Privacy
Last updated 2026-10-08. GoLive MCP is operated by Hapi.
What we store
- API keys and OAuth tokens, as SHA-256 hashes only, with a label, a scope and when they were last used.
- OAuth client registrations (client name and redirect URIs) created by MCP clients.
- GitHub connections: the GoLive GitHub App installations you connect, the names and ids of the repositories they cover, the app and branch you link, and the ids of webhook deliveries with a short summary (branch, commit, check result). We read repository files only when a tool asks for them, and keep no copy of your code or any GitHub token.
- Budgets opened by operators: amount, cap, expiry, who opened them.
- An audit log of every tool call that changes something, including dry runs and refusals: the tool, the caller's key label, the target (for example a domain or variable name), the outcome, the cost, and the arguments. Secret values passed to tools are never stored: the log keeps only their length and a short hash.
Read-only tool calls are not logged by GoLive. Standard request logs (time, path, status) are kept by our hosting provider for operations.
What we pass on
GoLive performs actions through the imagia platform (domains, DNS, deploys, configuration, storage, routing, audits) and through AI Mail MCP (email). Arguments needed for an action are sent to those services. Domain purchases go to the registrar through imagia. Audits read the code of the project or repository you name.
What we do not do
- We do not sell data or use it for advertising.
- We do not return secret values to callers once they are set.
- We do not train models on your data.
Deletion
Revoking a key ends every OAuth grant made with it. Ask the operator who issued your key to delete your keys and audit history.