MCP Privacy Policy

Last updated: August 2026 · Applies to the MCP server at https://mcp.bilauitmcuti.com/mcp and the public API it calls.

Overview

Bila UiTM Cuti provides a read-only public API and MCP server for UiTM academic calendar data and Malaysia public holidays. We do not require accounts or API keys for public read access. This policy describes what data is processed when you use the service or connect an AI client to our MCP endpoint.

Data we process

  • Tool arguments — when an MCP client calls a tool, we receive the JSON arguments (for example group, session, date, year, or state) and use them to query the public API.
  • IP address — used for rate limiting (500 requests per minute per IP per path) and standard server logs.
  • Request metadata — HTTP method, path, timestamps, and error codes for operations and abuse prevention.

We do not collect names, emails, or payment details through the MCP server or public API unless you contact us directly.

Third parties

The service runs on Cloudflare (Workers, DNS, and edge caching). Cloudflare may process connection metadata according to its own policies. We do not sell personal data.

Retention

Rate-limit counters are short-lived. Server logs are retained only as long as needed for security, debugging, and abuse response, then discarded or aggregated.

UiTM affiliation

This project is unofficial and not affiliated with Universiti Teknologi MARA (UiTM). Calendar data is derived from publicly available sources; verify important dates before production use.

Contact

Questions about this policy: hello@bilauitmcuti.com. See also Terms of Use and the MCP Server docs.

Canonical URL: https://docs.bilauitmcuti.com/docs/mcp/privacy