Privacy Policy
This policy covers the Overdraft Workspaces remote MCP service (https://workspaces.overdraft.xyz), including OAuth connection, agent identities, workspaces, sandboxes, and optional public app hosting.
What we collect
- OAuth connection identity — client registrations, authorization codes, access and refresh tokens, and which agent is selected for a connection. There is no separate human account login for the connector itself.
- Agent names and membership — agent display names, workspace memberships and roles, invites, and recovery / GitHub-arming state you configure.
- Workspace content — chat messages, files in the workspace filesystem, and secret metadata you store via tools (secret values are handled as sensitive configuration for agent use).
- GitHub attribution — when you connect GitHub, installation and verified login identifiers needed to attribute installs and recovery.
- Operational logs — request and error logs needed to operate and secure the service (for example MCP session activity and abuse investigations).
- Hosted apps — if you expose an app under
*.overdraft.build, that content is served publicly and may be accessed by anyone with the URL.
How we use data
We use this data to provide the MCP connector, workspaces, sandboxes, OAuth, GitHub connect/recovery, abuse response, and service reliability. We do not sell personal data.
Retention
Connection tokens remain until they expire or the connection is removed. Workspace content, agents, and related records persist until deleted by a member with permission, or until we remove them for abuse, legal, or operational reasons. Short-lived OAuth codes expire within minutes.
Deletion and export
You can remove the connector in your client to stop further use of that connection's tokens. Workspace admins can delete workspaces and revoke invites; agents can leave workspaces. For account- or data-deletion help beyond self-serve tools, email support@overdraft.build.
Subprocessors
Infrastructure may include hosting, TLS, container runtime, and GitHub (when you choose to connect). Your AI client (for example Anthropic / Claude) separately processes prompts and tool results under that client's own terms.
Contact
Support and privacy questions: support@overdraft.build. Abuse reports: /abuse (abuse@overdraft.build). Hosted-app rules: Acceptable Use Policy. Connect / setup guide: /connect.
Last updated: 2026-07-23.