Galaxy · Updated September 29, 2026
Privacy notice
This notice covers the Galaxy plugin and its hosted MCP and authorization services at mcp.galaxymcp.org and auth.galaxymcp.org. For privacy questions, contact the service operator through the private contact form. Your Galaxy instance and AI provider have their own policies.
Information used to connect
When you connect, the authorization service processes your selected instance, Galaxy API key, account identifier, requesting client's identifier, chosen permissions and authorization records. It uses your key to verify the Galaxy account. The key and stored authorization payloads are encrypted in the broker database; the running service necessarily handles decrypted credentials to make authorized requests. The raw key is not returned to the AI client as part of the connection.
Information used for your requests
At your request, the service retrieves account details, histories, dataset metadata, selected report content, tool or workflow information, and job status, or submits authorized analyses. These requests and results pass through the laboratory AWS-hosted service in Ohio, United States, and selected content is returned to your AI provider. It does not remain exclusively in Galaxy. Tool discovery may query public Galaxy and IWC resources; URL uploads cause the selected Galaxy instance to retrieve that URL.
The broker stores connection state, not a separate archive of your research histories or reports. The AI provider can retain conversation content and tool results under its own policies. Galaxy retains uploaded data, analyses and outputs under that instance's policies.
Optional analysis notifications
If you ask a compatible client to monitor a specific existing analysis, the broker encrypts its subscription: selected site, run handle, callback address, callback signing secret, expiry and delivery state. An observed outcome includes the run name, execution status, check time and available history link, not a full report or dataset. It is sent to the verified callback supplied by your AI client. Monitoring never starts or cancels an analysis, and execution completion does not establish scientific correctness.
Each subscription lasts at most 24 hours or the underlying grant's remaining lifetime. Your client may renew it while monitoring remains enabled. Expiry stops delivery and expired live records are pruned periodically; acknowledged outcomes remain encrypted until expiry. Stop monitoring in your client, remove the authorized site or revoke the connection to remove the affected live subscriptions. A notification already in flight cannot be recalled. Encrypted recovery backups follow the retention described below.
Support and private contact
Ordinary support and site requests use GitHub Issues; your GitHub profile and posted content are public. Do not post account-specific privacy or deletion requests there. The private contact form is hosted by Google Forms and collects the reply email you enter, your message and its submission time. The publisher uses these to handle your request and follow up. Form responses are restricted to the publisher and are not shown to other respondents; new-response notifications go to the publisher's mailbox. Google processes form data under its privacy policy. The form does not require Google sign-in, allow file uploads or save unfinished responses. Do not submit credentials, sensitive datasets or full chat transcripts.
Retention
- Live connections: access tokens last 10 minutes; a connection has a fixed maximum lifetime of 30 days. Expired records stop authorizing requests and are periodically removed from the live database. Successful token revocation invalidates that grant and removes its saved credential.
- Operational logs: the service records limited request and error metadata, such as timestamps, request identifiers, method/tool names, client metadata and response codes. It is configured not to log request bodies, report content, passwords, keys or tokens. Container logs rotate by size, up to three 10 MB files per container, not by a fixed number of days.
- Recovery backups: encrypted recovery copies are maintained manually and may outlast the 30-day live connection period. They currently have no automatic time-based expiry and remain until the operator replaces or removes them. Contact us to request deletion from recovery copies as well as live records.
- Contact records: form responses, notification emails and support correspondence remain in the publisher's Google account or mailbox while needed for the request and its follow-up, or until a deletion request is completed. They have no automatic time-based expiry. You can request their deletion through the private form. Public GitHub issues follow GitHub's retention and account controls.
Your controls
You choose the connected account, instance and permitted access. Ask a connected assistant to manage Galaxy connections; it creates a private five-minute link from that plugin's current authorization. The page does not use a browser login cookie or display saved API keys, and its action tokens are one-use. A client can also revoke its access or refresh token, but simply uninstalling an app does not guarantee it sends revocation. To immediately stop any future use of a Galaxy API key, revoke it in Galaxy. To request deletion from recovery backups, use the private contact form. Disconnecting does not delete Galaxy data, AI conversations or already submitted jobs.
Scope and limitations
The public information pages have no analytics scripts or advertising. The authorization service uses cookies to complete sign-in. This is a research preview, not a clinical or regulated-data service. Do not connect data that requires protections or agreements this service does not provide. Changes to this notice will be posted here with an updated date.