Privacy policy
Privacy
Plain language. What we collect, where it lives, how to get it deleted. Last updated 2026-05-19.
What we collect
- Account: email, organization name, the IP address of your sign-in.
- Workspace: the prompts you send to the generator, the generated server specifications, build logs, server names and slugs you choose.
- Tool-call metrics: counts, latencies, status codes — never the request or response payloads. We only know that a tool was called, how long it took, and whether it succeeded.
- Billing: Stripe customer id + subscription metadata for paid plans. Card details never touch our servers.
What we do NOT collect
- Plaintext credentials. Every secret you save is AES-256-GCM encrypted before it hits storage. We have no ability to read them; only your container at runtime can.
- Tool-call payloads. The arguments your AI client sends and the responses our server returns are not stored or logged.
- Browsing data, cross-site tracking, advertising identifiers.
Where it lives
- EU region by default (Hetzner Falkenstein, Germany).
- Postgres + Redis + container hosts are all in the same region.
- Backups encrypted at rest in Backblaze B2 EU.
Subprocessors
- Anthropic, USA (Claude AI — used for prompt analysis and code generation on Pro / Team / Enterprise tiers). Only the prompt text and resulting spec are sent. Anthropic's data-retention policy applies.
- Zhipu AI, China (GLM model — used for prompt analysis on the free Hobby tier only). Only the prompt text and resulting spec are sent. Upgrade to a paid tier to keep all AI processing within Anthropic (US).
- Stripe Payments Europe Ltd., Ireland (billing, invoicing, payment processing, automatic VAT). Stripe receives: email, billing address, payment method details. Card numbers are tokenised by Stripe and never reach our servers. Stripe is GDPR-compliant and Swiss-DSG-aligned via the EU-Swiss adequacy decision.
- Hetzner, Germany (compute, Postgres, Redis, runner containers).
- Backblaze, EU (encrypted backups).
- Cloudflare (DNS + DDoS protection + TLS termination).
AI processing per tier
- Hobby (free): prompts are sent to Zhipu AI (GLM, China) for analysis. Choose a paid tier if your prompts contain data that must not leave the EU/US.
- Pro: prompts are sent to Anthropic (Claude Haiku 4.5, USA).
- Team: prompts are sent to Anthropic (Claude Sonnet 4.6, USA).
- Enterprise: Anthropic (Claude Sonnet + Opus, USA) with EU-data-residency opt-in available on request.
Retention
- Active account: all workspace data kept while subscribed.
- Cancelled account: 30-day grace period, then full deletion (servers, builds, logs, audit).
- Audit log: 1 year on Team+, 30 days on Pro/Hobby.
- Tool-call metrics: 30 days, then aggregated to daily counts.
Your rights (GDPR)
- Access — export everything in JSON via the settings page (Sprint 4) or by email.
- Deletion — delete your organization in settings; everything goes within 30 days.
- Rectification — change name and email yourself; everything else is editable on request.
- Portability — the generated TypeScript source of every server is yours, downloadable.
Contact
Data controller: BuildMyMCPServer. Email [email protected] for any of the above.