Dwellir AB ("we", "us", "our") respects your privacy and is committed to protecting it through our compliance with this policy. This policy describes the types of information we may collect from you or that you may provide when you visit our website www.dwellir.com ("Website") or use our hosted Model Context Protocol (MCP) service. It describes our practices for collecting, using, maintaining, protecting, and disclosing that information.
This policy applies where we are acting as a data controller with respect to your personal data, in other words, where we determine the purposes and means of the processing of that personal data.
This Privacy Policy complies with the Swedish Personal Data Act (SFS 2018:218), the European General Data Protection Regulation (GDPR), and other applicable laws.
Dwellir AB is the controller and responsible for your personal data.
Our full details are:
Full Name of Legal Entity: Dwellir AB
Registered Company ID: 559324-4188
Email Address: support@dwellir.com
Postal Address: Drottninggatan 2 3TR, 753 10 Uppsala, Sweden
We collect several types of information from and about users of our Website, including information:
We collect this information:
We use the information that we collect about you or that you provide to us, including any personal data:
We do not sell, trade, or otherwise transfer your personal data to outside parties. This does not include trusted third parties who assist us in operating our Website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others' rights, property, or safety.
We have implemented measures designed to secure your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Under certain circumstances, you have rights under data protection laws in relation to your personal data including the right to receive a copy of the personal data we hold about you and the right to make a complaint at any time to the Data Protection Authority, the Swedish supervisory authority for data protection issues (www.datainspektionen.se).
We reserve the right to update our Privacy Policy at any time, and we will provide you with a new privacy policy when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal data.
To ask questions or comment about this privacy policy and our privacy practices, contact us at:
support@dwellir.com
Our MCP service connects supported AI clients to your Dwellir account. You approve account access through Dwellir's authorization flow. Choose from the access levels requested by your client. You can reduce read-write access to read access.
We process connection identifiers, approved permissions, authorization tokens, and an account credential to provide this connection. These records are encrypted in the MCP service's authorization database. If you approve email access, we can return your account email to the client.
The client sends tool requests and their arguments to Dwellir. Arguments can include blockchain addresses, transaction identifiers, or API key names. Dwellir processes these requests through its account services and blockchain endpoints. Results return to the requesting client. Blockchain requests count toward your account usage. MCP key-management results contain key references, not raw API key values.
Dwellir uses PostHog's EU ingestion service to measure MCP reliability and diagnose failures. Events contain tool names, timestamps, durations, outcomes, and normalized client information. They also contain session identifiers and a hashed connection identifier. The server derives a short intent description from tool names and selected argument values. These values include RPC method names, Hyperliquid Info query types, stream subscriptions, usage intervals, and documentation paths. It does not request conversation text for analytics.
MCP analytics exclude complete tool payloads, tool responses, credentials, and raw error messages. Selected argument values enter analytics as described above. These limits apply to MCP analytics. Account services and infrastructure also process requests to provide access, measure usage, and protect the service.
Optional MCP analytics is off until you enable it for a connection. Use the analytics_preferences tool without an enabled value to inspect its setting. Set enabled to true to opt in, or false to stop future capture. Read access is sufficient to change your own setting. Opt-in expires after 30 days. A new connection starts with analytics off. Calls to this control tool are never captured. Website cookie choices do not change this server setting. Already queued events can finish uploading after you opt out. Opt-out does not delete previously captured events.
Dwellir's account provider, Outseta, supports account login. PostHog processes the MCP analytics described above. Your chosen AI client receives tool results and applies its own data practices. Dwellir does not receive your full conversation through this MCP connection.
In the active MCP database, pending login records expire after 10 minutes. Authorization codes expire after one minute, and MCP OAuth access tokens expire after 15 minutes. Refresh-token records and replay-detection records expire after 30 days. Connection records and their account credentials expire after 90 days. The service renews an account credential during use when fewer than seven days remain. Client registration records expire after 3,650 days. Analytics consent records expire after 30 days. Opt-out or OAuth revocation removes consent. The running service checks expired records for deletion every minute. These periods describe active records, not backup or analytics retention.
Revoke an agent's access in your Dwellir dashboard to stop its account access. OAuth token revocation also removes the active MCP connection record. If downstream credential removal fails, encrypted cleanup records remain for up to 90 days. The service retries that cleanup every minute while running. Revocation does not erase previous usage records or analytics events.
Contact support@dwellir.com to request access to or deletion of your MCP personal data. Include the account email and client name. Do not send passwords or authorization tokens. Account, usage, log, backup, and analytics retention also depend on the purposes in section 7.
Last updated: 1 October 2026
and join other leading Web3 companies using Dwellir's infrastructure