Regulations.gov MCP privacy notice Effective September 26, 2026 What this service receives - The tool name and the parameters you or your AI client submit: search terms, agency codes, docket, document, and comment IDs, document types, and date ranges. Search terms are free text; do not put names, confidential acquisition details, or other sensitive information in them. - Your IP address and connection metadata, which Cloudflare processes to deliver the service. You do not need an account or API key. The service calls the Regulations.gov API with a key held by 1102tools, which is never shown to users. How it is used and who receives it - Every data request sends its parameters to the Regulations.gov API (api.regulations.gov, operated by GSA's eRulemaking Program and served through api.data.gov) to retrieve public docket, document, and comment records. - Results are public Regulations.gov records. Public comments can include names, organizations, and other information that commenters chose to make public; the service passes these records through as published. - Cloudflare hosts the service and uses your IP address to protect it and to apply a limit of 120 requests per minute per IP address. - Your AI client receives the results and processes your conversation under its own policy. 1102tools does not sell, share for advertising, or profile any of this information. How long it is kept - Parameters and results are not written to storage or to logs. Python application logging and Worker invocation logs are disabled. - To reduce load on the government API, Regulations.gov responses are kept in memory for at most 15 minutes, keyed by the API request (which includes the parameters you submitted). They are deleted earlier when the service stops after 2 idle minutes, restarts, or is redeployed, or when the cache reaches its size limit. Responses over 1 MiB are not cached. - The per-IP request limit counts requests over a 60-second window. - Request pacing state holds request timing and provider cooldowns, not query content, and is deleted when the service stops. - Worker logs record only generic availability events (such as the backend being unavailable), without parameters. Cloudflare keeps them for at most 7 days. - Cloudflare may retain other operational metadata under its own privacy policy. - Support email is kept as long as needed to answer it. Your choices - Search by docket or document ID instead of free text if you do not want search terms sent to Regulations.gov. - Because there are no accounts and query content is not stored, there is no profile to access or delete. For privacy questions or to ask that support correspondence be deleted, email james@1102tools.com. To correct or remove a public comment, contact the agency that posted it; see the Regulations.gov privacy notice. Other policies Regulations.gov privacy notice: https://www.regulations.gov/privacy-notice api.data.gov: https://api.data.gov/about/ Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/ Contact: james@1102tools.com