Legal
Privacy Policy
Last updated: June 8, 2026
MDPilot (“we”, “us”) is operated by Viveon Gizit Pvt Ltd. This policy explains what we collect when you use mdpilot.in and the MDPilot MCP server, and your rights over it. We designed MDPilot to collect as little as possible.
What we collect
Anonymous usage metadata.
When you use the web app, we record non-identifying metadata about each generation: which mode and file type you used, the AI provider, token counts, timestamps, and an anonymous session identifier. This contains no name, email, or account — we do not require or offer accounts.
Quality feedback.
If you rate a result or edit it, we record anonymous signals (e.g. kept-as-is, edited, thumbs up/down) to improve our prompt quality.
Content you submit.
Text and files you paste or upload are sent to the AI provider you select (see “Third parties”) and, for file conversion, processed to produce markdown. We do not store the raw content of your inputs or outputs — unless you explicitly opt in (below).
Opt-in training samples.
Only if you turn on the explicit “help improve MDPilot” option for a generation do we store that input/output sample. Before storage, we run automated PII scrubbing to remove emails, keys, phone numbers, URLs, and similar. This is off by default and you can decline at any time.
Server logs.
Our hosting provider records standard technical logs (such as IP address and request metadata) for security and operation.
The MCP server runs locally.
When you use the mdpilot-mcp server in your editor, it runs on your machine using your own AI provider API key. Your repository content is sent directly from your machine to your chosen AI provider — it does notpass through or get stored by MDPilot's servers. Secret-scanning excludes flagged files before anything is sent.
How we use it
To operate the service, prevent abuse, and improve the quality of our generated output. We do not sell your data or use it for advertising.
Legal basis & consent
We process anonymous metadata to provide and improve the service (our legitimate interest / to perform the service you request). We store content samples only with your explicit consent, which you can withdraw at any time.
Third parties (sub-processors)
- AI providers — Anthropic, OpenAI, Google, and/or Groq process the content you submit, under their own privacy terms.
- Supabase — stores the anonymous metadata and any opted-in samples.
- Vercel — hosts the site and processes standard request logs.
We share data with these providers only as needed to run MDPilot.
International transfers
The AI providers and infrastructure above may process data outside your country (including outside India and the EU). By using MDPilot you understand your submitted content may be processed in other jurisdictions under those providers' safeguards.
Data retention
Anonymous metadata and feedback are retained to operate and improve the service. Opted-in samples are retained until you ask us to delete them or withdraw consent.
Your rights
Depending on your location (including under India's DPDP Act and the EU GDPR), you may have the right to access, correct, or delete your data, and to withdraw consent for opted-in samples. Because most of what we collect is anonymous and not linked to your identity, we may be unable to associate it with you — but we will honor verifiable requests where we can. To exercise a right or raise a grievance, contact us at privacy@mdpilot.in.
Security
We use reasonable technical measures (access controls, secret scanning, scoped keys) to protect data. No system is perfectly secure; submit only content you're comfortable sending to an AI provider, and never paste secrets or others' confidential information.
Children
MDPilot is not directed to children and is intended for users who can lawfully consent under the laws of their jurisdiction.
Changes
We may update this policy; we'll change the “Last updated” date above. Material changes will be noted on this page.
Contact
Viveon Gizit Pvt Ltd — privacy@mdpilot.in. For users in India, this address also serves as our grievance contact under the DPDP Act.