Privacy policy
This policy covers FMEPM Connect for Oracle EPM (the connector), the service that links Claude to your Oracle Cloud EPM environment. It is written in plain language. Effective September 30, 2026.
Who I am
The connector is run by FMEPM (https://fmepm.com). When this policy says "I", it means FMEPM. Questions go to support@fmepm.com.
What I collect
- Your Microsoft account identity. When you sign in with Microsoft Entra ID I receive your name, your email address, your user id and your tenant id. I use them to know who you are and which organization you belong to. I never see your Microsoft password.
- EPM connection details. The label, the EPM URL, the application name, the sign-in type, and the secret needed to sign in: a username and password for credentials connections, or Oracle OAuth tokens for Oracle SSO connections. Secrets are encrypted before they are stored.
- Tool call audit metadata. For every tool call Claude makes through the connector I record the time, the user, the tool name, the connection, the policy decision, the outcome and the error message if any. Arguments are stored with passwords, tokens and similar values replaced by "[redacted]".
- Plan and subscription data. Which plan your organization is on and, for marketplace purchases, the subscription id Microsoft gives me.
- Operational logs. Request logs with timestamps, paths, status codes and error messages. They never contain secrets.
I do not collect the content of your EPM data for my own use. Data Claude asks for is passed from Oracle to Claude in the same request and is not kept by me, apart from the audit metadata above.
How I use it
- To sign you in and keep you signed in.
- To connect to the Oracle EPM environments you configured, on your behalf, when Claude calls a tool.
- To enforce policies and plan limits.
- To show you and your organization's admins what the connector did (the audit log).
- To run, secure and improve the service, and to answer your support requests.
I do not sell your data and I do not use it for advertising.
Where it is stored
The service runs on Microsoft Azure in the Canada Central region. Data is encrypted at rest and in transit. Connection secrets are additionally encrypted by the connector with AES-256-GCM using a key held in Azure Key Vault, so a copy of the database alone is not enough to read them.
Who I share it with
Nobody, with two exceptions that exist only because you asked for them:
- Oracle EPM endpoints you configured. I send your connection secret to the EPM URL and identity domain you entered, and nowhere else, to carry out the calls Claude requests.
- Anthropic, as the MCP client you chose. Claude receives the results of tool calls, your display name, and the policy guidance. Claude never receives connection secrets. Anthropic's handling of your conversation is covered by Anthropic's own terms and privacy policy.
Microsoft acts as my identity provider and hosting provider under Microsoft's terms. I do not share your data with any other third party unless the law requires it.
Retention
- Portal sessions: 8 hours, then they expire.
- Audit log: 90 days, then entries are deleted automatically.
- Connections and their secrets: until you delete the connection. Deleting it removes the secret right away.
- Account identity and plan data: until you ask me to delete your account.
- Operational logs: 30 days.
Your rights
- You can see and delete your connections at any time on the Connections page.
- You can see your organization's audit log on the Usage page.
- You can ask me to delete your account and everything tied to it by emailing support@fmepm.com from the address you signed in with. I confirm within 30 days.
- You can ask for a copy of the data I hold about you the same way.
- You can remove the connector from Claude at any time in Claude's connector settings. That revokes Claude's access tokens; your connections stay until you delete them here.
Security
Secrets never appear in chat, in logs or in the audit log. Access tokens for Claude live one hour. Refresh tokens rotate on every use. Every tool call passes a policy check before anything is sent to Oracle. If you believe you found a security problem, email security@fmepm.com.
Changes
If I change this policy in a way that matters, I update the date at the top and tell signed-in users on the home page before the change takes effect.
Contact
Privacy and support: support@fmepm.com
Security: security@fmepm.com
FMEPM, https://fmepm.com
Effective date: September 30, 2026.