Privacy Policy

Last updated: 2026-07-23

Ares ("Ares", "we", "us", or "our") operates the website and hosted Model Context Protocol (MCP) service at aresmcp.com(the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to this policy.

1. Who we are

Ares provides a hosted red-team / security toolkit that AI agents (for example Claude Code) can call over MCP. The Service is intended for authorized security testing and research only.

Contact for privacy questions: support@aresmcp.com.

2. Information we collect

2.1 Account (Google Sign-In)

When you sign in with Google, we receive information from Google according to your Google account settings and the scopes we request. Typically this includes:

  • Google account identifier (subject)
  • Name
  • Email address
  • Profile image URL

We do not receive or store your Google password. Authentication is handled by Google OAuth 2.0 / OpenID Connect.

2.2 Session and access tokens

After you sign in, we create a session for the website (cookie-based) and may issue a short- or medium-lived access token (JWT) that you use as a Bearer token to call the MCP API from an agent client. Token claims may include your user id, email, issued-at, and expiry. Tokens are signed with a server secret; we do not store the full token body after issuance except as needed for security logging.

2.3 Usage and operational data

When you use the Service we may process:

  • Tool invocations and parameters you submit (for example target hostnames/URLs)
  • Job metadata (status, timestamps, progress, errors)
  • Findings and artifacts produced by tools
  • IP address, user agent, and basic request logs
  • Approximate usage volume for rate limiting and abuse prevention

2.4 Cookies

We use cookies and similar technologies that are necessary to keep you signed in and protect the session (for example CSRF and session cookies). We do not use third-party advertising cookies on the Service.

3. How we use information

We use the information above to:

  • Authenticate you and secure access to the Service
  • Provide, operate, and improve the MCP tools and website
  • Enforce acceptable use, rate limits, and security policies
  • Investigate abuse, fraud, or unauthorized scanning
  • Comply with law and respond to lawful requests
  • Communicate service-related notices (for example security or outage notices)

We do not sell your personal information.

4. Legal bases (EEA/UK where applicable)

Where GDPR/UK GDPR applies, we process personal data on these bases:

  • Contract — to provide the Service you request after sign-in
  • Legitimate interests — security, abuse prevention, service improvement (balanced against your rights)
  • Legal obligation — when we must retain or disclose data to comply with law

5. Sharing

We may share information with:

  • Infrastructure providers that host the Service (compute, storage, DNS, TLS) under contractual confidentiality
  • Googleas the identity provider for sign-in (subject to Google's policies)
  • Authorities when required by law or to protect rights, safety, and the integrity of the Service

Tool traffic may contact third-party systems you designate as scan targets. Those systems and their operators may log your probe traffic. You are responsible for having authorization to test those targets.

6. Retention

We retain account identifiers while your account is active. Job artifacts, findings, and raw tool output are retained for a limited operational period (typically up to 30 days unless a longer period is required for security investigation), then deleted or anonymized. Logs may be kept longer in aggregated or minimized form for security.

You may request deletion of your account data by emailing support@aresmcp.com. We may retain limited records as required for legal, security, or abuse-prevention purposes.

7. Security

We use industry-standard measures appropriate to the Service, including transport encryption (TLS), access controls, signed tokens for API access, and network/policy controls that block certain sensitive destinations (for example private networks and cloud metadata endpoints). No method of transmission or storage is 100% secure.

8. International transfers

The Service may be hosted in the United States or other countries. If you access the Service from another region, your information may be processed in countries with different data-protection laws. We take steps designed to protect personal data in line with this policy.

9. Children

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. To exercise these rights, email support@aresmcp.com. You may also revoke Google access to Ares from your Google account permissions page.

11. Changes

We may update this policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated via the Service or email when appropriate.

12. Contact

Privacy and data requests: support@aresmcp.com

Abuse reports (unauthorized scanning, misuse): support@aresmcp.com