Privacy Policy
Effective 2026-08-16. This policy covers prop-line.com, the API at api.prop-line.com, and the hosted MCP server at mcp.prop-line.com. PropLine is operated by Andy Thompson (sole proprietor, United States).
1. What we collect
Account data. When you request an API key we store your email address, the API key we issue, your plan tier and daily limit, and the time you signed up. If you arrived through a tracked link we store the referrer, the?ref= value and the first page you landed on. If you subscribe, we store your Stripe customer and subscription ids. We do not see or store card numbers — Stripe handles payment details on its own pages.
API usage. Every authenticated request writes one usage row: your API key id, the endpoint path, and a timestamp. We do not store request query strings, response bodies, or IP addresses in that log. IP addresses are used in memory for abuse throttling and are not written to the database.
Dashboard session. Signing in to the dashboard sets one session cookie. There is no third-party analytics or advertising script on the site.
Emails you send us. Support mail to support@prop-line.com is kept in our mailbox so we can answer it.
2. How we use it
- To authenticate requests and enforce your plan's limits.
- To bill subscriptions through Stripe.
- To send transactional email — your API key, receipts, payment problems, and security notices.
- To send a small number of product emails (for example, when you are near your daily cap). Every one has an unsubscribe link; one click stops all of them.
- To understand aggregate usage (requests per endpoint, signups per channel) so we can run the service. Aggregates only; we do not profile individuals.
We do not sell personal data and we do not share it with data brokers or advertisers.
3. Who processes it for us
- Fly.io (US) hosts the API, database and MCP server.
- Vercel hosts this website.
- Stripe processes payments and holds card details.
- Resend delivers our email.
- Sentry receives error reports from our servers; those may include an API key id and an endpoint path, never a key value.
- Amazon S3 stores encrypted database backups.
4. Hosted MCP server
Requests to https://mcp.prop-line.com/mcp are forwarded to the PropLine API using the API key you send in the request (or a shared demo key if you send none). The key is used for that request only and is not stored by the MCP server. Tool calls are logged as API usage exactly like direct API calls (key id, endpoint, timestamp). The content of your conversation with your AI client is never sent to us — only the tool call arguments.
5. Retention
Account records are kept while your account is active and for up to 24 months after it is deactivated, unless you ask us to delete them sooner. Usage rows are kept for operational history. Encrypted backups are kept for disaster recovery and are not used for anything else.
6. Your choices
Email support@prop-line.com to see the data we hold about you, to correct it, or to delete your account and its data. We answer within 30 days. You can rotate your API key at any time from the dashboard, and cancel a subscription from the billing portal.
7. Changes
We update this page when what we collect changes. The effective date at the top moves when we do.
8. Contact
support@prop-line.com. See also our Terms of Service.