Urbit · Geographic Intelligence
Urbit MCP — Privacy Policy
Effective date: September 16, 2026
This Privacy Policy explains how URBIT SERVIÇOS DE INFORMÁTICA LTDA (CNPJ 31.687.326/0001-62), with registered office at Av. Paulista, 509 – Sala 1513, Bela Vista, São Paulo – SP, Brazil, and commercial office at WT Morumbi, 7th floor, Av. das Nações Unidas, 14261 – Vila Gertrudes / Chácara Santo Antônio, São Paulo – SP, 04794-000 (“Urbit”, “we”, “us”) collects, uses, shares and protects personal data when you use the Urbit MCP server, the Urbit API, our website and related services (the “Service”). Urbit is the data controller for the processing described here, under the Brazilian General Data Protection Law (Law 13.709/2018, “LGPD”).
1. Scope
This Policy applies to Users who create an account, connect the MCP server to an AI assistant or client application, purchase Credits or contact Customer Support. It does not apply to the AI assistants or third-party platforms through which you may access the Service (for example, an MCP client); those are governed by their providers’ own privacy policies.
2. Personal data we collect
Data you provide
- Account data: name, business email address, company name, CNPJ/CPF when required for invoicing, job title and password (stored in hashed form).
- Billing data: billing address, invoicing details and payment confirmation. Card or bank details are handled by our payment processors; Urbit does not store full card numbers.
- Support data: the content of messages you send to Customer Support and any attachments.
Data collected automatically when you use the Service
- Request data: the endpoints or MCP tools called, query parameters (such as addresses, coordinates, radius and limits), timestamps, response status and size, and the Credits consumed.
- Technical data: IP address, API key or token identifier, client or MCP host identifier, user agent and error logs.
- Website data: pages visited and basic analytics, collected through cookies as described in Section 9.
Data we do not collect. The Service is designed for professional real estate and urban analysis. The Content it returns is compiled from public and licensed sources and from Urbit’s own models, and the Service does not return confidential taxpayer information or personal data about the owners or occupants of properties. We do not intentionally collect sensitive personal data (as defined in Article 5, II of the LGPD) and ask that you do not send it to us. Addresses and coordinates you submit as query parameters are treated as business inputs; where they could identify an individual, they are processed only to answer your Request and are protected as described below.
3. How we use personal data
- To provide the Service: authenticate you, process Requests, return Content, meter Credits and maintain your balance.
- To bill and manage the relationship: issue invoices and tax documents, apply welcome credits, process purchases and prevent fraud.
- To support you: answer questions, investigate errors and resolve disputes.
- To secure and improve the Service: monitor abuse, enforce rate limits and acceptable use, debug errors, and analyse aggregate usage to improve coverage, performance and pricing.
- To communicate: send service notices (changes to prices, terms, availability) and, with your consent or where permitted by law, product updates. You can opt out of marketing messages at any time.
- To comply with legal obligations, including tax, accounting and regulatory requirements in Brazil.
4. Legal bases under the LGPD
| Purpose | Legal basis (LGPD, Art. 7) |
|---|---|
| Providing the Service, metering Credits, billing | Performance of a contract (Art. 7, V) |
| Invoicing, tax and accounting records | Compliance with a legal obligation (Art. 7, II) |
| Security, abuse prevention, service improvement, aggregate analytics | Legitimate interest (Art. 7, IX) |
| Marketing communications, non-essential cookies | Consent (Art. 7, I) |
| Defending Urbit’s rights in disputes | Exercise of rights in proceedings (Art. 7, VI) |
5. How we share personal data
We do not sell personal data. We share it only with:
- Service providers (operators) who process data on our behalf under contract: cloud hosting and infrastructure, payment processors, invoicing and tax platforms, email delivery, analytics and customer-support tools.
- AI assistant and MCP client providers, only to the extent that your Requests and the Content returned pass through the client you chose to use. Urbit does not send your account data to those providers.
- Professional advisers and authorities when required by law, court order or regulatory request, or to protect Urbit’s rights, Users or the public.
- A successor in the event of a merger, acquisition or sale of assets, subject to this Policy.
6. International transfers
Some of our service providers store or process data outside Brazil (for example, cloud infrastructure in the United States or the European Union). When that happens, we rely on the transfer mechanisms of Articles 33–36 of the LGPD, including standard contractual clauses approved by the Brazilian National Data Protection Authority (ANPD), and require providers to apply security measures equivalent to those described in this Policy.
7. Data retention
| Data | Retention period |
|---|---|
| Account data | For the life of the account and up to 5 years after closure, to meet legal and contractual obligations |
| Request and usage logs | 12 months in identifiable form; aggregated thereafter |
| Technical and security logs | At least 6 months, as required by the Brazilian Internet Framework (Law 12.965/2014, Art. 15) |
| Billing and tax records | 5 years, as required by Brazilian tax law |
| Support communications | Up to 2 years after the ticket is closed |
When a retention period ends, data is deleted or irreversibly anonymized.
8. Security
Urbit applies technical and organizational measures appropriate to the risk, including encryption in transit (TLS), hashed credentials, access controls and least-privilege permissions, logging and monitoring, and regular backups. No system is completely secure; if we become aware of a security incident that may cause significant risk or damage to you, we will notify you and the ANPD as required by Article 48 of the LGPD.
9. Cookies and analytics
Our website uses essential cookies (session, authentication, security) that are necessary for it to work, and, with your consent, analytics cookies that help us understand how the site is used. You can manage non-essential cookies through your browser settings or the cookie banner. The MCP server and API do not use cookies; they authenticate Requests through API keys or tokens.
10. Your rights
Under Article 18 of the LGPD you may, at any time and free of charge, request:
- confirmation that we process your personal data and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD;
- portability of your data to another provider, subject to ANPD regulation;
- information about the public and private entities with which we have shared your data;
- information about the possibility of not giving consent and the consequences of refusal;
- withdrawal of consent and deletion of data processed on that basis;
- review of decisions taken solely on the basis of automated processing.
To exercise these rights, contact our Data Protection Officer using the details in Section 13. We may ask you to verify your identity before responding, and we will reply within the time limits set by the ANPD. You may also lodge a complaint with the ANPD.
11. Children
The Service is intended for professionals and businesses and is not directed to anyone under 18. We do not knowingly collect personal data from minors; if you believe a minor has provided data to us, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, in the law or in our practices. The current version is always available with its effective date. Material changes will be announced through the Service or the contact channels on your account before they take effect.
13. Contact and Data Protection Officer
Fernando Souza (Data Protection Officer / Encarregado): privacidade@urbit.com.br
URBIT SERVIÇOS DE INFORMÁTICA LTDA — CNPJ 31.687.326/0001-62 Av. Paulista, 509 – Sala 1513, Bela Vista, São Paulo – SP, Brazil
General support: contato@urbit.com.br