GSA Per Diem MCP privacy notice Effective September 26, 2026 What this service receives - The tool name and the parameters you or your AI client submit: city, state, ZIP code, county, travel month, number of nights, and fiscal year. These are not meant to contain personal information; do not put names, confidential acquisition details, or other sensitive information in them. - Your IP address and connection metadata, which Cloudflare processes to deliver the service. You do not need an account or API key. The service calls the GSA API with a key held by 1102tools, which is never shown to users. How it is used and who receives it - ZIP, state, and M&IE lookups for bundled fiscal years (FY2021 onward) are answered from copies of GSA's published per diem files included in the service. Nothing from those requests is sent to anyone. - City lookups, and lookups for fiscal years that are not bundled, send the city, state, ZIP code, and fiscal year to the GSA Per Diem API (api.gsa.gov, served through GSA's api.data.gov). - Cloudflare hosts the service and uses your IP address to protect it and to apply a limit of 120 requests per minute per IP address. - Your AI client receives the results and processes your conversation under its own policy. 1102tools does not sell, share for advertising, or profile any of this information. How long it is kept - Parameters and results are not written to storage or to logs. Python application logging and Worker invocation logs are disabled. - To reduce load on the government API, GSA API responses (public rate data, keyed by the requested city, state, ZIP code, and fiscal year) are kept in memory for at most 24 hours. They are deleted earlier when the service stops after 2 idle minutes, restarts, or is redeployed, or when the cache is full. - The per-IP request limit counts requests over a 60-second window. - Request pacing state holds request timing and provider cooldowns, not query content, and is deleted when the service stops. - Worker logs record only generic availability events (such as the backend being unavailable), without parameters. Cloudflare keeps them for at most 7 days. - Cloudflare may retain other operational metadata under its own privacy policy. - Support email is kept as long as needed to answer it. Your choices - For bundled fiscal years, use ZIP-code lookups if you do not want a location sent to GSA. - Because there are no accounts and query content is not stored, there is no profile to access or delete. For privacy questions or to ask that support correspondence be deleted, email james@1102tools.com. Other policies GSA privacy policy: https://www.gsa.gov/website-information/website-policies#privacy api.data.gov: https://api.data.gov/about/ Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/ Contact: james@1102tools.com