Privacy Policy.
Last updated: May 2026. This policy explains what data Roost Hosting collects, why, and how we protect it — including data processed by our AI assistant and MCP server features.
1. Who we are
Roost Hosting LLC ("Roost Hosting", "we", "us", "our") is a limited liability company registered in the State of Wyoming, USA. We operate roosthosting.com and the client panel at app.roosthosting.com. We are the data controller for personal data processed through these services.
Contact: privacy@roosthosting.com
2. What we collect
We collect the following categories of personal data:
- Account data: name, email address, billing address, phone number (optional).
- Payment data: processed via Stripe or PayPal. We do not store card numbers, CVV, or raw payment instrument data. Stripe stores payment method tokens on our behalf subject to their privacy policy.
- Service data: server configurations, domain names, IP addresses assigned to your services, OS and software choices.
- Usage data: login timestamps, IP addresses, browser and device information, actions taken in the panel — used for security and fraud prevention.
- Support data: content of support tickets you submit.
- Communications: emails we send you (invoices, service notifications, support replies). We log metadata for our records; body content is retained per section 6.
- AI interaction data: see section 2a below.
- MCP token data: see section 2b below.
2a. Roost AI — data processed by the panel assistant
When you use the Roost AI assistant, the following data is sent to the AI inference API for the purpose of generating a response:
- Contextual server data: the name, IP address, resource metrics (CPU, RAM, disk usage), and current status of the service you are viewing in the panel at the time of the request.
- Your query text: the message you type into the AI chat field.
- Conversation history: prior messages from the current session window, to provide contextual responses.
- Log excerpts: when you or the assistant explicitly triggers a log-read action, relevant log lines from your server are included in the request payload.
Inference provider: By default, Roost AI routes requests through Anthropic's Claude API (Anthropic PBC, San Francisco, CA, USA). Anthropic processes your query under their API Terms of Service and Privacy Policy. Roost Hosting does not use your AI queries to train models. Anthropic's API-level data handling terms apply; Anthropic does not use API data to train their models per their posted API policy.
Bring Your Own Key (BYOK): If you supply your own Anthropic API key, requests are sent directly to Anthropic's API using your key. Your key is stored encrypted at rest. Only the last-used timestamp is surfaced in the panel UI. You are the data controller for those requests; Anthropic's terms apply directly between you and Anthropic.
Retention: We do not persist AI conversation content beyond your active browser session. Server context snapshots used to populate requests are not stored separately. Anthropic's own retention policy governs data on their side.
Do not input: passwords, private keys, credit card numbers, government ID numbers, or health data into the AI chat. The assistant does not need this information and it would be transmitted to the inference provider.
2b. MCP server — data accessible via token
The Roost MCP (Model Context Protocol) server allows external AI clients (such as Claude Desktop, Cursor, or other MCP-compatible tools) to query your hosting account data programmatically.
- MCP tokens: stored as hashed values in our database. The plaintext token is shown once at creation and cannot be retrieved thereafter. You can revoke tokens at any time from Profile → AI Keys.
- Data accessible via MCP: service list, service status, resource metrics, recent log lines, domain list, and account credit balance. Payment instrument details and personal account data are not exposed via the MCP interface.
- Third-party MCP clients: when you connect Claude Desktop, Cursor, or another MCP client, data returned by the Roost MCP server is processed by that client application under its own privacy policy. Anthropic's privacy policy governs data processed by Claude Desktop. We are not responsible for how third-party clients handle data they receive from our MCP server.
- Your responsibility: treat MCP tokens like passwords. Do not share them in public repositories, forums, or screenshots. Revoke and regenerate tokens if you suspect compromise.
3. Why we collect it (legal basis)
- Contract performance: To provision and maintain the services you purchase, send invoices, and process payments.
- Legitimate interests: Security monitoring, fraud prevention, product improvement, and abuse prevention — balanced against your privacy interests.
- Legal obligation: Retaining financial records for the period required by applicable law (typically 7 years in the USA).
- Consent: Marketing emails, if you opt in. You can withdraw at any time without affecting your service.
4. How we use your data
We use your data to:
- Create and manage your account and services
- Process payments and issue invoices
- Send transactional emails (invoices, service notifications, password resets)
- Respond to support tickets
- Detect and prevent fraud and abuse
- Power the Roost AI assistant and MCP server features as described in section 2a and 2b
- Comply with legal obligations
We do not sell your personal data. We do not use your data for third-party advertising.
5. Who we share data with
We share data only with the following categories of third parties:
- Payment processors: Stripe (Stripe Inc., USA) and PayPal (PayPal Holdings Inc., USA) for payment processing. Each has their own privacy policy and acts as an independent data controller for payment data.
- AI inference — Anthropic: When using Roost AI with the shared key, query data and server context described in section 2a is sent to Anthropic PBC as a data processor acting on our behalf. Anthropic processes this data to provide inference results.
- Infrastructure providers: The data centres and cloud providers where your services are hosted. These providers have access only to infrastructure-level data necessary to operate the physical or virtual hardware.
- Email delivery: SMTP/transactional email providers used to deliver service notifications and invoices.
- Analytics: Aggregate, anonymised analytics only. No individual-level data is shared with analytics vendors.
- Legal authorities: Where required by a valid US court order, subpoena, or applicable law, or to protect our legal rights, property, or the safety of our users.
6. Data retention
- Account data: retained while your account is active. Deleted within 90 days of verified account closure, except where legal retention applies.
- Financial records (invoices, transactions): retained for 7 years as required by US tax and accounting laws.
- Activity logs: 2 years.
- Support tickets: 3 years after closure.
- Email body content: 90 days, then body is deleted; metadata (timestamps, recipient) retained per activity log schedule.
- AI conversation content: not retained beyond the active browser session (see section 2a).
- MCP token hashes: retained until you revoke the token, then deleted within 30 days.
7. Your rights (GDPR / EEA and UK)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the GDPR or UK GDPR:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your data, subject to legal retention obligations.
- Portability: Receive your account and service data in a structured, machine-readable format.
- Restriction: Request that we limit processing of your data pending resolution of a dispute.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is consent-based, withdraw at any time without affecting prior processing.
International transfers: Roost Hosting LLC is based in the United States. If you are in the EEA or UK, your data is transferred to and processed in the USA. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for these transfers. You may request a copy of applicable SCCs by emailing privacy@roosthosting.com.
To exercise any of these rights, email privacy@roosthosting.com. We will respond within 30 days (extendable by 60 days for complex requests with notice).
You also have the right to lodge a complaint with your local data protection authority.
8. Your rights (CCPA — California residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you additional rights:
- Know: The categories of personal information we collect, the purposes for collection, and the categories of third parties we share it with (see sections 2 and 5).
- Delete: Request deletion of personal information we have collected, subject to legal exceptions.
- Correct: Request correction of inaccurate personal information.
- Opt out of sale or sharing: We do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm.
- Non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request: privacy@roosthosting.com. We will respond within 45 days.
9. Cookies
We use cookies to maintain your session, prevent CSRF attacks, and remember preferences. See our Cookie Policy for full details including a category-by-category breakdown.
10. Security
We use industry-standard security measures: HTTPS/TLS for data in transit, encryption at rest for sensitive fields (including stored API keys), bcrypt for password hashing, and two-factor authentication. MCP tokens are stored as hashed values. We conduct periodic security reviews. We cannot guarantee absolute security, but we take commercially reasonable steps to protect your data and will notify affected users of confirmed data breaches as required by applicable law.
11. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes via email at least 14 days before the change takes effect. The current version is always available at roosthosting.com/privacy.
12. Contact
For privacy-related questions, data requests, or to exercise your rights: privacy@roosthosting.com
Roost Hosting LLC