Voidly Atlas connector privacy notice
This notice covers the four public, read-only Atlas MCP tools at https://atlas-mcp.voidly.ai/mcp. Voidly, operated by Ai Analytics LLC, provides the connector. It does not require an account, wallet, API key, or payment information. This notice describes the data handling for these four connector tools; other Voidly products are covered by their own notices.
What a request contains
The connector transiently processes an MCP JSON-RPC request body, up to 64 KiB. It includes protocol fields and, for a tool call, the tool name and permitted arguments. Incident detail accepts a published incident ID or bounded hexadecimal hash; country data accepts a two-letter country code; incident statistics and measurement summary accept no arguments. Clients may also send protocol or client metadata used to handle the request. The connector does not request a conversation transcript or accept arbitrary URLs, account IDs, payment details, or free-form search text as tool arguments.
IP address and rate limits
Cloudflare supplies the connecting IP address to the Worker. The connector validates and normalizes it for a Cloudflare per-location rate-limit key and also checks an aggregate limit. The current limits are 30 approved reads per 60 seconds for an IP key and 600 per 60 seconds for the aggregate key. Several people using one client platform may share its outgoing IP and limit. Cloudflare manages the counters; this notice does not assert an exact counter-retention period or globally exact counting. A missing or invalid client IP or unavailable limiter makes reads unavailable.
Upstream read and returned fields
For an approved tool call, the adapter makes one fixed public-data GET through an internal Voidly Worker binding. It forwards the selected public path and an Accept: application/json header, not the incoming request body, caller IP, cookies, authorization header, or client metadata. The adapter checks the upstream shape and returns selected public fields with source attribution, fetch time, freshness context, and interpretation limits. Token-pattern redaction is heuristic; it is not a guarantee that every upstream string is harmless. The disabled incident-evidence tool is not part of these four reads.
Storage and infrastructure
The adapter code has no application database or request-payload log statement. The current publisher configuration disables Workers Logs, traces, and Logpush. MCP responses use Cache-Control: no-store. This HTML contains no scripts or externally loaded resources and does not set a cookie.
Cloudflare still terminates TLS and can process zone security events, IP addresses, user agents, aggregate traffic analytics, and rate counters under its own settings. The upstream Voidly service and your MCP client may process data separately. Their records and retention are not established by the adapter source or this page. Voidly does not promise universal no-logging or a single retention period across these systems.
Source rights and interpretation
The connector projects selected public fields. Its source labels and API URLs are attribution, not independently verified evidence or guaranteed measurement permalinks. Fetch time and a country response's lastUpdated value do not establish measurement observation time; incident counts alone do not establish a current event. An absent record does not prove accessibility.
Public access is not a blanket reuse license. Voidly-owned material is CC BY 4.0 only where expressly designated. OONI-derived data can be subject to CC BY-NC-SA 4.0, and other upstream fields can have separate terms. Keep source attribution and check the relevant rights before redistribution. See the Voidly terms and the connector documentation.
Contact
For privacy questions: privacy@voidly.ai. For security issues: security@voidly.ai. For connector help: Voidly support or support@voidly.ai. Do not send credentials or private content in a support message.