{
  "markdown": "<p align=\"center\">\n  <img src=\"./assets/logo.png\" alt=\"Tuteliq\" width=\"200\" />\n</p>\n\n<h1 align=\"center\">Tuteliq MCP Server</h1>\n\n<p align=\"center\">\n  <strong>MCP server for Tuteliq - AI-powered child safety tools for Claude</strong>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@tuteliq/mcp\"><img src=\"https://img.shields.io/npm/v/@tuteliq/mcp.svg\" alt=\"npm version\"></a>\n  <a href=\"https://github.com/Tuteliq/mcp/blob/main/LICENSE\"><img src=\"https://img.shields.io/github/license/Tuteliq/mcp.svg\" alt=\"license\"></a>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://docs.tuteliq.ai\">API Docs</a> •\n  <a href=\"https://tuteliq.ai\">Dashboard</a> •\n  <a href=\"https://trust.tuteliq.ai\">Trust</a> •\n  <a href=\"./CHANGELOG.md\">Changelog</a> •\n  <a href=\"https://discord.gg/7kbTeRYRXD\">Discord</a>\n</p>\n\n---\n\n## What is this?\n\nTuteliq MCP Server brings AI-powered child safety tools directly into Claude, Cursor, and other MCP-compatible AI assistants. Ask Claude to check messages for bullying, detect grooming patterns, or generate safety action plans.\n\n**Reads context, not just keywords.** Every detector understands coded slang, emoji, leetspeak, algospeak, and deliberate filter evasion, and weighs the conversation around a message — so it tells gaming trash-talk apart from targeted harassment instead of drowning your team in false positives. This coded-language resilience is platform-wide (it applies to grooming, fraud, radicalisation, and the rest, not just bullying) and is built from our own research into how bad actors evade moderation. In an internal benchmark of coded-language and filter-evasion cases, Tuteliq detected roughly **1.7x more** of them than leading general-purpose moderation APIs (319-case evasion set; vendors unnamed).\n\n**Fast mode.** Pass `verdict_only: true` on `detect_grooming` or `detect_bullying` to get just the verdict (risk level, flags, recommended action) without the per-message breakdown — lower latency for real-time screening. The verdict itself is unchanged.\n\n**Interactive results.** In hosts that support MCP Apps, results render as interactive cards rather than walls of JSON — see [Interactive widgets](#interactive-widgets) below.\n\n## Interactive widgets\n\nTwelve widgets return a rendered card instead of raw text in hosts that support MCP\nApps (Claude desktop and web, and other MCP-compatible clients). Everywhere else\nthe same data arrives as `structuredContent`, so nothing depends on the UI.\n\nEvery card carries the same frame: a chrome bar naming the tool that produced the\nresult, the result itself, and a footer with the data-handling note and a Trust\nCenter link. In a transcript holding a dozen results, the chrome bar is what tells\nyou which is which.\n\n| Widget | Tools |\n|--------|-------|\n| Detection result | `detect_bullying`, `detect_grooming`, `detect_unsafe`, `analyze`, and the other `detect_*` tools |\n| Multi-endpoint | `analyse_multi` |\n| Emotions | `analyze_emotions` |\n| Media | `analyze_voice`, `analyze_image`, `analyze_video`, `analyze_document` |\n| Synthetic media | `detect_synthetic_text`, `detect_synthetic_image`, `detect_synthetic_audio`, `detect_synthetic_video` |\n| Action plan | `get_action_plan` |\n| Incident report | `generate_report` |\n| Incidents overview | `get_incidents_overview` |\n| Incidents list | `list_incidents` |\n| Incident detail | `get_incident` |\n| Incident trends | `get_incident_trends` |\n| Moderation queue | `moderation_queue` |\n\n**Severity is rankable by colour.** The ramp runs monotonically from safe to\ncritical, so two chips can be compared without reading their labels:\n\n| Level | Colour | |\n|---|---|---|\n| `critical` | `#9C3A29` | ![#9C3A29](https://placehold.co/12x12/9C3A29/9C3A29.png) |\n| `high` | `#C2543A` | ![#C2543A](https://placehold.co/12x12/C2543A/C2543A.png) |\n| `medium` | `#D98A3D` | ![#D98A3D](https://placehold.co/12x12/D98A3D/D98A3D.png) |\n| `low` | `#B7C2D4` | ![#B7C2D4](https://placehold.co/12x12/B7C2D4/B7C2D4.png) |\n| `safe` | `#19B79A` | ![#19B79A](https://placehold.co/12x12/19B79A/19B79A.png) |\n\n**Design notes.** The widgets are deliberately calm. They report on grooming,\nself-harm, and abuse, and a card that animates or pulses at the reader turns\nmaterial that is already distressing into an alarm they cannot dismiss. Severity\nis carried by a rule and a glyph, not by motion. The crisis-support card leads\nwith reassurance rather than the severity colour, and its helpline numbers are the\nlargest targets on the card because transcribing digits under stress is where\npeople fail.\n\nWidgets are read-only renderers by design. Selecting incidents in the list widget\nassembles the ID list for a `batch_review_incidents` call you fire yourself — the\nmutating call still goes through your host's approval step, so the\nhuman-in-the-loop stays in the loop.\n\n### Working on the widgets\n\n```bash\nnpm run preview:ui   # builds every widget against fixture data\nopen dist-preview/__preview.html\n```\n\nWidget source lives in `ui/src`. Design tokens are centralised in\n`ui/src/theme.ts`; prefer them over colour literals so the palette stays in one\nplace.\n\n## Available Tools (81 MCP)\n\n### Safety Detection\n\n| Tool | Description |\n|------|-------------|\n| `detect_bullying` | Analyze text for bullying, harassment, and gaming toxicity — including coded slang, emoji, and deliberate filter evasion, with context that tells trash-talk apart from genuine harm |\n| `detect_grooming` | Detect grooming patterns and predatory behavior in conversations |\n| `detect_unsafe` | Identify unsafe content (self-harm, violence, explicit material) |\n| `analyze` | Quick comprehensive safety check (bullying + unsafe) |\n| `analyse_multi` | Run multiple detection endpoints on a single piece of text in one call |\n| `batch_analyze` | Analyze up to 50 items in a single request — all twelve detection types (bullying, grooming, unsafe, emotions, social_engineering, app_fraud, romance_scam, mule_recruitment, gambling_harm, coercive_control, vulnerability_exploitation, radicalisation) — ideal for bulk triage |\n| `analyze_emotions` | Analyze emotional content and mental state indicators — accepts single text or full conversations |\n| `get_action_plan` | Generate age-appropriate guidance for safety situations |\n| `generate_report` | Create incident reports from conversations |\n\n### Fraud & Harm Detection\n\n| Tool | Description |\n|------|-------------|\n| `detect_social_engineering` | Detect social engineering tactics (pretexting, urgency fabrication, authority impersonation) |\n| `detect_app_fraud` | Detect app-based fraud (fake investment platforms, phishing apps, subscription traps) |\n| `detect_romance_scam` | Detect romance scam patterns (love-bombing, financial requests, identity deception) |\n| `detect_mule_recruitment` | Detect money mule recruitment tactics (easy-money offers, bank account sharing) |\n| `detect_gambling_harm` | Detect gambling-related harm indicators (chasing losses, concealment, distress) |\n| `detect_coercive_control` | Detect coercive control patterns (isolation, financial control, monitoring, threats) |\n| `detect_vulnerability_exploitation` | Detect exploitation of vulnerable individuals (elderly, disabled, financially distressed) |\n| `detect_radicalisation` | Detect radicalisation indicators (extremist rhetoric, us-vs-them framing, ideological grooming) |\n\n### Voice, Image, Video & Document Analysis\n\n| Tool | Description |\n|------|-------------|\n| `analyze_voice` | Transcribe audio and run safety analysis on the transcript |\n| `analyze_image` | Analyze images for visual safety + OCR text extraction |\n| `analyze_video` | Analyze video files for safety concerns via key frame extraction (supports mp4, mov, avi, webm, mkv) |\n| `analyze_document` | Analyze PDF documents for safety concerns — per-page multi-endpoint detection with chain-of-custody hashing (max 50MB, 100 pages) |\n\n### Synthetic Content Detection\n\n| Tool | Description |\n|------|-------------|\n| `detect_synthetic_text` | Detect AI-generated text across 10 child-safety categories (synthetic CSAM, deepfake scripts, AI grooming) |\n| `detect_synthetic_image` | 6-signal forensic pipeline: vision AI, EXIF metadata, pixel stats, C2PA Content Credentials, watermarks, pHash |\n| `detect_synthetic_audio` | Dual-signal forensics: transcript + mel spectrogram vision + quantitative audio statistics |\n| `detect_synthetic_video` | 5-track analysis: per-frame vision, temporal face consistency, lip-sync correlation, spectral audio, transcript |\n\n### Identity & Age Verification\n\n| Tool | Description |\n|------|-------------|\n| `create_verification_session` | Create a session for age or identity verification — returns a URL for the user to complete the flow |\n| `get_verification_session` | Poll session status — returns full document intelligence (MRZ, barcode, authenticity, face match, liveness) |\n| `cancel_verification_session` | Cancel an active session (no credits consumed) |\n\n### Incidents & Moderation\n\nRead the incident store, triage a queue, and record moderator decisions. The\nreview tools emit signed receipts for EU AI Act Art 14 human-oversight evidence.\n\n| Tool | Description |\n|------|-------------|\n| `get_incidents_overview` | Counts by category, severity, source, status and platform over a window |\n| `list_incidents` | Paginated, filterable incident list |\n| `get_incident` | Full detail for one incident, including the risk trajectory across messages |\n| `get_incident_trends` | Incident volume bucketed by hour, day or week, split by severity |\n| `moderation_queue` | Moderator triage console: the unreviewed queue, the next item, and — optionally — your own analysis trace and recommended decision, rendered for human sign-off. Read-only |\n| `review_incident` | Record a moderator decision (confirm / downgrade / escalate / reclassify / dismiss) with a signed receipt |\n| `batch_review_incidents` | Apply one decision across many incidents in a single call |\n| `get_audit_receipt` | Fetch the signed receipt for a past inference |\n| `get_audit_logs` | Query the audit log |\n\n**The decision is the moderator's, and the card makes them take it.** The\naction buttons call `review_incident` through the host, because a moderator\nclicking \"Escalate\" *is* the human decision. They do not fire on one click:\n`review_incident` persists an override and emits a signed Art 12 audit receipt\nand requires a `reason_code`, so the button opens a reason picker and a second\nclick commits. Nothing is ever defaulted into that receipt on the moderator's\nbehalf.\n\nThe reasoning, confidence and analysis trace on the card are supplied by the\ncalling assistant and are labelled as such — an argument for a human to weigh,\nnot a Tuteliq measurement.\n\nPass `operator_name` to brand the header with the customer or team name. Omit it\nand the card is unbranded — it is never defaulted to a placeholder.\n\n### Webhook Management\n\n| Tool | Description |\n|------|-------------|\n| `list_webhooks` | List all configured webhooks |\n| `create_webhook` | Create a new webhook endpoint |\n| `update_webhook` | Update webhook configuration |\n| `delete_webhook` | Delete a webhook |\n| `test_webhook` | Send a test payload to verify webhook |\n| `regenerate_webhook_secret` | Regenerate webhook signing secret |\n\n### Pricing\n\n| Tool | Description |\n|------|-------------|\n| `get_pricing` | Get available pricing plans |\n| `get_pricing_details` | Get detailed pricing with features and limits |\n\n### Usage & Billing\n\n| Tool | Description |\n|------|-------------|\n| `get_usage_history` | Get daily usage history |\n| `get_usage_by_tool` | Get usage by tool/endpoint |\n| `get_usage_monthly` | Get monthly usage with billing info |\n| `get_usage_summary` | Get current billing-period summary (used, limits, purchased credits) |\n| `get_usage_quota` | Get real-time rate-limit status — pre-flight check before batch runs |\n\n### Policy Configuration\n\n| Tool | Description |\n|------|-------------|\n| `get_policy` | Get the account's detection policy (per-category flag/block thresholds, auto-moderation) |\n| `set_policy` | Update the account's detection policy configuration |\n\n### Policy Automation Rules\n\n| Tool | Description |\n|------|-------------|\n| `list_policy_rules` | List all automation rules (block/flag/escalate/notify/log_only on matching detections) |\n| `create_policy_rule` | Create a rule that acts automatically when detections match its conditions |\n| `get_policy_rule` | Get full detail of a single rule |\n| `update_policy_rule` | Update any subset of a rule's fields (e.g., pause with `enabled: false`) |\n| `delete_policy_rule` | Permanently delete a rule |\n| `evaluate_policy_rules` | Dry-run rules against a hypothetical detection result |\n\n### Detection Settings\n\n| Tool | Description |\n|------|-------------|\n| `get_detection_settings` | See which detection endpoints are enabled/disabled + default context |\n| `update_detection_settings` | Enable/disable endpoints, set default context |\n| `reset_detection_settings` | Reset to defaults (all endpoints enabled) |\n\n### Threat Intelligence (Business+ tier)\n\n| Tool | Description |\n|------|-------------|\n| `get_intelligence_trends` | Anonymised network-wide threat trends by endpoint/category/age/platform/geo |\n| `get_emerging_threats` | Emerging threat patterns over a recent window |\n| `get_weekly_digest` | Weekly digest: summary, top categories, notable changes |\n| `get_risk_trends` | Anonymised global risk trends |\n\n### GDPR Account\n\n| Tool | Description |\n|------|-------------|\n| `delete_account_data` | Delete all account data (Right to Erasure) |\n| `export_account_data` | Export all account data as JSON (Data Portability) |\n| `record_consent` | Record user consent for data processing |\n| `get_consent_status` | Get current consent status |\n| `withdraw_consent` | Withdraw a previously granted consent |\n| `rectify_data` | Correct user data (Right to Rectification) |\n| `get_audit_logs` | Get audit trail of all data operations |\n\n### Breach Management\n\n| Tool | Description |\n|------|-------------|\n| `log_breach` | Log a new data breach (starts 72-hour notification clock) |\n| `list_breaches` | List all data breaches, optionally filtered by status |\n| `get_breach` | Get details of a specific data breach |\n| `update_breach_status` | Update breach status and notification progress |\n\n---\n\n## Common Parameters\n\n### Context Fields\n\nAll detection tools accept an optional `context` object. These fields influence severity scoring and classification:\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `language` | `string` | ISO 639-1 code (e.g., `\"en\"`, `\"sv\"`). Auto-detected if omitted. |\n| `ageGroup` | `string` | Age group (e.g., `\"10-12\"`, `\"13-15\"`, `\"under 18\"`). Triggers age-calibrated scoring. |\n| `platform` | `string` | Platform name (e.g., `\"Discord\"`, `\"Roblox\"`). Adjusts detection for platform norms. |\n| `relationship` | `string` | Relationship context (e.g., `\"classmates\"`, `\"stranger\"`). |\n| `sender_trust` | `string` | Sender verification status: `\"verified\"`, `\"trusted\"`, or `\"unknown\"`. |\n| `sender_name` | `string` | Name of the sender (used with `sender_trust`). |\n\n#### `sender_trust` Behavior\n\nWhen `sender_trust` is set to `\"verified\"` or `\"trusted\"`:\n- **AUTH_IMPERSONATION** is fully suppressed — a verified sender cannot be impersonating an authority\n- **URGENCY_FABRICATION** is suppressed for routine time-sensitive information (schedules, deadlines, appointments)\n- Content is only flagged if it contains genuinely malicious elements (credential theft, phishing links, financial demands)\n- This prevents false positives on legitimate institutional messages (school notifications, hospital reminders, government advisories)\n\n### `support_threshold`\n\nControls when crisis support resources (helplines, text lines, web resources) are included in the response:\n\n| Value | Behavior |\n|-------|----------|\n| `low` | Include support for Low severity and above |\n| `medium` | Include support for Medium severity and above |\n| `high` | **(Default)** Include support for High severity and above |\n| `critical` | Include support only for Critical severity |\n\n> **Note:** Critical severity **always** includes support resources regardless of the threshold setting.\n\n### `analyse_multi` Endpoint Values\n\nThe `analyse_multi` tool accepts up to 10 endpoints per call. Valid endpoint values:\n\n| Endpoint ID | Description |\n|-------------|-------------|\n| `bullying` | Bullying and harassment detection |\n| `grooming` | Grooming pattern detection |\n| `unsafe` | Unsafe content detection (self-harm, violence, explicit material) |\n| `social-engineering` | Social engineering and pretexting |\n| `app-fraud` | App-based fraud patterns |\n| `romance-scam` | Romance scam patterns |\n| `mule-recruitment` | Money mule recruitment |\n| `gambling-harm` | Gambling-related harm |\n| `coercive-control` | Coercive control patterns |\n| `vulnerability-exploitation` | Exploitation of vulnerable individuals |\n| `radicalisation` | Radicalisation indicators |\n\n---\n\n## Installation\n\nTuteliq is a hosted MCP server at `https://api.tuteliq.ai/mcp`. Most clients\nshould connect with OAuth and install nothing.\n\n### Connect with OAuth (recommended)\n\nPoint the client at the URL with no credentials and sign in through the browser.\nTuteliq implements OAuth 2.1 with dynamic client registration and PKCE, so the\nclient registers itself. Nothing is pasted into a config file, and access is\nrevoked from the dashboard rather than by editing your machine.\n\n**Claude Desktop:** **Settings > Connectors**, **Add custom connector**, name it\n**Tuteliq**, URL `https://api.tuteliq.ai/mcp`, then **Connect** and approve in\nthe browser.\n\n**Claude Code, Cursor, Windsurf and other clients supporting remote servers:**\n\n```json\n{\n  \"mcpServers\": {\n    \"tuteliq\": {\n      \"type\": \"http\",\n      \"url\": \"https://api.tuteliq.ai/mcp\"\n    }\n  }\n}\n```\n\nIn Claude Code, run `/mcp` to start the sign-in if it does not open on its own.\n\n### Static token (headless and automation)\n\nOAuth needs a browser, so a CI pipeline, cron job or container cannot complete\nit. Send a token in the `Authorization` header instead, generated in the\ndashboard under **Settings > Plugins**. This is a long-lived credential: keep it\nout of version control, and prefer OAuth wherever a browser exists.\n\n```json\n{\n  \"mcpServers\": {\n    \"tuteliq\": {\n      \"type\": \"http\",\n      \"url\": \"https://api.tuteliq.ai/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer your-secure-token\"\n      }\n    }\n  }\n}\n```\n\n### stdio (clients without remote server support)\n\nFor clients that only speak stdio. This runs a local process that calls the same\nhosted API, so the tools are identical; only the transport and authentication\ndiffer.\n\n```json\n{\n  \"mcpServers\": {\n    \"tuteliq\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@tuteliq/mcp\"],\n      \"env\": {\n        \"TUTELIQ_API_KEY\": \"your-api-key\"\n      }\n    }\n  }\n}\n```\n\n---\n\n## Usage Examples\n\nOnce configured, you can ask Claude:\n\n### Bullying Detection\n> \"Check if this message is bullying: 'Nobody likes you, just go away'\"\n\n**Response:**\n```\n## ⚠️ Bullying Detected\n\n**Severity:** 🟠 Medium\n**Confidence:** 92%\n**Risk Score:** 75%\n\n**Types:** exclusion, verbal_abuse\n\n### Rationale\nThe message contains direct exclusionary language...\n\n### Recommended Action\n`flag_for_moderator`\n```\n\n### Grooming Detection\n> \"Analyze this conversation for grooming patterns...\"\n\n### Quick Safety Check\n> \"Is this message safe? 'I don't want to be here anymore'\"\n\n### Emotion Analysis\n> \"Analyze the emotions in: 'I'm so stressed about school and nobody understands'\"\n\n### Action Plan\n> \"Give me an action plan for a 12-year-old being cyberbullied\"\n\n### Incident Report\n> \"Generate an incident report from these messages...\"\n\n### Voice Analysis\n> \"Analyze this audio file for safety: /path/to/recording.mp3\"\n\n### Image Analysis\n> \"Check this screenshot for harmful content: /path/to/screenshot.png\"\n\n### Webhook Management\n> \"List my webhooks\"\n> \"Create a webhook for critical incidents at https://example.com/webhook\"\n\n### Usage\n> \"Show my monthly usage\"\n\n### Synthetic Content Detection\n> \"Is this image AI-generated? /path/to/suspect-image.jpg\"\n> \"Check if this audio is a voice clone: /path/to/voice.mp3\"\n> \"Analyze this video for deepfake indicators: /path/to/video.mp4\"\n> \"Is this text AI-generated? 'The generated text to analyze...'\"\n> \"Show me the synthetic content profile for customer cust_xyz789\"\n\n### Identity & Age Verification\n> \"Create an age verification session\"\n> \"Create an identity verification session with passport as preferred document\"\n> \"Check the status of verification session abc123\"\n> \"Cancel verification session abc123\"\n\n### Fraud Detection\n> \"Check this message for social engineering: 'Your account will be suspended unless you verify now'\"\n> \"Is this a romance scam? 'I know we just met online but I need help with a medical bill'\"\n\n---\n\n## Get Started (Free)\n\n1. [Create a free Tuteliq account](https://tuteliq.ai)\n2. Go to your [Dashboard](https://tuteliq.ai/dashboard) and generate an **API Key**\n3. For Claude Desktop and other MCP plugins, generate a **Secure Token** under **Settings > Plugins**\n4. Use the API key for direct API/SDK access, or the Secure Token when connecting via MCP\n\n---\n\n## Requirements\n\n- Node.js 18+\n- Tuteliq API key\n\n---\n\n## Supported Languages (27)\n\nLanguage is auto-detected when not specified. Beta languages have good accuracy but may have edge cases compared to English.\n\n| Language | Code | Status |\n|----------|------|--------|\n| English | `en` | Stable |\n| Spanish | `es` | Beta |\n| Portuguese | `pt` | Beta |\n| French | `fr` | Beta |\n| German | `de` | Beta |\n| Italian | `it` | Beta |\n| Dutch | `nl` | Beta |\n| Polish | `pl` | Beta |\n| Romanian | `ro` | Beta |\n| Turkish | `tr` | Beta |\n| Greek | `el` | Beta |\n| Czech | `cs` | Beta |\n| Hungarian | `hu` | Beta |\n| Bulgarian | `bg` | Beta |\n| Croatian | `hr` | Beta |\n| Slovak | `sk` | Beta |\n| Slovenian | `sl` | Beta |\n| Lithuanian | `lt` | Beta |\n| Latvian | `lv` | Beta |\n| Estonian | `et` | Beta |\n| Maltese | `mt` | Beta |\n| Irish | `ga` | Beta |\n| Swedish | `sv` | Beta |\n| Norwegian | `no` | Beta |\n| Danish | `da` | Beta |\n| Finnish | `fi` | Beta |\n| Ukrainian | `uk` | Beta |\n\n---\n\n## Best Practices\n\n### Message Batching\n\nThe **bullying** and **unsafe content** tools analyze a single `text` field per request. If you're analyzing a conversation, concatenate a **sliding window of recent messages** into one string rather than sending each message individually. Single words or short fragments lack context for accurate detection and can be exploited to bypass safety filters.\n\nThe **grooming** tool already accepts a `messages[]` array and analyzes the full conversation in context.\n\n### PII Redaction\n\nEnable `PII_REDACTION_ENABLED=true` on your Tuteliq API to automatically strip emails, phone numbers, URLs, social handles, IPs, and other PII from detection summaries and webhook payloads. The original text is still analyzed in full — only stored outputs are scrubbed.\n\n---\n\n## Supported Languages\n\nTuteliq supports **27 languages** with automatic detection — no configuration required.\n\n**English** (stable) and **26 beta languages**: Spanish, Portuguese, Ukrainian, Swedish, Norwegian, Danish, Finnish, German, French, Dutch, Polish, Italian, Turkish, Romanian, Greek, Czech, Hungarian, Bulgarian, Croatian, Slovak, Lithuanian, Latvian, Estonian, Slovenian, Maltese, and Irish.\n\nAll 24 EU official languages + Ukrainian, Norwegian, and Turkish. Each language includes culture-specific safety guidelines covering local slang, grooming patterns, self-harm coded vocabulary, and filter evasion techniques.\n\nSee the [Language Support docs](https://docs.tuteliq.ai/languages) for details.\n\n---\n\n## Support\n\n- **API Docs**: [docs.tuteliq.ai](https://docs.tuteliq.ai)\n- **Discord**: [discord.gg/7kbTeRYRXD](https://discord.gg/7kbTeRYRXD)\n- **Email**: support@tuteliq.ai\n\n---\n\n## Privacy & Legal\n\nTuteliq processes content for safety analysis on behalf of the operator (the API key holder). The MCP server is a thin transport that forwards requests to `api.tuteliq.ai` over TLS — no text, audio, image, or video content is stored locally by the MCP package.\n\n| Topic | Link |\n|-------|------|\n| Privacy Policy | [tuteliq.ai/privacy](https://tuteliq.ai/privacy) |\n| Terms of Service | [tuteliq.ai/terms](https://tuteliq.ai/terms) |\n| Data Processing Agreement | [tuteliq.ai/legal/dpa](https://tuteliq.ai/legal/dpa) |\n| AI Transparency | [tuteliq.ai/ai-transparency](https://tuteliq.ai/ai-transparency) |\n| Contact | privacy@tuteliq.ai |\n\n**What is collected, used, and stored**\n\n- **Authentication:** API keys (server-side) or OAuth 2.1 access tokens (Claude / Cursor connectors). OAuth tokens are issued by `api.tuteliq.ai` and follow the standard RFC 9728 / RFC 8414 discovery flow.\n- **Request content:** text, audio, images, video, and PDFs you submit to detection or analysis tools are processed in-memory by the upstream API. Content is not retained beyond the request unless you explicitly enable history features in the dashboard.\n- **Metadata stored:** request timestamps, tool name, status, latency, and credit consumption — used for usage analytics, billing, and audit logs.\n- **PII redaction:** enable `PII_REDACTION_ENABLED=true` to strip emails, phone numbers, URLs, social handles, and IPs from stored summaries and webhook payloads. The original input is still analyzed in full; only stored outputs are scrubbed.\n- **Sub-processors and retention:** see the [DPA](https://tuteliq.ai/legal/dpa).\n- **Your rights:** the MCP exposes GDPR tools (`export_account_data`, `delete_account_data`, `record_consent`, `withdraw_consent`, `rectify_data`, `get_audit_logs`) so you can exercise data subject rights directly from your client.\n\n---\n\n## License\n\nMIT License - see [LICENSE](LICENSE) for details.\n\n---\n\n## Get Certified — Free\n\nTuteliq offers a **free certification program** for anyone who wants to deepen their understanding of online child safety. Complete a track, pass the quiz, and earn your official Tuteliq certificate — verified and shareable.\n\n**Three tracks available:**\n\n| Track | Who it's for | Duration |\n|-------|-------------|----------|\n| **Parents & Caregivers** | Parents, guardians, grandparents, teachers, coaches | ~90 min |\n| **Young People (10–16)** | Young people who want to learn to spot manipulation | ~60 min |\n| **Companies & Platforms** | Product managers, trust & safety teams, CTOs, compliance officers | ~120 min |\n\n**Start here →** [tuteliq.ai/certify](https://tuteliq.ai/certify)\n\n- 100% Free — no login required\n- Verifiable certificate on completion\n- Covers grooming recognition, sextortion, cyberbullying, regulatory obligations (KOSA, EU DSA), and more\n\n---\n\n## The Mission: Why This Matters\n\nBefore you decide to contribute or sponsor, read these numbers. They are not projections. They are not estimates from a pitch deck. They are verified statistics from the University of Edinburgh, UNICEF, NCMEC, and Interpol.\n\n- **302 million** children are victims of online sexual exploitation and abuse every year. That is **10 children every second**. *(Childlight / University of Edinburgh, 2024)*\n- **1 in 8** children globally have been victims of non-consensual sexual imagery in the past year. *(Childlight, 2024)*\n- **370 million** girls and women alive today experienced rape or sexual assault in childhood. An estimated **240–310 million** boys and men experienced the same. *(UNICEF, 2024)*\n- **29.2 million** incidents of suspected child sexual exploitation were reported to NCMEC's CyberTipline in 2024 alone — containing **62.9 million files** (images, videos). *(NCMEC, 2025)*\n- **546,000** reports of online enticement (adults grooming children) in 2024 — a **192% increase** from the year before. *(NCMEC, 2025)*\n- **1,325% increase** in AI-generated child sexual abuse material reports between 2023 and 2024. The technology that should protect children is being weaponized against them. *(NCMEC, 2025)*\n- **100 sextortion reports per day** to NCMEC. Since 2021, at least **36 teenage boys** have taken their own lives because they were victimized by sextortion. *(NCMEC, 2025)*\n- **84%** of reports resolve outside the United States. This is not an American problem. This is a **global emergency**. *(NCMEC, 2025)*\n\nEnd-to-end encryption is making platforms blind. In 2024, platforms reported **7 million fewer incidents** than the year before — not because abuse stopped, but because they can no longer see it. The tools that catch known images are failing. The systems that rely on human moderators are overwhelmed. The technology to detect behavior — grooming patterns, escalation, manipulation — in real-time text conversations **exists right now**. It is running at [api.tuteliq.ai](https://api.tuteliq.ai).\n\nThe question is not whether this technology is possible. The question is whether we build the company to put it everywhere it needs to be.\n\n**Every second we wait, another child is harmed.**\n\nWe have the technology. We need the support.\n\nIf this mission matters to you, consider [sponsoring our open-source work](https://github.com/sponsors/Tuteliq) so we can keep building the tools that protect children — and keep them free and accessible for everyone.\n\n---\n\n<p align=\"center\">\n  <sub>Built with care for child safety by the <a href=\"https://tuteliq.ai\">Tuteliq</a> team</sub>\n</p>\n",
  "bytes": 29405,
  "sha": "0901034e613d06c6f6768adde87dbf954b43e6fd91ecf0e3cb3be18fed95a993",
  "repo_slug": "tuteliq/mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_ai_tuteliq_mcp_b969de56/readme"
}