Privacy Policy

Effective date: August 25, 2026

1. What ValuationMCP is

ValuationMCP is an MCP-native valuation application for wealth-management practices. Your AI agent connects to our MCP server, reaches into the platforms that already hold your practice data — such as your CRM, portfolio accounting system, custodian, billing tool, or general ledger — and sends the figures it finds to our application, which scores them, runs the valuation methods, and stores the result.

2. What we store

When your agent calls the upsert_practice tool, the practice figures it supplies are saved to a practice record in our database. That includes the firm name and any free-text notes your agent provides, along with the financial and operating inputs it sends:

  • Revenue (trailing 12-month), EBITDA, and EBOC (earnings before owner compensation)
  • AUM and client household count
  • Cash flow used as the DCF base year, growth rate, discount rate, and terminal growth rate
  • Revenue multiple, EBITDA multiple, EBOC multiple, and value per client
  • The firm name and any free-text notes about the firm or the data gathered

These practice records persist until you delete them. They are scoped to your account and readable only by you: access is enforced per-user at the database level, and the admin view exposes only valuation outputs and provenance summaries.

3. What else we store

  • Derived quality scores. Your agent may send raw quality metrics — for example client retention percentage, average client age, recurring-revenue share, top-10 revenue concentration, advisor tenure. We convert those to the six 0–100 quality scores our engine consumes using fixed published anchors, store the scores, and drop the raw values.
  • Provenance metadata. We record which platform or system supplied a given input — for example, "revenue from QuickBooks," "client count from Salesforce," or "AUM from BridgeFT" — so each valuation is traceable.
  • Calculated valuation outputs. We store the results produced by our valuation engine: per-method values, the blended valuation, the quality multiplier, method-level confidence, the headline asking-price estimate, and the explainability and optimization insights generated with each run.

4. What we do not have

We do not hold credentials for your external platforms. Your agent connects to those platforms through their own MCP servers or APIs using credentials you control. We cannot see and do not store those credentials.

We do not copy bulk records, files, or reports your agent reads from connected systems. Only the specific figures your agent sends to upsert_practice reach our database. Statements, transaction histories, CRM exports, position-level data, payroll files, and similar source material stay on your side.

5. Do not send client information

No client names, no account numbers, no positions. ValuationMCP has no field for client-identifying data. Nothing in the valuation asks for it, no MCP tool accepts it, and no table stores it. Client households are held as a count, never a roster — the valuation needs to know how many relationships a practice has, never who they are.

The one thing that could carry client information into the system is text you type yourself.

Do not place client names, account numbers, Social Security numbers, contact details, or any other nonpublic personal information into the notes field, the data_sources.detail field, the valuations.source_summary field, or any other input. ValuationMCP is designed to hold firm-level practice economics only. It is not designed, configured, or contracted to hold client nonpublic personal information (NPI).

If you are an investment adviser subject to Regulation S-P, the Safeguards Rule, state privacy statutes, or similar obligations, you should not route client data through this service. If you submit client information anyway, you do so at your own risk and you are responsible for that submission and for any resulting obligations.

6. Aggregated and de-identified benchmarks

Practice records and valuation outputs are stored in identified form and tied to your account. We may compute aggregate statistics across valuation runs — such as average blended multiple, median quality score, or method-level ranges — only after stripping firm-identifying fields, including the firm name, notes, user and practice identifiers, and email addresses.

We do not sell, license, or share identifiable practice records or valuation outputs with third parties. Any benchmark dataset we publish or use internally is derived from de-identified aggregates.

7. Authentication and account data

To use the MCP endpoint and save valuations, you create an account. We store your account profile (email, user ID, and role) through our authentication provider so we can authorize tool calls and show you your own history. We do not use your email for marketing unless you explicitly opt in.

8. Data retention and deletion

Practice records, derived quality scores, provenance metadata, and valuation outputs are retained while your account is active so you can review and compare past runs. From your workspace you can delete individual recorded valuations, all valuations for a practice, or the practice record itself — deleting a practice removes the stored practice inputs, its quality scores, its provenance log, and its valuations.

If you delete your account, we remove your practice records, valuations, provenance metadata, and profile data within a commercially reasonable period, except where we are required to retain data for legal or security purposes. De-identified aggregates that can no longer be linked to you may be retained.

9. Security

We use industry-standard security practices, including encrypted transport, authenticated MCP sessions, per-user row-level access control, and role-based access in the application. Practice records and valuation outputs are scoped to the account that created them.

10. Your rights

You can access, export, correct, or delete your practice records, valuation outputs, and account information through the workspace. If you need help with a request you cannot complete in the app, contact us at hnycomb.ai.

11. Changes to this policy

We may update this Privacy Policy as the product evolves. If we materially change how we handle data, we will notify you by email or through the app before the change takes effect.

12. Contact

For questions about this Privacy Policy or our data practices, contact us at hnycomb.ai.