Legal

Privacy Policy

Context Layer connects authorized Jira, Confluence, and GitHub resources to an MCP client.

Last updated: 13 August 2026

What we store

  • Your Context Layer account name and email address.
  • Your workspace membership, role, and configuration.
  • Selected Jira projects, Confluence spaces, or GitHub repositories and connection status.
  • Encrypted Atlassian OAuth access and refresh tokens.
  • MCP client consent records, hashed OAuth credentials, personal token hashes, and MCP activity records.

Provider identity

Context Layer does not store provider account IDs or profile names. Identity tools retrieve that information from the provider when invoked and return it directly to the MCP client.

Content handling

Read tools return requested Jira, Confluence, and GitHub content to the MCP client. Write tools send content from the MCP client to the selected provider. Context Layer does not store that content in its database.

Retention and security

Disconnecting an integration clears its stored OAuth credentials. Other account, workspace, configuration, and activity records remain in the database until the service operator removes them. Invitation, MCP personal tokens, and MCP OAuth credentials are stored as SHA-256 hashes. Integration-provider OAuth credentials are encrypted with AES-256-GCM. Revoking a connected MCP client removes its outstanding access and refresh credentials.