This policy describes how the GTH Intelligence MCP Server (https://gth-mcp-server.pages.dev/mcp) handles data. The directory itself is SAMHSA-sourced public facility data, not patient records.
When you call a tool, we receive the name of the tool you called and the query parameters you supply — state, city, treatment type, insurance, and facility-name searches — together with the number of results returned and a timestamp. We also record the user-agent string and referer (if any) of the calling software and, where your client supplies one, the MCP session identifier. If you send a legacy API key, we record its access tier (otherwise the call is logged as "anonymous"). We receive your IP address from the network connection and use it only (a) for rate limiting and (b) as a transient input to a daily-rotating, non-reversible session-correlation value; your raw IP address is never written to any store.
To operate the service and return results; to enforce rate limits (100 calls per IP per day); and to produce aggregate, non-identifying analytics on which treatment categories and locations are searched, so we can understand coverage and improve the directory.
Usage records are stored in Cloudflare D1 (our hosting provider's own database) and mirrored to Airtable for review. Each record holds the non-identifying call metadata described above — tool, query arguments, user-agent, referer, and the derived session identifier — and does not contain your IP address or any account identity. Your IP address is held only as a per-day rate-limit counter in Cloudflare KV, which expires automatically after 48 hours. Individual usage records are retained for up to 24 months, after which they are deleted; aggregate, de-identified demand statistics derived from them may be kept indefinitely.
We use Cloudflare as our hosting and infrastructure provider (including the D1 database) and Airtable as a processor. We use aggregate, non-identifying search-demand insights to inform directory coverage decisions. We do not sell or share the query or demand data, and we do not provide paid or ranked placement.
No patient health information is requested or required — the tools accept only location, treatment type, and insurance filters, so do not submit personal health details. We do not store your IP address as part of usage records, set cookies, or require account registration. The session identifier is an ephemeral, daily-rotating correlation value, not a persistent user ID.
We may update this policy; the current version is always at this URL.