.
- OpenAI or another MCP client selected by the user receives tool results, including requested website content and change status, so it can complete the user’s request.
- GitHub receives repository reads, branches, commits, and pull requests needed to prepare and publish changes.
- Vercel receives narrowly scoped requests needed to verify an approved project deployment and provide temporary access to its private preview.
- Your organization and its authorized agency administrators may receive account, website, change, and audit information according to their roles.
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate confidentiality protections. We do not sell personal information or share it for cross-context behavioral advertising.
Retention
Browser sign-in sessions last 30 minutes. Email sign-in and password-reset links last 30 minutes and work once. HostedStatic access tokens last one hour, refresh access expires after 30 days without renewal, and private-preview access grants last one hour. Expiration prevents reuse; associated hashed or redacted security records may remain in the operational history described below.
We keep account, membership, website configuration, change, deployment, redacted tool-call, and audit records while the related customer relationship is active. After it ends, we review those records at least annually and generally delete or de-identify them within 24 months, unless a longer period is reasonably necessary for security, fraud prevention, dispute resolution, or legal compliance. Short-lived rate-limit records become inactive automatically and are removed through routine cleanup. Connected providers may retain their own copies under their policies.
Your choices and controls
You can disconnect HostedStatic from your MCP client to stop future access. You or your organization’s authorized administrator may ask us to provide, correct, or delete account information, or close an account, by contacting info@lastfrontiermedia.com. We may need to verify the request and may retain limited records when legally permitted or reasonably necessary to protect the service and its users.
Security
We use one-time passwordless sign-in links, access controls, audience-bound authorization, hashed HostedStatic tokens, redacted operational logs, encrypted Vercel credentials, and scoped provider permissions. No internet service can guarantee absolute security. Please do not send passwords, API keys, one-time codes, payment-card data, government identifiers, or health information through HostedStatic tools or support email.
Children
HostedStatic is a business website-management service and is not directed to children under 13. If you believe a child has provided personal information, contact us so we can address it.
Changes to this policy
We may update this policy as the service changes. We will post the updated date here and provide reasonable notice before a material change applies to information already collected when notice or consent is required.
Contact
Privacy requests and questions can be sent to info@lastfrontiermedia.com.