Privacy policy

Your context, handled with care.

This policy explains what Sutra processes when you use its web app and hosted Model Context Protocol service, why that processing happens, and the controls available to you.

Effective September 3, 2026

What this policy covers

This policy applies to Sutra's public website, account dashboard, and hosted MCP service. Sutra provides private, user-scoped memory and reusable skills that compatible AI tools can access only through credentials or OAuth authorization associated with your account.

Data controller

Sutra is operated by Shivnath Tathe, Hyderabad, Telangana, India. Shivnath Tathe is the data controller for personal data processed through Sutra.

For privacy requests, GDPR requests, and all other enquiries, contact contact@shivnathtathe.com.

Information Sutra processes

  • Account data: email address, account identifiers, profile details you provide, and authentication session data managed through Supabase Auth.
  • Memory data: observations and other content you or an authorized agent submit, plus clusters, tags, importance, source-agent labels, and timestamps used to organize that content.
  • Skill data: SKILL.md instructions and supporting resources you or an authorized agent upload, plus names, descriptions, versions, enablement status, source-agent labels, and timestamps. Agent-uploaded versions remain disabled until you enable them.
  • Connection data: API-key names, permissions, hints, hashes, status, and usage timestamps. Sutra stores API keys as one-way hashes rather than retaining the raw key after creation.
  • OAuth data: identity and authorization details needed to connect supported clients. Authorized grants can be reviewed and revoked, subject to the lifetime of access tokens already issued by the OAuth provider.
  • Activity and operations data: audit events for memory, skill, export, and security operations, along with technical logs and rate-limit counters needed to operate, troubleshoot, and protect the service.

How information is used

  • Authenticate you and authorized clients, enforce connection permissions, and provide the dashboard and MCP tools.
  • Store, retrieve, search, organize, and export memory at your request or at the request of an agent you authorize.
  • Store skill uploads, preserve immutable versions, and provide only the skill versions you explicitly enable to authorized agents.
  • Maintain audit history, apply rate limits, investigate failures or misuse, and secure the service.
  • Communicate service-related information and respond to support, privacy, or legal requests.

Service providers and disclosure

Sutra relies on service providers to run the product: Supabase for authentication and database services, Render for the hosted MCP service, Vercel for the web app, and Upstash Redis for rate limiting. Those providers process data under their own terms and configurations.

Information may also be disclosed when reasonably necessary to comply with law, respond to valid legal process, protect users or the service, or address fraud and security issues. If the project or service changes ownership, relevant information may transfer as part of that transaction, subject to applicable law.

International transfers

Your data is stored on Supabase servers located in the United States. By using Sutra, you acknowledge this international transfer.

Storage, security, and retention

Memory records and skill bundles are scoped to a user identifier in Supabase. The MCP service uses validated principals and explicit user filters when accessing records. API keys are hashed, OAuth grants are revocable, and relevant operations create audit records. No security measure eliminates all risk.

Memory and skill data is retained until you delete it or close your account. Audit logs are retained for 90 days. Account data is deleted within 30 days of account closure.

Rights for people in the European Economic Area

If you are in the European Economic Area, you have the right to access, correct, export, restrict, object to, or delete your personal data. Submit requests to contact@shivnathtathe.com.

Your choices

  • Review your memories, clusters, skill versions, connection details, and activity in the dashboard.
  • Export your memory and associated metadata using Sutra's export capability.
  • Revoke individual API keys and supported OAuth grants when you no longer want a client connected.
  • Ask about access, correction, export, restriction, objection, or deletion by emailing contact@shivnathtathe.com.

Updates and contact

This policy may be updated as Sutra changes. Material revisions will be reflected by changing the effective date on this page.

For support, privacy, security, GDPR, legal, or other enquiries, email contact@shivnathtathe.com. Do not send credentials, API keys, or private memory content.