Data and your choices
Privacy
This page explains what the hosted Bleavit Foresight service stores, why it is used, and how you can delete it.
Information processed
The service receives the content in your explicit tool calls, which may include forecast questions, selected units, definitions, resolution sources and criteria, background information, and news. It also processes the record ID and timestamps needed to continue and expire a workflow. The MCP service does not request the full chat transcript. Your ChatGPT or Codex client may process conversation content under its own privacy terms.
Purposes and legal bases
We use submitted content to provide the workflow you request, including validating, rendering, storing, retrieving, and deleting forecast specifications. Where the GDPR applies, we rely on the performance of our service agreement for this processing (Article 6(1)(b) GDPR). We and Cloudflare may process technical request and error information to operate, troubleshoot, and protect the service. Where the GDPR applies, our legal basis for this security and reliability processing is our legitimate interest in maintaining a secure and available service (Article 6(1)(f) GDPR). We do not use submitted content for advertising, analytics, profiling, or model training.
How information is used and stored
Submitted information is used to validate, render, and continue your forecast specification. The hosted service stores records in a Cloudflare Worker and D1 database. It does not require a user account; the record ID acts as a bearer reference, so anyone who obtains it can access or update that record until it expires or is deleted.
Service providers
Cloudflare provides the Worker and database infrastructure and may process connection, request, and error metadata to operate and secure that service. The Worker code does not put forecast content or record IDs into its error messages. The D1 database was created with an Eastern Europe (EEUR) location hint; Cloudflare says a location hint does not guarantee an exact location or restrict all processing to that region. The Worker runs on Cloudflare’s global network. Cloudflare may process personal data in other countries under its data processing terms and applicable transfer safeguards. See Cloudflare’s Data Processing Addendum.
ChatGPT or Codex routes your explicit tool calls to the MCP endpoint; its handling of the conversation and account data is governed by that provider’s own terms and privacy information. If you choose to post a non-sensitive bug report on the public GitHub issue tracker, GitHub processes that information and the report is publicly visible. Do not post forecast content, record IDs, credentials, or personal information there.
Retention and controls
A record expires 30 days after its most recent update. It becomes
inaccessible at expiry and is removed by an hourly cleanup; an access
request also removes an expired record. You can ask the MCP service to
delete an active record immediately with
delete_forecast_specification, providing its record ID.
Deletion is permanent. Keep the ID private, and do not submit secrets
or sensitive information.
Cloudflare also handles technical connection and invocation information. Its Workers Logs retention depends on the account plan and settings; Cloudflare currently documents a maximum of three days on its Free plan and seven days on its Paid plan. Support emails are kept for as long as needed to respond and to meet applicable legal requirements.
Your rights
Where the GDPR applies, you may have the right to request access to, correction or deletion of your personal data, restriction of processing, and a copy of data you provided. You may object to processing based on legitimate interests. To exercise a right or ask a privacy question, email [email protected]. We may ask for information needed to verify and handle your request. You may also lodge a complaint with a data protection supervisory authority, including the Hamburg Commissioner for Data Protection and Freedom of Information, or the authority where you live or work.
Controller and privacy contact
The controller for personal data processed by Bleavit Foresight is Christopher Maximilian Altmann, c/o IP-Management #9993, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany. For privacy questions or requests, email [email protected].
Contact
For general questions, see Support. Do not include forecast content, record IDs, or other private information in the public issue tracker.