1. Introduction
IAN Cloud, Inc. ("IAN," "we," "us," or "our") operates the IAN platform at iancloud.ai and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, APIs, and MCP (Model Context Protocol) integrations.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and organization details. If you sign in through GitLab SSO, we receive your GitLab username, email, and user ID.
Cloud Infrastructure Data
When you connect your AWS account, IAN accesses your cloud resources through a scoped IAM role you create via CloudFormation. This includes:
- Resource inventory (EC2 instances, S3 buckets, RDS databases, etc.)
- Cost and billing data from AWS Cost Explorer
- CloudTrail events for security monitoring
- IAM configuration for security auditing
IAN does not store your AWS credentials. Access is granted through an IAM role with a trust relationship scoped to your account and an external ID.
Repository and Code Data
When you connect GitLab repositories, IAN accesses repository metadata, CI/CD configuration, and infrastructure-as-code files for auditing purposes. IAN does not store raw source code beyond what is needed for active audit analysis.
MCP Integration Data
When you connect to IAN through MCP-compatible clients (such as Claude, Cursor, or other AI assistants), we collect:
- OAuth authorization records (client ID, authorized scopes, timestamps)
- Tool invocation logs (method called, duration, success/failure status)
- Session metadata (client name, protocol version, IP address)
We do not log the content of your conversations with AI assistants. We only log which IAN tools were called and their execution status.
Usage Data
We automatically collect standard usage data including IP addresses, browser type, pages visited, and feature usage patterns to improve the platform.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the IAN platform
- Generate infrastructure audits, cost reports, and security assessments
- Process MCP tool calls and return results to authorized clients
- Send transactional notifications (audit results, cost alerts, security findings)
- Provide customer support
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
4. Data Sharing
We do not sell your personal information. We share data only in these circumstances:
- AI Model Providers — When you use IAN's AI assistant features, prompts may be sent to third-party AI providers (e.g., Anthropic, Moonshot) to generate responses. These providers process data according to their own privacy policies and do not use your data to train models.
- Infrastructure Providers — We use AWS and Hetzner to host the platform. Your data is stored and processed on these providers' infrastructure.
- MCP Clients — When you authorize an MCP client, that client receives the tool results you requested through IAN. Authorization can be revoked at any time from your MCP settings.
- Legal Requirements — We may disclose information if required by law, court order, or governmental authority.
5. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS) and at rest
- OAuth 2.0 with PKCE for MCP authentication
- Capability-based access control (observe, operate, administer scopes)
- Audit logging of all administrative and MCP operations
- Service token rotation and revocation capabilities
6. Data Retention
We retain your account data for as long as your account is active. Infrastructure scan results and audit findings are retained for 90 days. MCP invocation logs are retained for 30 days. You may request deletion of your data at any time by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Revoke MCP client authorizations at any time
- Export your data in a portable format
- Opt out of non-essential communications
8. MCP-Specific Provisions
IAN's MCP server enables AI assistants to interact with your infrastructure on your behalf. Important details:
- Authorization is explicit — Each MCP client must be authorized via OAuth before accessing any tools.
- Capabilities are scoped — You control whether a client can only observe (read) or also operate (write) through capability presets.
- Service tokens — Programmatic access tokens can be created with specific capability sets and expiration dates.
- Revocation — You can revoke any client authorization or service token immediately from your dashboard.
- Telemetry — All tool invocations are logged and visible in your MCP dashboard for full auditability.
9. Cookies
We use essential cookies for session management and authentication. We use Cloudflare analytics for performance monitoring. We do not use third-party advertising cookies.
10. Children's Privacy
IAN is not intended for use by individuals under the age of 16. We do not knowingly collect information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
12. Contact
For privacy-related questions or requests, contact us at:
- Email: [email protected]
- General support: [email protected]