TMA plugin privacy

Effective October 7, 2026. This notice supplements Tweet Media Archive’s privacy policy for this hosted MCP connection.

Connection data

You enter a dedicated TMA connector key on our consent page. The OAuth service stores it encrypted in Cloudflare KV so it can call TMA on your behalf. OAuth access tokens and authorization codes are stored as hashes. Connection metadata includes the client identifier, approved permissions, and an opaque key-derived identifier. The plugin does not receive your Google password or access to your browsing history, saved TMA library, or storage-provider accounts.

Media requests

Public URLs you submit are processed by TMA’s media services and contacted source websites. Selected media, filenames, preparation status, and expiring file links are returned to your agent. If the agent downloads a file, it receives the media bytes. OpenAI or another agent provider handles that data under its own policies. We do not request unrelated conversation history.

Retention and removal

TMA connector keys expire after 90 days. OAuth grants last at most 30 days and can be renewed by reconnecting; registration metadata can persist to support reconnection. Temporary prepared files expire after five hours and file links after at most 30 minutes. Revoke a key in Agent connections to block new requests and existing download links. Accepted work may finish before automatic expiry. Already delivered bytes cannot be recalled. Contact support for removal of connection metadata.

Infrastructure and diagnostics

The service runs on Cloudflare. Application request logging is disabled for this Worker. Cloudflare and TMA may process network and operational metadata to deliver the service, prevent abuse, and apply request limits. Credentials are not included in the public plugin package or tool responses.

Contact

For access, deletion, or support requests, contact TMA support. TMA does not sell personal information.