Privacy Policy
This Privacy Policy explains what information Mockeryn needs to operate the service and how that information is used.
Mockeryn is provided and operated by Tereshchenko Mykhailo, a sole proprietor conducting business in Poland (JDG - jednoosobowa dzialalnosc gospodarcza) ("Mockeryn", "we", "us", "our").
Contact: contact@mockeryn.com
Mockeryn lets users create projects, scenarios, endpoints, mock responses, request matching rules, runtime configuration keys, generated documentation, and request history for mock API workflows.
We collect only the information needed to provide, secure, and maintain Mockeryn:
- Account information, such as your name, email address, password hash, avatar, login provider, email verification status, and account security settings.
- Workspace information, such as teams, projects, scenarios, endpoints, mock definitions, JSON schemas, response examples, documentation outputs, and integration settings you create.
- Runtime mock data, such as request method, URL, path parameters, query parameters, headers, request body, response body, status code, timing, and matching scores when your mock endpoints are called.
- Authentication, authorization, and runtime configuration data, such as login provider identifiers, session metadata, authentication token metadata, token prefixes or identifiers, hashed or encrypted token values where implemented, IP allow/deny settings, rate-limit settings, authorization records, and runtime configuration keys used to route or configure mock API requests.
- Technical data, such as timestamps, IP address, user agent, diagnostic logs, error logs, and basic usage events needed to operate and protect the service.
- Billing data if paid plans are enabled. Payment details are handled by payment providers such as Stripe; Mockeryn does not store full card numbers.
- Support messages or feedback you send to us.
Mockeryn distinguishes between security credentials and runtime configuration keys. Security credentials, such as user API tokens, session tokens, upstream API secrets, passwords, or OAuth credentials, are used only for authentication or authorization and are not intentionally shared with other users or returned in ChatGPT/MCP tool outputs.
Project runtime configuration keys used in mock runtime URLs are not upstream API credentials and are not user account passwords or login secrets. They are Mockeryn configuration identifiers used to route, select, or configure mock API behavior. They may appear in generated runtime URLs, cURL examples, or mock configuration outputs when needed for the user to call or test a mock endpoint.
Mockeryn is a mock API tool. You should not put passwords, MFA/OTP codes, private keys, access tokens, API keys, refresh tokens, client secrets, payment card data, PCI-regulated data, protected health information, government identifiers, production secrets, or confidential third-party data you are not authorized to process into mock definitions, schemas, request payloads, headers, logs, generated documentation, or ChatGPT/MCP tool requests.
We use information to:
- create and manage your account;
- provide projects, scenarios, endpoints, mocks, request matching, documentation, and runtime mock API domains;
- show request history, telemetry, validation status, and debugging information;
- generate mock responses and documentation when you ask Mockeryn to do so;
- secure the service, prevent abuse, enforce limits, and investigate errors;
- provide support and respond to questions;
- meet legal, tax, accounting, and compliance obligations.
- We do not sell your personal data.
- We do not build advertising profiles from your workspace content.
- We do not use your mock definitions, schemas, request payloads, or generated documentation for third-party advertising.
- We do not ask for sensitive personal data to use Mockeryn.
- We do not intentionally expose user authentication tokens, session tokens, upstream API secrets, passwords, MFA/OTP codes, payment card data, or OAuth credentials in ChatGPT/MCP tool outputs.
- Mock runtime configuration keys may be included in runtime URLs or cURL examples when needed to let the user call a mock endpoint. These keys are Mockeryn configuration identifiers, not upstream API credentials or user account authentication secrets.
If you connect Mockeryn to ChatGPT or another MCP-compatible client, Mockeryn uses an MCP-only authorization flow to let that client act on your behalf inside Mockeryn.
Depending on the tool used, ChatGPT or another MCP-compatible client may send Mockeryn project, team, scenario, endpoint, and mock request names, aliases, and identifiers; endpoint URIs; HTTP methods; status codes; request matching rules; path, query, header, and body constraints; body mode; raw request bodies provided by the user; response scenarios; JSON Schemas; example JSON; generated documentation; proxy configuration metadata; and user instructions needed to complete the requested action.
Mockeryn returns tool outputs back to the connected client so the user can see the result. Depending on the tool, outputs may include project, scenario, endpoint, and mock metadata; mock definitions; preview plans; conflict information; JSON Schemas; runtime URLs; cURL examples; request history; telemetry; proxy configuration metadata; and operation results.
Some connected-client actions may create, update, delete, enable, disable, or clear Mockeryn resources when the user requests that action, including projects, scenarios, endpoints, mock requests, request history, proxy settings, and runtime configuration keys.
Mockeryn does not request the full ChatGPT conversation history. Mockeryn only receives the specific tool inputs that ChatGPT or the user sends for the selected action. We use that information only to provide the requested Mockeryn functionality. The connected client may have its own privacy policy and data practices.
Mockeryn may include optional proxy features that let users forward requests from a Mockeryn runtime endpoint to an upstream API configured by the user.
When Proxy Mode is enabled or explicitly requested by the user, Mockeryn may transmit the incoming request method, path, query parameters, path parameters, headers, request body, and related metadata to the configured upstream API. The upstream API may return response headers, response bodies, status codes, and errors back to Mockeryn.
Depending on the selected proxy mode and project settings, Mockeryn may store proxy request and response data in request history for debugging, replay, mock generation, and audit purposes. Mockeryn may apply default and user-configured sanitization rules to reduce sensitive values stored in request history, telemetry, and proxy history. Sanitization may redact common secret-like fields such as authorization headers, cookies, passwords, tokens, API keys, and client secrets. Sanitization is a safety measure, but users remain responsible for avoiding unauthorized or sensitive data in mock traffic.
Users are responsible for ensuring that they are authorized to send requests to the configured upstream API and that their use complies with that API provider's terms and privacy policy. Third-party upstream APIs process data according to their own terms and privacy practices. Mockeryn must not be used to bypass third-party API restrictions, authentication requirements, rate limits, access controls, or terms of service.
We may share information only as needed with:
- hosting, database, infrastructure, logging, email, and security providers;
- payment processors if paid plans are enabled;
- authentication providers when you use social login;
- OpenAI, ChatGPT, or another MCP-compatible client when you connect Mockeryn through the OpenAI App or another MCP-compatible client;
- third-party upstream APIs configured by you when Proxy Mode is enabled or explicitly requested;
- third-party services you choose to connect, such as documentation, project management, or source control tools;
- authorities or other parties when required by law or to protect rights, safety, and security.
We keep account and workspace information while your account is active or while it is needed to provide the service, resolve disputes, enforce agreements, or meet legal obligations. Operational records such as runtime request history, missing endpoint logs, expired authentication tokens, password reset tokens, sessions, team invites, and activity logs are also subject to automatic retention cleanup.
By default, runtime request history and missing endpoint logs are kept for up to 30 days, activity logs for up to 90 days, expired authentication and MCP tokens for a 7 day grace period, password reset tokens for up to 24 hours, and sessions and team invites for up to 30 days, unless a longer period is needed for security, abuse prevention, dispute resolution, or legal obligations.
To avoid keeping inactive account data longer than necessary, Mockeryn may notify users whose accounts have been inactive for 90 days. If the user does not sign in during the grace period stated in the notification, the account may be scheduled for deletion according to this policy. Signing in again cancels the scheduled deletion.
Deleted data may remain in backups until the backup rotation expires, usually up to 30 days. Mockeryn may keep limited deletion audit records, such as deletion timestamps, deletion reason, and hashed user identifiers, where needed to prove that deletion occurred or to prevent abuse.
Mockeryn is currently in public beta. As described in the Terms of Service, beta data may be deleted or reset. You can delete your account from Profile, Security, Delete account after confirming your current password. Account deletion removes your account and owned workspace data, subject to backup rotation and limited records we may keep for legal, billing, tax, security, abuse-prevention, or dispute-resolution purposes. You can also contact contact@mockeryn.com for account, workspace, or personal-data deletion requests.
We use reasonable technical and organizational measures to protect information, including access controls, token-based authentication, and monitoring. No online service can be guaranteed to be completely secure, so you are responsible for keeping your security credentials, account tokens, and upstream API secrets private.
Mockeryn is operated from Poland and may be accessed from other countries. Your information may be processed where we or our service providers operate, subject to appropriate safeguards where required.
Depending on your account permissions and product features, you can control your information by editing or deleting projects, scenarios, endpoints, mock requests, response scenarios, JSON Schemas, and generated documentation; clearing endpoint request history; disabling Proxy Mode; configuring or removing proxy settings; creating or deleting personal API tokens; and disabling or deleting runtime configuration keys where available. You can delete your account from Profile, Security, Delete account after entering your current password.
You can also request access, correction, export, restriction, or deletion of your personal data by contacting contact@mockeryn.com.
Mockeryn is not intended for children. If you believe a child has provided personal data to Mockeryn without appropriate consent, contact us and we will take appropriate steps.
We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the "Last updated" date.