Privacy Policy

Effective date: July 7, 2026 · Applies to pcaplm.com and the PcapLM MCP connector.

What we collect

Account data. Your email address and a bcrypt hash of your password. We never store your password in plaintext.

Network captures. The pcap files you upload, and the metadata PcapLM derives from them (connections, DNS queries, HTTP requests, detection findings). Captures often contain sensitive network data — treat PcapLM as you would any analysis backend and upload only captures you are authorized to analyze.

Usage and billing data. Per-month capture counts for plan quotas, and your subscription status. Payments are processed by Stripe; your card details go directly to Stripe and never touch our servers.

Credentials for integrations. API keys and OAuth tokens for the MCP connector are stored as SHA-256 hashes only.

Server logs. Standard access logs (IP address, request path, timestamp) for security and abuse prevention.

How we use it

Solely to provide PcapLM: parsing and analyzing your captures, answering your questions about them, enforcing plan limits, and billing. We do not sell your data, use it for advertising, or share it with anyone except the processors listed below.

AI processing

When you use the chat, analyst roles, or the MCP connector's run_role tool, relevant excerpts of your capture's derived metadata (statistics, findings, query results — not the raw pcap file) are sent to Anthropic's Claude API to generate the answer. Anthropic's API terms govern that processing; Anthropic does not train models on API data by default. The structured query tools (summaries, findings, connections, DNS, HTTP) run entirely on our servers.

Third parties

We share data with exactly two processors: Stripe (payments) and Anthropic (AI responses, as described above). When you connect PcapLM to an MCP client such as Claude, tool results are returned to that client at your request — what its operator does with them is governed by their privacy policy.

Storage, retention, and deletion

Data is stored on our production servers and encrypted in transit (TLS). Uploaded captures and their derived data are retained for as long as your account exists, so you can revisit past analyses. Database backups age out on a rolling basis. You can revoke MCP API keys yourself from the Account page at any time. To delete specific captures, or your entire account and all associated data, contact us and we'll complete the deletion within 30 days.

Contact

Privacy questions, data requests, or security reports: support@pcaplm.com.