> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cedarai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP privacy addendum

> Supplemental privacy notice for the Cedar ARMS MCP connector, including the categories of data disclosed, recipients, retention, and user controls.

**Effective date: August 26, 2026**

This MCP Privacy Addendum (the "Addendum") is a supplemental privacy notice describing how Cedar AI, Inc. ("Cedar AI," "we," "us") handles data when an authorized user connects a third-party AI assistant to the ARMS platform through Cedar AI's Model Context Protocol ("MCP") connector at `https://mcp.arms.cedarai.com/mcp`.

This Addendum supplements, and should be read together with, the [Cedar AI Privacy Policy](https://www.cedarai.com/privacy). It does not modify, replace, or limit that policy. Where this Addendum is silent, the Privacy Policy governs. Capitalized terms not defined here have the meaning given in the Privacy Policy.

## 1. Scope

This Addendum applies only to the customer MCP connector identified above. It does not apply to the ARMS web application, the Cedar public REST APIs, or any other Cedar AI product surface, each of which is covered by the Privacy Policy.

Connecting an AI assistant to ARMS is **optional** and is initiated by the individual user. No data is disclosed through this connector unless a user signs in and issues a request.

## 2. How the connector works

* **Authentication.** Connecting requires the user to sign in with their own Cedar AI credentials over OAuth 2.0. There is no shared API key and no separate MCP-only credential.
* **Authorization.** Every request is authorized against the signed-in user's existing ARMS permissions. The connector returns only data that user is already permitted to view in ARMS. It does not widen access.
* **Read-only.** The connector registers only list, get, and search operations. It cannot create, modify, move, or delete records. Write operations remain in the ARMS user interface.

## 3. Categories of data disclosed

When a user issues a request through a connected AI assistant, we return the relevant rail operational records to that assistant. Depending on the request and the user's permissions, these records may include:

* Equipment and inventory data, including car initials and numbers, load status, and location within a terminal.
* Station, track, and network structure, including equipment counts.
* Waybill and shipment summaries, including origin and destination city and state, waybill date and number, and consignor and consignee names.
* Work orders, trip plans, and booking stops.
* Quotes, invoices, and charge records, including amounts and billing references.
* Customer and business records, including business names and the city, state, and country of their locations.
* Notes and other operational records created by platform users.

Most of this data concerns railcars, shipments, and businesses rather than individuals. However, some records are Personal Data or may contain it — for example, the name of a platform user who recorded an action, or business contact details that a user has typed into an operational free-text field.

## 4. What we minimize before returning

We reduce results before returning them to the connected assistant, so that data which is not needed to answer operational questions is not disclosed. Among other things, we remove:

* Internal record identifiers on inventory and customer results.
* Street address lines and postal or ZIP codes.
* Email addresses and telephone numbers, including telephone-qualified party identifiers on load tenders.
* The body text, highlighted snippets, author email address, and attachments of notes.
* Internal audit and approval comments and attached documents on invoices.
* Party address blocks and free-text handling and business instructions on load tenders.
* Free-text charge notes, the email address of the user who last edited a charge, and truck license plate references.

We also cap the size of inventory results, so that a single request cannot extract an entire railcar inventory.

Minimization reduces but does not eliminate the possibility that an operational record contains Personal Data. Users should treat connector output as they would any other export of ARMS operational data.

## 5. Purposes and legal basis

We disclose this data for a single purpose: to fulfill the request the user made through the assistant they chose to connect. This processing is necessary to provide the functionality of our Products, consistent with the "Purposes for Which We Process Personal Data" section of the Privacy Policy. We do not use this connector to send data for advertising, marketing, or profiling.

## 6. Recipients

The recipient of data returned through this connector is **the provider operating the AI assistant the user connects** — for example, OpenAI, where a user installs the Cedar ARMS connector in ChatGPT. Other MCP clients a user may choose, such as a desktop coding or chat assistant, are likewise recipients.

Cedar AI does not select the assistant on the user's behalf and does not send connector results to any other third party.

<Info>
  Once data is returned to a connected assistant, it is processed under **that provider's** privacy policy and terms. Cedar AI has no control over, and is not responsible for, that provider's handling of the data. Review the provider's terms before connecting, and connect only an assistant you trust with your organization's operational data.
</Info>

Cedar staff operator tools that perform writes are not part of this connector and are not available to it. They run on a separate internal path.

## 7. Retention

Cedar AI does not retain the contents of results returned through this connector as a separate record. Metadata about requests — such as the time of a call and the identity of the calling user — is retained as usage and log data under the retention periods stated in the "How Long Do We Keep Your Personal Data?" section of the Privacy Policy.

Any retention of returned data by the connected assistant's provider is governed by that provider, not by Cedar AI.

## 8. Your controls

* **Disconnect at any time.** A user can remove or revoke the Cedar ARMS connector from within the AI assistant, which immediately ends its access.
* **Permissions govern access.** A carrier administrator can change or revoke a user's ARMS permissions, which immediately changes what the connector can return for that user.
* **No write access.** Because the connector is read-only, a connected assistant cannot alter ARMS records.
* **Data subject rights.** The rights described in the "Your Rights Relating to Your Personal Data" section of the Privacy Policy apply to processing described in this Addendum. Where Cedar AI acts as a processor on behalf of a customer, requests should be directed to that customer, as described in the Privacy Policy.

## 9. Security

Requests to the connector are transmitted over TLS and authorized per request. The organizational, technical, and physical safeguards described in the "How We Secure Your Personal Data" section of the Privacy Policy apply to this connector.

## 10. Changes to this Addendum

We may update this Addendum to reflect changes to the connector or to legal requirements. When we do, we will revise the effective date above. Material changes will be handled as described in the "Changes to This Privacy Policy" section of the Privacy Policy.

## 11. Contact

Questions about this Addendum, or requests relating to your Personal Data, can be sent to [privacy@cedar.ai](mailto:privacy@cedar.ai).

## Related pages

* [Cedar AI Privacy Policy](https://www.cedarai.com/privacy) — the governing company-wide notice.
* [Acceptable use](https://www.cedarai.com/aup) — how Cedar services may be used.
* [MCP data handling](/user-docs/api-reference/mcp) — the technical description of what each tool returns and omits.


## Related topics

- [MCP data handling](/user-docs/api-reference/mcp.md)
- [API Introduction](/user-docs/api-reference/introduction.md)
