Who provides the service
Khimba is the publisher and service provider. Privacy, access or deletion questions can be sent to support@khimba.ai. Include the guest or account reference shown by the service where relevant, but never email secrets or source code.
Information processed
The website can process coarse interaction events such as audience route selected, installation command copied, endpoint copied, directory link clicked and documentation link clicked. Each event contains the page path, a coarse source category and an optional integration name. It contains no cookie, persistent visitor ID, full referrer, search query, prompt or source content.
The MCP service processes authentication or guest-session information, the selected model and purpose, confirmed questions and context, opinion results, token usage, charges, operational logs, and feedback a user explicitly chooses to send. Payment providers process payment details when a user buys credit; Khimba does not need the full card number.
Why and where data is processed
Data is used to authenticate requests, prepare and deliver opinions, calculate charges, prevent abuse, support users, maintain security and understand aggregate product use. Confirmed context is transmitted to Khimba’s infrastructure and the selected third-party model provider. Provider identity and pricing are shown before confirmation. Providers may process data in other countries under their applicable safeguards and service terms.
Retention
Raw source bundles are encrypted in transit and at rest and deleted after the opinion runs. Opinion records, usage and transaction records may be retained to operate the service, resolve disputes, prevent abuse and meet legal obligations. Website delivery logs are retained for up to 30 days; anonymous daily event counters are retained for up to 13 months. Support messages and explicitly submitted feedback are retained while relevant to the request and product improvement.
Choices and rights
Before inference, users can change or cancel the model, purpose and evidence. Ignore files can exclude repository paths. Users may request access, correction or deletion where applicable by contacting support. Some transaction, security and legal records may need to be retained. Users can also avoid website event submission by disabling JavaScript; all important content and installation instructions remain available.
Children, changes and limitations
The service is intended for adults and professional users, not children. We will publish material changes here and record them in the changelog. No automated filter can identify every secret or sensitive fact, so inspect the evidence manifest and avoid including unnecessary personal or confidential information.