The FlyMCP

The Fly MCP /mcp

Privacy & support

Market intelligence with clear permission boundaries

The compact /chatgpt/mcp app profile is read-only. The full /mcp profile also includes explicitly OAuth-scoped personal account tools that can change watchlists and account preferences.

Terms and privacy

Use of The Fly Content through this MCP remains subject to The Fly Terms of Use and Privacy Policy.

Content use must follow those terms, including restrictions on copying, scraping, aggregating, redistributing, or building derivative products except as authorized by The Fly.

Market content is informational only. It is not investment advice or a recommendation to buy, sell, or hold securities.

MCP/API keys authorize read-only market-data access. If you connect a personal OAuth account, OAuth-scoped personal tools can create or delete watchlists, add or remove watchlist tickers, update watchlist notifications, and enable or disable calendar and notification preferences only inside that connected account. Keys and OAuth access can be revoked from account tooling or by contacting support.

Data categories and purposes

The service processes company names, symbols, keywords, story identifiers, dates, market-brief options, screener criteria, and returned market data to run the selected tool. OAuth can additionally process account and client identifiers, verified email and profile attributes, approved scopes, consent and token-family records, expiry data, and encrypted upstream credentials. The full profile can process watchlist or portfolio identifiers and settings only when an authorized personal tool requires them.

Limited usage, security, and rate-limit metadata includes tool name and time, authentication class, scope outcome, quota state, coarse success or failure stage, allowlisted error category, HTTP status, and a random request correlation identifier. These categories are used to return requested market intelligence, authorize access, prevent abuse, meter usage, and support reliability.

Processors, recipients, and retention

OpenAI processes ChatGPT conversations, tool inputs, and returned results under the user's OpenAI settings and terms. The Fly and MSD/The Fly backend services process the tool request and market data. Microsoft Azure can provide hosting, networking, logs, and database storage; Auth0/Okta provides The Fly sign-in. Authorized support and security personnel receive limited records only when needed to operate, secure, or support the service.

Tool inputs and full result bodies are processed in transit and are not stored as an MCP conversation transcript. Azure App Service HTTP request logs are currently configured for three-day retention and contain request metadata rather than MCP tool bodies or result payloads. Upstream service or security logs may process request data under those services' configured retention and legal requirements; those copies are not part of the MCP operational-event store or its 30-day period. Sanitized operational events exclude tool arguments and result payloads and expire after 30 days. A bounded per-account history retains the 50 most recent tool-name usage events while the MCP account is active. Short-lived OAuth bridge records expire after about 10 minutes, access tokens normally after about one hour, and rotating refresh credentials normally within 30 days unless revoked sooner.

User controls

You can disconnect the app and revoke its OAuth grant, revoke API keys, delete the MCP portal account and its stored identifiers, or contact support to request access, correction, export, or deletion. Deleting the MCP portal account does not automatically delete a separate The Fly identity, OpenAI conversation, or underlying The Fly watchlist.

Support

For The Fly MCP support, contact support@thefly.com.