Privacy Policy
Last updated: 18 August 2026
1. Who We Are
Pear MCP is operated by Ashton Turner, based in Australia. For privacy enquiries, contact [email protected].
2. Information We Collect
Account Information
When you sign up, we collect your email address and use magic links for authentication. We also store the account and session information needed to keep you signed in, manage your subscription, and operate the dashboard.
Provider Credentials and OAuth Tokens
To provide the Service, we store the provider connection credentials you choose to add. For Apple iCloud connections, this includes your Apple Account email, optional iCloud Mail address, and an app-specific password. For Microsoft 365 connections, this includes OAuth access tokens, refresh tokens, expiry information, and the scopes granted to Pear. For compatible IMAP/SMTP mailboxes, this includes the mailbox address, server settings, and mailbox credential you choose to add. If Google provider access is enabled, Google connections use OAuth tokens and granted scopes rather than your Google password. These credentials and tokens are encrypted at rest using AES-256-GCM with a server-side key. We never store your main Apple ID, Microsoft, or Google password.
API Keys and OAuth Access
Pear stores API key hashes and limited key metadata, such as the last four characters, so keys can be verified and rotated without storing the raw key. For OAuth-compatible clients, Pear issues authorization codes and access tokens tied to your account and current API key state.
Usage Data
We track metered action counts per user per calendar month for billing and rate-limiting purposes. We also collect pseudonymous tool usage metadata (tool name, response time, success/failure, error type, and timestamp) to improve the Service, and Pro users can view this metadata in the Activity page. Tool analytics use pseudonymous, stable keyed HMAC-SHA256 identifiers for users and sessions rather than storing plain IDs; those identifiers remain linkable for authorized product and activity analysis. For security and abuse prevention, MCP audit records may also include HMAC-SHA256 hashes of the trusted request IP, coarse IP prefix, and user-agent, plus limited request metadata such as host, origin, referer origin, and country when provided by the trusted edge. MCP audit records may include a canonical client family, a bounded client version bucket, and categories describing how confidently that family was identified. These values can come from a registered OAuth client, MCP client information, an explicit client header, or a user-agent fallback. Self-reported and inferred client values are not treated as verified identity. Pear does not store raw IP addresses, full user-agent strings, or raw unrecognized MCP client names in MCP audit records.
Marketing Analytics
Public marketing pages send a bounded pageview and fixed-enum conversion events to the configured Rybbit analytics endpoint. Pageviews include the site hostname, page path and title, approved UTM campaign fields, referrer origin, language, and screen dimensions. Conversion events include only an approved CTA surface, contact channel, or example workflow category. Web Vitals events include only a fixed metric name, rounded value, rating, fixed public route category, and the exact server-attested release SHA; they do not include the browser metric ID, performance entries, or navigation details. Arbitrary query parameters, raw URLs or referrers, form values, contact details, and account identifiers or browser identifiers are not sent to Rybbit. The relay forwards a bounded browser user-agent and standard fetch metadata so Rybbit can classify the browser and operating system and reject bots. It also forwards the trusted request IP so Rybbit can derive pseudonymous visitor and session metrics and coarse location; Rybbit retains those derived values, not the raw IP or full user-agent. The requests come from a sandboxed frame with credentials omitted; the frame itself does not use cookies or browser storage. For aggregate funnel analysis, an allowed content CTA or workflow event is also written to Pear's server-side lifecycle analytics with a pseudonymous browser identifier and bounded first touch: a fixed landing-route taxonomy, approved UTM fields, and referrer origin. Pear honors Global Privacy Control, Do Not Track, and an explicit opt-out saved through Pear's earlier analytics-choice UI for both emissions. Marketing analytics are separate from essential authentication or product functions and from server-side operational, security, and audit records.
Payment Information
Payments are processed by Stripe. We do not store credit card numbers or bank details. We store your Stripe customer ID and subscription ID to manage your subscription. See Stripe's Privacy Policy for how they handle payment data.
Provider Data
When you or your AI assistant makes a request, we access connected provider data in real time. For Apple iCloud, this can include Calendar and legacy reminder data Apple still exposes through CalDAV, Contacts through CardDAV, and iCloud Mail through IMAP and SMTP. Pear's hosted Apple connection cannot access Apple's upgraded Reminders store. For Microsoft 365, this can include Calendar, Microsoft To Do, Contacts, and Outlook Mail data through Microsoft Graph. For compatible IMAP/SMTP mailboxes, this can include mailbox folders, messages, drafts, and send actions. If Google provider access is enabled, the current Stage A grant can include Google Calendar availability and events, Google Tasks, Google Contacts, and user-requested Gmail send actions through Google APIs. It does not grant Pear access to search or read the Gmail inbox.
For read requests, provider data is fetched live, processed in memory, and returned to the AI or MCP client you selected. Pear does not build a separate database copy of your mailbox, calendars, tasks, or contacts. Full provider response bodies, message bodies, attachments, contact records, calendar event bodies, and task details are not retained in ordinary logs or analytics.
Approved Write Records
Pear's approved-write workflow is an exception to live-only processing. When that workflow is used and persistence succeeds, Pear stores an approval ledger so it can prove that the action executed was the action approved. A ledger record can include the exact draft and approved action payload, provider and account identifiers, tool and action type, timestamps, approval or rejection details, source-reference metadata, risk and redaction classifications, execution status, normalized failure details, the provider execution receipt or result, and undo-plan metadata. Depending on the action, the exact payload can contain email recipients, subject and body; calendar title, description and attendees; task details; or contact fields. The ledger does not contain provider passwords or OAuth tokens. Read-only provider results are not added to this ledger merely because they were returned to your client.
Support Communications
If you email support or use the public contact form, we collect the information you choose to send so we can investigate, route, and respond to the request. Contact-form fields include your name, reply email, optional Pear account email, topic, subject, and message. The form also sends the path portion of the referring page (up to 240 characters) and the request user-agent (up to 300 characters). The support email is delivered through Resend. When Pear's Activepieces contact webhook is configured, those same submitted fields and bounded request details are also sent to that automation endpoint, together with the derived message length, to route and action the request. Pear also records one contact-submitted product event containing the topic, whether an optional account email was supplied, subject and message lengths, and the bounded referrer path.
Pear keeps a delivery ledger so retrying the same form submission does not repeat completed delivery steps. That ledger stores keyed HMAC-SHA256 digests of the retry token and canonical form payload, delivery states and timestamps, and bounded event or provider identifiers. It does not store the submitted name, email addresses, topic, subject, message, user-agent, or referrer.
3. How We Use Your Information
- To authenticate you and provide access to the Service
- To connect to provider accounts you choose, including Apple iCloud, Microsoft 365, compatible mailboxes, and Google when enabled
- To perform user-requested calendar, tasks, contacts, and mail actions through those provider accounts
- To issue, verify, rotate, and revoke Pear API keys and OAuth access
- To process subscription payments via Stripe
- To enforce usage limits (Free: 50 counted provider actions/month; Pro removes that monthly cap)
- To improve the Service through pseudonymous analytics and the Activity page
- To deliver, route, and respond to contact and support requests
- To send important service-related communications (e.g. security issues, billing problems)
- To prevent abuse, debug failures, and keep the Service reliable
4. Data Sharing
We do not sell your personal data. We share data only with:
- Apple iCloud — your credentials are sent to Apple's CalDAV, CardDAV, IMAP, and SMTP servers to fulfil requests
- Microsoft — OAuth tokens are sent to Microsoft Graph when you connect Microsoft 365 provider workflows
- Compatible mailbox providers — mailbox credentials and message requests are sent to the IMAP/SMTP servers you configure
- Google APIs — when Google provider access is enabled, OAuth tokens are sent to Google APIs to fulfil Google Calendar, Tasks, Contacts, and Gmail requests you initiate
- Your selected AI or MCP client — provider data and tool results needed for your request are returned to the client you chose to connect to Pear
- Stripe — for payment processing
- Supabase — for database hosting and authentication
- Resend — for transactional product emails and delivery of public contact-form messages to Pear support
- Activepieces — when the contact webhook is configured, for routing submitted contact-form fields, derived message length, and the bounded referrer path and user-agent described above
- Hetzner/Coolify — for production application hosting
- Vercel — for preview-only deployments
We do not sell provider data or use Google Workspace API data for advertising. Pear does not use or transfer Google Workspace API data to develop, improve, or train generalized AI or machine learning models. Google data is transferred to your selected AI or MCP client solely to provide the specific user-requested tool result; the client you choose is an independent service governed by its own terms and privacy practices.
Pear's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We may disclose information if required by law or to protect our rights and the safety of our users.
Some service providers may process data outside Australia. Where that happens, we use reputable providers and limit the information shared to what is needed to provide the Service.
5. Data Security
- Provider OAuth refresh tokens and iCloud app-specific passwords are encrypted at rest with AES-256-GCM
- All connections use HTTPS/TLS
- API keys use cryptographically secure random generation and are stored as hashes
- Billing columns are protected by database-level triggers
- Rate limiting is enforced on all API endpoints
- Provider message bodies, attachments, contacts, calendar details, and task contents are not stored in ordinary analytics or logs; approved-write ledger records are the exception described above
No system is 100% secure. If you believe your account has been compromised, contact us immediately and regenerate your API key in Settings.
6. Data Retention
Your account data and encrypted credentials are retained while your account is active. If you disconnect a provider account, the active encrypted credential or token values are removed, revoked where supported, or replaced with a disconnected marker. Usage analytics, security records, and approved-write ledger records may be retained to protect the Service, understand reliability, maintain billing records, and preserve an audit trail of actions you approved. Disconnecting a provider does not by itself delete those existing operational or approval records.
Pear has documented a proposed 366-day retention window for MCP audit events and approval-ledger records, but that window is not yet an approved or deployed automatic deletion guarantee. Until a production retention schedule is approved and deployed, those records may be retained for longer. Limited records may also be retained where needed for legal, tax, billing, security, incident-response, or dispute-resolution reasons.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict processing of your data
Pro users can export a safe metadata view of recent tool and approval activity from the Activity page. That export does not include raw approved-write payloads, message content, provider responses, or OAuth tokens. You can permanently delete an eligible account from the danger zone in Settings. Active subscriptions and shared account data must be resolved first. To request a broader account export, get help with a blocked deletion, or exercise another privacy right, email [email protected]. We will verify the request before processing it. Deletion remains subject to the limited retention grounds described above.
8. Cookies
We use essential cookies for authentication (Supabase session tokens). We do not use advertising cookies. The bounded marketing pageview request described above uses credentials omitted and does not use cookies or browser storage through Pear's sandboxed analytics frame.
9. Children
The Service is not intended for users under 16. We do not knowingly collect data from children.
10. Privacy Complaints
If you have a privacy concern, email [email protected] and we will review it. If you are in Australia and remain dissatisfied, you may also be able to contact the Office of the Australian Information Commissioner.
11. Changes
We may update this policy from time to time. We will notify users of material changes via email or an in-app notice.
12. Contact
For privacy enquiries, contact [email protected].