Q4
ProductUse Cases
Company
Early Access
Sign inBook a Demo
Privacy

Q4 MCP privacy policy

This policy covers the Q4 Model Context Protocol connector at api.q4.sa/mcp — the sign-in flow, subscriptions, and tool calls used by Claude, ChatGPT, Cursor, and similar clients. It does not replace any separate terms that apply to the q4.sa website.

DocumentationPrivacy policycontact@q4.sa

Last updated: 6 September 2026. Controller: Q4 Intelligence. Contact: contact@q4.sa.

What the connector does

After you sign in, your AI client can call Q4 tools to look up Saudi listed companies and retrieve cited excerpts from filings, news, and earnings-call transcripts. Q4 returns text excerpts and metadata. It does not send PDF or audio file bytes through MCP.

Personal data we process

  • Account. Name, email address, and a hashed password. We do not store your password in plain text.
  • Subscription. Whether you have platform or MCP-only access, expiry, and Stream Pay subscription identifiers needed to confirm payment.
  • OAuth. The client identifier, redirect URL, PKCE challenge, and the short-lived authorization code and access token we issue. Access tokens expire after 7 days. We do not issue refresh tokens.
  • Tool requests. Queries and parameters your client sends (for example a company symbol or search phrase) so we can return results and keep the service reliable.
  • Technical logs. IP address, user agent, timestamps, and error codes generated by our hosting provider when you reach the authorize page or MCP endpoint.

Q4 does not receive your full Claude or ChatGPT conversation. We only see the tool calls the client sends to Q4 and the excerpts we return.

How we use it

  • Authenticate you and enforce an active MCP entitlement.
  • Return research results you asked the client to fetch.
  • Process MCP-only checkout through Stream Pay when you subscribe from the connector.
  • Operate, secure, and debug the service (including rate limiting).
  • Respond to support requests you send to contact@q4.sa.

Sharing

We share personal data only as needed to run the connector:

  • Your AI client (Claude, ChatGPT, Cursor, or another MCP client) receives the excerpts and citations you requested.
  • Stream Pay processes MCP-only payments. Card details are handled by Stream, not stored by Q4.
  • Infrastructure providers that host the API and database (including Vercel and our PostgreSQL host).
  • Authorities when required by applicable law.

We do not sell personal data. We do not use MCP tool queries to train third-party foundation models.

Retention

Account and subscription records are kept while your account is open and as long as we need them for billing, security, or legal obligations. Authorization codes expire in minutes. Access tokens expire in 7 days. Hosting and application logs are kept only as long as needed for operations and abuse prevention.

Security

Access to tools requires a valid token and an active subscription. Passwords are hashed. OAuth uses PKCE. We apply per-user rate limits and sanitize error responses. No method of transmission or storage is completely secure; if you believe an account is compromised, email contact@q4.sa.

Your rights

Depending on applicable law, including the Saudi Personal Data Protection Law, you may request access, correction, or deletion of your personal data, or object to certain processing. Email contact@q4.sa. We may need to verify the request and keep limited records where the law requires it.

Children

The connector is intended for professional use and is not directed at children under 18.

Changes

We may update this policy. The date at the top of the page will change when we do. The current version is always published at https://q4.sa/mcp/privacy.

Home
ProductUse CasesEarly Access
Product
TerminalMCP
Company
Careerscontact@q4.sa
Legal
Privacy PolicyTerms of ServiceLegal
© 2026 Q4. All rights reserved.