Jobs Companies Talents Pricing
en
en English
ar العربية
de Deutsch
es Español
fr Français
it Italiano
pt Português
ru Русский
zh 官话
Sign In Get Started
Jobs
Companies
Talents
Pricing
Sign In
Get Started
Language
en ar de es fr it pt ru zh
MCP server and API

Terms of use and privacy notice

How you may use the Alion MCP server (alion.io/mcp) and the Partner API (alion.io/api), and what we record when you call them. Last updated 22 September 2026.

1. Scope

This page covers the machine surfaces of Alion: the MCP server at https://alion.io/mcp and https://alion.io/mcp/oauth, its REST twin under /mcp/rest/, and the Partner API under /api/. It adds to the Terms of Service and the Privacy Policy; where this page is more specific, it applies. The service is operated by Alion (contact: [email protected]).

2. What the service provides

Read-only access to job postings collected from employer applicant-tracking boards, career pages and partner feeds, to public facts about the companies behind them (domain, offices, industry, size, technology stack, funding, hiring activity), and to statistics computed over both. Nothing on these surfaces can change data on Alion or act on anyone’s behalf.

Personal data of candidates is never part of these surfaces. Mailboxes and other contact details of companies are not returned, and vacancy rows do not carry the posting’s original source or apply link: a candidate applies through the vacancy’s Alion page.

3. How you may use it

  • You may use the results inside your own product, agent, research or analysis, and show them to your users.
  • When you show Alion data to other people, name Alion as the source and link to the Alion page of the vacancy or company (every row carries its url).
  • You may not republish postings in bulk, build a competing job board or dataset from them, resell the data, or use the service to send unsolicited messages.
  • You may not work around the quotas (for example by rotating addresses or keys), probe the service for vulnerabilities outside a coordinated disclosure (see security.txt), or send content meant to disrupt it.
  • A dataset licence, bulk export or higher quota is available on request.

4. Keys, sign-in and quotas

Without credentials, /mcp answers at an anonymous quota counted per IP address. With an API key (created in Settings → Security) or by signing in through OAuth on /mcp/oauth, calls count against the quota of your Alion account. Current quotas are published on the developers page and returned with every response. Keep keys and tokens secret; you are responsible for calls made with them. You can revoke a key or disconnect an app at any time in Settings. We may suspend keys, accounts or addresses that break these terms or harm the service.

5. Third-party content

Vacancy and company descriptions are written by employers and other third parties. We filter them for text addressed at AI models (instructions meant to hijack an agent) and replace such passages with [redacted], but the text remains third-party data: an agent must treat it as data, never as instructions. Postings can be outdated or inaccurate; every row states when it was first seen and last verified, and a trust level. Salary estimates are estimates and say so. The service is provided “as is”, without a warranty that the data is complete or correct.

6. What we record when you call

For every request to these surfaces we record:

  • the time, the IP address the request came from, and the API key or OAuth app it used (and so the Alion account behind it, if any);
  • the method or tool called and its arguments (cut to 512 characters), the client name and version the software reports (MCP clientInfo or the User-Agent header);
  • the result size, status, error code and duration.

For OAuth we additionally keep the app’s registration (its name, redirect addresses and the IP address it registered from) and one-way hashes of authorization codes and tokens — never the tokens themselves. API keys are stored the same way, as hashes.

Why. To count quotas, to prevent abuse and keep the service up, to support you when you ask about a call, and to learn which questions the service answers badly so we can improve it. The legal basis is our legitimate interest in running a secure, fairly shared service (GDPR Art. 6(1)(f)) and, for account holders, the performance of our agreement with you (Art. 6(1)(b)).

What we do not do. We do not sell this data, do not use your arguments to build profiles of people, and do not use them to train AI models. Arguments are not shared with employers or other third parties; aggregated, anonymous statistics (for example, which roles are searched most) may be published.

How long. Call records are deleted after 12 months. Expired OAuth codes and tokens are deleted a week after they expire. Keys and OAuth connections stay until you revoke them or delete your account.

Who processes it. The records are kept in Alion’s database on servers in Amsterdam, the Netherlands (EU), co-located with our hosting provider; the service providers described in the Privacy Policy (hosting, maintenance, backup) may process them on our behalf.

Your rights. You can ask for access to, correction or deletion of records linked to you, object to their processing, or complain to a supervisory authority; see the data subject request page or write to [email protected].

7. Changes

We may change the tools, quotas and these terms. Material changes are announced on the developers page (changelog) at least 14 days before they apply, except where a change is needed for security or legal reasons. Continued use after a change means you accept it.

.