1. Who we are
Wicket is a hosted authorization gateway for AI agents. It sits between AI agents and the external services they reach over the Model Context Protocol (“MCP”), evaluating a policy decision before each tool call reaches your upstream services and recording an audit entry of that decision.
The Wicket service is operated by Z Strike LLC, a New Jersey limited liability company, United States (“Z Strike,” “Wicket,” “we,” “us,” or “our”). This policy explains what personal data we process, why, and the rights you have. It applies to wicket.sh and its subdomains, including our application, MCP proxy, marketing site, and documentation (together, the “Service”).
2. Controller and processor roles
For data about your own account and your use of the marketing site, Wicket acts as a data controller. For data you route through the proxy on behalf of your organization — including audit records of your agents' tool calls and the service credentials you connect — Wicket acts as a data processor, processing that data under your instructions as the controller. Where you are an organization administrator, you are responsible for the lawful basis of the members and end users you onboard.
3. Personal data we collect
Account & authentication data
- Email address — used for magic-link sign-in and account communication.
- Authentication identifiers — one-time login codes, session identifiers, and, if you sign in with GitHub, your GitHub user ID and profile basics returned by OAuth.
- Member & team data — agent names, member roles (owner/member), invitation status, and tags you create.
Connected-service credentials
To proxy tool calls, you connect upstream services (e.g. GitHub, Slack, Linear, and others). The OAuth tokens for those connections are encrypted at rest with AES-256-GCM and are decrypted only in flight to forward an authorized call. We never store these tokens in plaintext.
Audit & usage metadata
For every tool call, we record an audit entry containing:
- Principal — which member made the call;
- Action — which tool, on which resource;
- Context — timestamp, source IP address, and session identifier;
- Decision — allow or deny, the matched policy rule, and latency.
Website & support data
- Waitlist / demo requests — the email address you submit.
- Contact form — the name, email address, optional company, subject, and message you submit, together with the referral and campaign parameters (e.g. UTM tags) present in the URL when you submit.
- Support communications — messages you send us and their contents.
- Technical logs — limited server and error-monitoring data (e.g. IP, user agent, error traces) used to operate and secure the Service.
- Product analytics — usage events, pages viewed, device and browser type, and approximate location (derived from IP), collected via PostHog to understand and improve how the Service is used. We run PostHog in a cookieless mode: we do not set analytics cookies or store persistent identifiers on your device, so no cookie-consent banner is required.
- Site traffic measurement — aggregate request counts, referrer, and coarse device data for wicket.sh, measured at the CDN edge by Cloudflare on our own domain. It is likewise cookieless: no analytics cookies and no cross-site identifiers.
4. What we deliberately do not collect or store
By design, the proxy sees only enough to make a policy decision and write an audit record. We do not store:
- Tool-call arguments — forwarded to the upstream service, never logged;
- Tool-call responses — returned to the agent, never persisted;
- Decrypted credentials — held in memory only during a request, never written in plaintext.
We do not use your audit data, policies, or connected-service data to train machine-learning models, and we do not pool it across customers. Each customer's data is isolated.
5. How we use personal data, and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Provide and operate the Service (authentication, policy evaluation, proxying, audit) | Performance of a contract |
| Secure the Service, prevent abuse, debug and monitor | Legitimate interests |
| Communicate about your account and beta program | Performance of a contract / legitimate interests |
| Respond to waitlist, demo, and support requests | Consent / legitimate interests |
| Measure and improve the Service through cookieless product analytics | Legitimate interests |
| Comply with legal obligations | Legal obligation |
6. Sharing and sub-processors
We do not sell your personal data. We share it only with service providers (“sub-processors”) that help us run the Service, under contracts that require appropriate safeguards. Our sub-processors as of the effective date include:
| Sub-processor | Purpose |
|---|---|
| Fly.io | Application hosting & database infrastructure |
| Cloudflare | Marketing-site hosting, CDN & traffic analytics |
| Sentry | Error monitoring |
| PostHog | Product analytics |
| Resend | Transactional & magic-link email delivery |
| Forminit | Contact, demo, and waitlist form intake |
| GitHub | OAuth sign-in (if you choose it) |
We may also disclose data to comply with law, enforce our terms, or protect the rights and safety of Wicket and others.
7. International data transfers
We are based in the United States and may process data there and in other countries where our sub-processors operate. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
8. Data retention
- Account data — kept while your account is active and deleted within a reasonable period after closure.
- Audit records — retained for the period you configure or for as long as your account is active, then deleted on request or account closure.
- Connected-service tokens — kept until you disconnect the service, revoke the connection, or close your account.
- Backups & logs — retained for a limited window for security and continuity, then expired.
9. Security
We apply technical and organizational measures appropriate to the sensitivity of the data, including AES-256-GCM encryption of connected-service tokens at rest, encryption in transit, per-customer isolation, and a member-key model in which member keys are shown once and never stored — only a one-way lookup tag is kept. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties of incidents as required by law.
10. Your rights under the GDPR / UK GDPR
If you are in the EEA, UK, or Switzerland, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure (“right to be forgotten”);
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, without affecting prior processing; and
- lodge a complaint with your local supervisory authority.
To exercise these rights, email eng@wicket.sh.
11. Your rights under the CCPA / CPRA (California)
If you are a California resident, you have the right to:
- know what personal information we collect, use, and disclose;
- request deletion of your personal information;
- correct inaccurate personal information;
- opt out of the “sale” or “sharing” of personal information; and
- not be discriminated against for exercising these rights.
We do not sell or share your personal information as those terms are defined under the CPRA, and we do not use sensitive personal information beyond the purposes permitted by law. To make a request, email eng@wicket.sh. We will verify your request consistent with the law.
12. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by an updated “Last updated” date and, where appropriate, additional notice.
14. Contact us
For privacy questions or to exercise your rights, contact Z Strike LLC at eng@wicket.sh.