B"H · Awtsmoos Shliach · Jacob Kaufer
Privacy Policy
Effective October 1, 2026. This policy covers Awtsmoos Shliach (Agent) and its Awtsmoos OAuth, MCP and tunnel integration. The publisher and contact responsible for this plugin is Jacob Kaufer. Other Awtsmoos website features have separate website privacy information.
Data used by the integration
- Account and authorization: account identifiers, OAuth client identifiers, requested and granted scopes, resource/audience identifiers, consent and token records. The host receives access credentials from the OAuth exchange. Server refresh-token records store a hash of the refresh token along with account, client, scope, timestamps and revocation state.
- Device and task information: device/tunnel identifiers, availability and capability information, selected paths, action names and parameters, file contents or command/browser results requested through authorized actions.
- Saved work: plans, prompts deliberately appended to plans, checklists, mission summaries, project paths, status and operational history. Plans are durable records, not temporary chat-only text.
- Operational information: request timing, network address information available to the web infrastructure, usage counts, bytes, success/error results, Peruta credit balances and usage-ledger entries, and security audit records. Conversation-event records can include action names, paths or URLs, summaries and preview links.
- Support: the contact form requests name, email, subject and message. Its implementation forwards accepted messages through the configured email service and may persist a reference, timestamp and network-address hint.
Why it is used
The integration uses this information to authenticate you, check permissions, route your requested actions, return results, coordinate saved work, troubleshoot failures and protect the service. Only use it for data you are permitted to access and share. A request to read a private file can send that file's contents back to your AI host.
Where information goes
Requests and responses pass between your AI host, Awtsmoos.com infrastructure and the selected device or application. Returned tool data becomes available to the AI host and may appear in the conversation. OpenAI handles its own services under its privacy policy; this policy does not control that host's retention or model-data settings. Hosting, network and email services process information needed to operate those services. Browser or command actions can contact other destinations you request, whose policies also apply.
Private task results are not automatically made into public website posts by the MCP transport. Explicit publishing, sharing, preview and application-write actions can expose content according to the selected operation and permissions. Do not request a public preview of private material.
Retention and deletion
Retention depends on the kind of record. Authorization codes are one-time, memory-held records with a 15-minute validity window. Refresh-token records have a 30-day validity period; expiration or revocation does not itself erase the persisted record. Short-lived response blobs default to 5 minutes and are capped at 15 minutes. Pageable temporary results default to 30 minutes and are capped at 3 hours. Expired temporary entries are cleaned when the respective stores are accessed.
Current conversation-history storage is bounded to 30 conversations per user and 100 events per conversation; the tunnel-security audit list is bounded to 5,000 records. These are size limits, not guaranteed deletion deadlines. Plans and other durable mission records remain in their underlying store until removed. This implementation does not provide one automatic time-based deletion schedule for all account, audit, support and backup records.
You can disconnect the plugin in your AI host and stop or restrict your device agent to prevent further use of that connection. Disconnecting does not erase earlier results in chat, existing mission records or copies you created. Device-side plan removal and other deletion actions must follow the current schemas and account permissions. For access, correction or deletion requests concerning server-held plugin data, contact Jacob Kaufer through the Awtsmoos contact form, identify the account and record category, and never include credentials. Identity and authority may need verification. No unverified deletion deadline or backup-erasure guarantee is promised here.
Security and your choices
The remote MCP endpoint uses HTTPS and OAuth bearer authorization bound to its protected resource. Authorized actions remain subject to scopes, ownership and device checks. HTTPS protects transport; it is not a statement that every stored record is encrypted at rest. Protect your accounts, grant only the access you intend, keep the agent updated and avoid sending secrets or unrelated personal data in prompts or support messages.
Updates and contact
Policy updates will carry a revised effective date on this page. Use plugin support for questions about these practices.