WalletFollow MCP connection privacy
Effective 10 October 2026. This notice covers the WalletFollow plugin and MCP service at mcp.walletfollow.ai.
The browser connection form sends your WalletFollow API key to this service to verify access and authorize the assistant client you choose. The key is retained in encrypted OAuth grant properties in a Cloudflare Durable Object. Access and refresh tokens are stored as hashes; the assistant receives a distinct MCP token rather than your API key. Grant metadata contains a pseudonymous key identifier, selected scopes and client details.
At each tool call, the service sends the selected parameters and your key to the WalletFollow API through a private service binding. The API applies its current account restrictions, permission grants and quotas. Results, including any account records you requested, return to your chosen assistant provider. That provider’s own privacy terms also apply.
Connection grants expire after 30 days and access tokens after 10 minutes. Expired records are immediately unavailable and scheduled cleanup reclaims them. Refresh tokens are single-use and never extend the connection’s absolute lifetime. Confirmed reuse of a spent refresh token revokes the connection; if a refresh response is lost, reconnect in your assistant. You can review client names, scopes and expiry and revoke individual connections in the account API tab. Revoking an MCP connection stops its access tokens immediately; revoking or expiring the underlying API key stops upstream access through the API’s current security checks. Use a dedicated key to revoke this integration independently.
The MCP application does not log keys, cookies, tokens, request bodies or tool results. Its Cloudflare request logging is disabled. Cloudflare processes IP addresses and protocol traffic for hosting and security, and the existing WalletFollow API retains its ordinary usage/security receipts. Never put credentials or wallet private keys in prompts.
For access, deletion or privacy requests, use the operator contact process at Support. Removing the plugin from an assistant does not automatically revoke a WalletFollow API key.