What happens to prompts sent through OfflineCreator MCP
Trace prompt storage, moderation, cloud-provider processing, account history, and analytics exclusions.
Get practical MCP creation notesChoose the next review based on the sensitive field
If an attached image is sensitive, continue with the media-privacy review. Studio's policy says generation media remains private to the account unless the owner publishes it, while fal documents separate controls for JSON payload storage and CDN media lifecycle. If the concern is authorization rather than retention, return to the MCP security directory before allowing an agent to submit a prompt.
Follow one MCP prompt from tool call to provider
An OfflineCreator MCP prompt does not stay inside the MCP client. The client invokes a Studio generation tool, and Studio handles that request through the same cloud generation workflow used by its web app, API, and CLI. The current privacy policy says the service collects the prompt, selected settings, and source media when present. It also says that, when a generation runs, those inputs are sent to fal.ai for the selected model. The cloud provider disclosure states that the current launch catalog is routed through fal.
OfflineCreator's Terms and Acceptable Use Policy say prompts may be screened before dispatch and providers apply additional safety systems. If Studio dispatches the generation, its privacy policy identifies the provider payload as the prompt, settings, and any source media. The accessible public sources do not document a finer reservation, upload, or provider-URL sequence, so this page does not assert one.
This page follows the prompt itself rather than testing privacy slogans. For a review receipt, record five facts separately: the tool arguments sent by the client, the Studio account history created for the generation, the moderation decision before dispatch, the provider named for the selected model, and the prompt-related fields excluded from the analytics flow described by policy. That trace answers what happened to one prompt without implying that every MCP implementation uses the same storage or provider path.
- 1. MCP request
- Prompt and selected generation arguments reach StudioMCP is an interface to Studio's cloud service, not a local inference boundary.
- 2. Studio handling
- The prompt may be screened before dispatchOfflineCreator and the selected provider can apply separate safety controls.
- 3. Provider dispatch
- Send model input to falThe model input includes the prompt and applicable settings, plus source media for an image-conditioned workflow.
Separate Studio history from fal request retention
There are two retention boundaries. In Studio, the privacy policy defines prompts as generation content and says generation history and media remain until the user deletes them or closes the account, subject to short backup windows. A generation stays private to the account unless its owner explicitly publishes it to Community; publishing makes that generation's media, prompt, and settings public until it is unpublished.
At fal, current documentation says JSON request inputs and outputs are stored for 30 days by default to power provider request history. fal offers `X-Fal-Store-IO: 0` to prevent that JSON storage, but warns that this control does not remove CDN files. OfflineCreator's public policy and MCP page do not state whether Studio sends that header, so this research does not establish the effective fal payload-retention setting for a production MCP request. Neither deleting Studio history nor using fal's JSON control should be described as automatically deleting provider input CDN files.
- Studio account record
- Generation history, including its promptPolicy retention lasts until deletion or account closure, with short backup windows.
- fal JSON payload
- Documented 30-day provider defaultThe provider documents an opt-out header; OfflineCreator's public pages do not state the production setting.
- fal media objects
- A separate lifecycle and access boundaryDisabling JSON payload storage does not by itself remove uploaded or generated CDN files.
Know what moderation and analytics do with the text
Prompt screening is part of this path. OfflineCreator's Terms and Acceptable Use Policy say prompts may be screened before dispatch and that providers apply additional safety systems. fal separately documents that certain models apply content filters and that model arguments can include safety-checker or prompt-expansion controls. Those provider behaviors vary by model, so this page does not claim that every prompt is rewritten, inspected by a person, or handled by one universal provider filter.
Product measurement is a different data flow. OfflineCreator's privacy policy says first-party events can record events such as generation started or failed, and that consented Google Analytics can measure pages, sign-ups, generations, and purchases, but never prompts, uploads, generated media, or email addresses. The policy separately describes sampled API request logs as recording route, status code, key identifier, and a truncated one-way network-address hash. That field list supports this narrow policy summary; it does not prove that every operational, infrastructure, provider, or support log path excludes free text.
- Moderation
- The prompt can be screened before dispatchProvider safety behavior remains model-specific and may add another decision point.
- Product analytics
- Generation events without prompt bodiesThe policy excludes prompts, uploads, outputs, and email from consented Google Analytics.
- Sampled API audit
- Route and security metadata described by policyThis is not an absolute claim about every possible application or infrastructure log.
Evidence boundary and unresolved questions
The supported answer is narrow: Studio stores prompts as generation content in account history, may screen them before dispatch, sends prompts and applicable inputs to fal, and excludes prompt bodies from the consented Google Analytics measurements described by policy. fal documents a 30-day default for JSON request payloads and an opt-out header, but OfflineCreator's public pages do not disclose the production header. The effective provider payload-retention setting therefore remains unverified.
Community evidence is not used on this page because no retrieved item supported an OfflineCreator prompt-handling claim. The latest engine pass returned 75 items with zero relevant classifications; Reddit ended partial after rate limiting, Instagram failed with HTTP 404, and X was unconfigured. Treat those outcomes as retrieval limits, not as proof that any community was quiet. This research also did not submit a prompt, inspect a production account, or test deletion, provider retention, moderation, or analytics behavior end to end.
The decision this trace supports is whether the disclosed Studio-to-fal path is acceptable for the prompt at hand. It does not decide whether MCP is private in general or whether a local transport is local execution. Those myth-level questions belong to the prompt-privacy myths guide; this page owns the concrete OfflineCreator prompt record and processor sequence.