Account information only. It is never shown to the AI client you connect, and it is kept apart from your research — which is not logged at all.
Your token is the key to the MCP: claude.ai custom connectors and ChatGPT developer mode take it in the URL; Claude Code and the rest take it as a bearer header. It is also in your welcome email. Install instructions.
No token yet. One token per address, shown once and mailed to you with setup steps — claude.ai custom connectors and ChatGPT developer mode need it in the URL; Claude Code and the rest take it as a bearer header. Install instructions.
Your MCP token. Anyone holding it can search on your subscription, so keep it off shared screens.
Header form (recommended) — this endpoint, with
Authorization: Bearer <your token>.
URL form — for claude.ai custom connectors and ChatGPT developer mode, which cannot set a header. The whole credential is in the address:
The dedicated fast index: searches run on a machine nobody else queues for, with full-text highlighted excerpts. Higher MCP limits, and semantic search when it lands.
See ProThank you.
Manage billingDelete my account: email [email protected] and it is done by hand, usually the same day. (Self-serve deletion is not built yet.)
Free, and it takes a minute. Registered visitors skip the Cloudflare checks, and your MCP token for Claude or ChatGPT is issued at the end of this.
Already have an account? Sign in instead.
You stay signed in for 30 days on this browser.
Continue with Google Continue with MicrosoftNo account yet? Create a free one.
We sent a six-digit code.
It expires in ten minutes, works once, and only in this browser. Five wrong tries void it. Send another code.
Your account is live and the Cloudflare checks are off for this browser.
Here is your MCP token. It is shown once — it is also in the welcome email we just sent you, with setup steps.
Header form (recommended) — this endpoint, with
Authorization: Bearer <your token>.
URL form — for claude.ai custom connectors and ChatGPT developer mode, which cannot set a header. The whole credential is in the address:
That address already had a token, so we did not issue a second one — two live credentials for one mailbox is how people end up with a working laptop and a broken office machine. Your connector URL is in your inbox under “Your Syfert legal research connector URL”; if it is gone, call 904-383-7448.
Privacy
Effective 10 September 2026
This site is run by one person: Graham W. Syfert, a Jacksonville, Florida attorney. There is no company behind it, no analytics department, no data broker. What follows is a plain description of what this machine actually records.
The short version. The website keeps ordinary web-server logs for fourteen days, and those logs contain search terms. The MCP connector does not log your research at all. Nothing here is sold, and nothing is shared with anyone but me.
Every request to syfert.com is written to an Apache access log: your IP address, the date
and time, the URL you asked for including its query string, the page that referred you,
and your browser's user-agent string. Search on this site happens through the URL, so
your search terms are in that log — a search arrives as ?q=... and is
stored exactly as you typed it. The logs rotate daily and the fifteenth day's copy is deleted,
so nothing survives past fourteen days. I read them for traffic, breakage and scraping, not for
people.
syf_jur — a first-party cookie holding the jurisdictions you picked, so
the navigation stays scoped as you move around. Thirty days. No identifier in it.G-SLC22YB820) runs on site pages and
sets its own cookies. Google receives page views and the device and approximate-location
information it collects, under Google's own policy. Any tracker blocker stops it and the
site works exactly the same without it.__cf_bm).There is no advertising network, no retargeting pixel, and no third-party tracker other than the two named above.
Two internal logs can capture query text: a slow-query log, which records the URL and the SQL of any database query that takes more than three seconds, and a search-fallback log. They exist so I can find the queries that break things. Website searches can land in them. Queries that arrive through the MCP are redacted from them.
The ? control in the top bar sends me a report about a page. It stores what you typed, the page you were on, your IP address, your browser string, and the basic browser diagnostics the panel shows you before you send, in a database kept outside the web root, and mails a copy to me. Those reports are not deleted on a schedule. Ask and I will delete yours.
A brief you paste or upload is read inside a sandbox, checked, and thrown away the moment the request finishes. It is not logged and not stored. One narrow exception, unchanged from the site terms: if the checker breaks in a way I cannot reproduce, I may hold a copy for up to thirty days to find out why. That is an emergency power, not a filing cabinet.
When your AI calls mcp.syfert.com, this server logs the tool name, how long the
call took, whether it succeeded or failed, your subscriber handle, and your IP address. The
content of your research — your queries, the citations you check, the documents you read
— is not logged by the MCP, and it is redacted from the search backend's diagnostic
logs. Those operational records are kept for about twelve weeks and then deleted. A running
account of a lawyer's research is a dangerous thing for anyone to hold, so this machine does not
hold one.
Activation stores the email address you type, the IP address you typed it from, and the browser details your browser volunteers, so that I know whose token is whose and can stop abuse. Your address is kept as long as your token is live. It is used to send you your access URL and, rarely, to tell you something about the service. It is not added to a marketing list, because there is no marketing list.
You can sign in to Syfert Legal Research with a Google account or a Microsoft account instead of an emailed link. When you do, the provider sends this site three things and nothing more: your email address, your name, and a numeric account identifier (Google may also send a profile-picture URL, which is discarded). That is the whole of the openid, email and profile scopes the sign-in requests. The site does not ask for, and cannot reach, your mail, contacts, calendar, files, or anything else in that account.
The email address and name are used for one purpose: to identify your account so that the same person is recognised on the website, in the MCP connector, and on the billing page. They are stored in an account record on this server together with the profile you fill in (firm, states of practice, and an optional bar number), and the sign-in creates a session cookie named syf_session on syfert.com. The provider's tokens are used once to complete the sign-in and are not stored.
Google and Microsoft account data is not shared with anyone, not sold, not used for advertising, and not used to train anything. It is kept until you delete your account, which you can do from your account page or by emailing [email protected]; deletion removes the account record, the profile, and any sessions within seven days. Billing records held by Stripe are kept as long as the law requires. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Requests from outside the countries this site serves are refused, and the refusal is recorded with the country code and the IP address. The scraper detector records events only — a user-agent fingerprint or a network range that triggered a block, never a path, never a query, never an individual reader's browsing.
I do not sell anything here, share it with partners, or build advertising profiles. Nobody sees any of it but me, except where a court leaves me no choice — and by the time anyone asks, most of it no longer exists.
Email [email protected] and say what you want removed — your MCP token and email address, an error report, whatever it is. I will remove it and tell you it is done. Server logs age out on their own inside fourteen days.
This is a research tool for lawyers and people handling their own cases. It is not directed at children under 13 and I do not knowingly collect anything from them.
If this policy changes in a way that matters, the effective date at the top changes with it, and MCP subscribers get an email about it.