> ## Documentation Index
> Fetch the complete documentation index at: https://docs.evermuse.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & privacy

> How the Evermuse MCP server scopes access, protects credentials, and handles your data.

## Access model

* **You choose the workspace.** Every connection is bound to one Evermuse workspace, chosen on the consent screen.
  Tools can't read or write any other workspace, even ones you belong to.
* **The agent acts as you.** Tools reach only data in the workspace you authorized, and every write is attributed to
  you.
* **Access is checked on every call.** The server verifies on each tool call that you're still a member of the
  workspace, and that every product, project, source, signal or note id passed in belongs to it. Ids from another
  workspace are treated as not found.
* **Evermuse data only.** The standard tools work only on data inside Evermuse (`openWorldHint: false` on all 27). They
  don't browse the web or call third-party tools connected to your workspace. The only outbound fetch is optional:
  if you pass a recording URL to `add_source`, Evermuse downloads that file to process it. Workspaces in early-access
  programs may see additional tools, which are annotated accordingly.
* **Reads and writes are labelled.** On a standard workspace, 22 of the 27 tools are read-only. The five write tools are annotated, so your
  client can ask for confirmation before running them, and `update_signals` and `update_shaping_note` are marked
  destructive. See [Tools reference](/mcp/tools#write-tools).

## Credentials

* **OAuth 2.1 with PKCE.** Only the authorization code grant with `S256` PKCE is accepted. Redirect URIs must exactly
  match the client's registration, and dynamically registered clients may only use HTTPS or loopback redirect URIs.
* **No secrets in the browser.** Clients are public OAuth clients. You sign in on Evermuse's own pages, never inside
  the AI client.
* **Short-lived, hashed tokens.** Access tokens expire after one hour. Refresh tokens rotate on every use, and a reused
  refresh token revokes the whole token family. Evermuse stores only SHA-256 hashes of tokens, authorization codes and
  API keys, never the raw values.
* **Automatic revocation.** Removing someone from a workspace or deleting their account invalidates their tokens. Tool
  calls are refused at once, and any cached validation expires within a minute. See [Revoking access](/mcp/authentication#revoking-access) for the other options.
* **Visibility.** The first time a new application connects to a workspace, Evermuse emails you, and you can reply to
  have our team revoke it.

## Transport security

* All traffic is served over HTTPS with HSTS.
* Cross-origin browser requests are accepted only from known MCP client origins.
* Responses carry strict security headers, including a locked-down Content Security Policy.
* Rate limits apply per access token, per API key, to client registration and token requests, and per IP address. See [Limits & errors](/mcp/limits-and-errors#rate-limits).

## How your data is used

| Data | How it's used |
| - | - |
| Tool arguments (queries, ids, filters) | Used to answer the request, for example to run a semantic search over your workspace's evidence. |
| Data returned by tools | Comes from your authorized workspace and is sent only to the client that made the request. |
| Content you add | Sources added with `add_source` go through the same processing as uploads in the Evermuse app, including AI extraction of signals, and are stored in your workspace. Signals and shaping notes you write are stored in your workspace. |
| AI processing | Semantic search converts queries into embeddings, and source processing uses AI models. Evermuse uses third-party AI providers, such as OpenAI, for this. See the Privacy Policy for details. |
| Account details | Your user id, and your email only if the client requests the `email` scope, through `/oauth/userinfo`. |

Evermuse doesn't use the conversation in your AI client. The server only sees the tool calls your client sends.

## Logging and analytics

To operate and improve the service, Evermuse records:

* **Request logs:** method, full URL (including query string), status code, duration and response size for each
  request. Request bodies of MCP calls aren't logged.
* **Security events:** client registrations, authorizations, consent decisions, and token issuance, refresh and
  revocation, with the client, workspace and user ids involved.
* **Usage analytics:** for each tool call, the tool name, success or failure, duration, result size, the optional
  `workflow` label, and the MCP client's name, version and user agent, keyed to your internal user and workspace ids.
  Analytics are processed by PostHog. **Tool results, and arguments other than the `workflow` label, aren't included in
  analytics.**
* **Billing records:** the workspace, user and tool for each successful call, to meter credits.

## Content from your sources

Search results and transcripts contain text your customers and colleagues wrote. That text is returned as data. Like any
MCP tool output, it shouldn't be treated as instructions. Evermuse's tool descriptions and skills tell agents to quote and
cite evidence, not to act on it.

## Policies and contact

* [Privacy Policy](https://www.evermuse.com/privacy): what Evermuse collects, how it's processed, retention and your
  rights.
* [Terms of Service](https://www.evermuse.com/tos)
* Report a security vulnerability: [security@evermuse.com](mailto:security@evermuse.com)
* Support: [team@evermuse.com](mailto:team@evermuse.com)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.