Privacy policy

Privacy

Plain language. What we collect, where it lives, how to get it deleted. Last updated 2026-05-19.

What we collect

  • Account: email, organization name, the IP address of your sign-in.
  • Workspace: the prompts you send to the generator, the generated server specifications, build logs, server names and slugs you choose.
  • Tool-call metrics: counts, latencies, status codes — never the request or response payloads. We only know that a tool was called, how long it took, and whether it succeeded.
  • Billing: Stripe customer id + subscription metadata for paid plans. Card details never touch our servers.

What we do NOT collect

  • Plaintext credentials. Every secret you save is AES-256-GCM encrypted before it hits storage. We have no ability to read them; only your container at runtime can.
  • Tool-call payloads. The arguments your AI client sends and the responses our server returns are not stored or logged.
  • Browsing data, cross-site tracking, advertising identifiers.

Where it lives

  • EU region by default (Hetzner Falkenstein, Germany).
  • Postgres + Redis + container hosts are all in the same region.
  • Backups encrypted at rest in Backblaze B2 EU.

Subprocessors

  • Anthropic, USA (Claude AI — used for prompt analysis and code generation on Pro / Team / Enterprise tiers). Only the prompt text and resulting spec are sent. Anthropic's data-retention policy applies.
  • Zhipu AI, China (GLM model — used for prompt analysis on the free Hobby tier only). Only the prompt text and resulting spec are sent. Upgrade to a paid tier to keep all AI processing within Anthropic (US).
  • Stripe Payments Europe Ltd., Ireland (billing, invoicing, payment processing, automatic VAT). Stripe receives: email, billing address, payment method details. Card numbers are tokenised by Stripe and never reach our servers. Stripe is GDPR-compliant and Swiss-DSG-aligned via the EU-Swiss adequacy decision.
  • Hetzner, Germany (compute, Postgres, Redis, runner containers).
  • Backblaze, EU (encrypted backups).
  • Cloudflare (DNS + DDoS protection + TLS termination).

AI processing per tier

  • Hobby (free): prompts are sent to Zhipu AI (GLM, China) for analysis. Choose a paid tier if your prompts contain data that must not leave the EU/US.
  • Pro: prompts are sent to Anthropic (Claude Haiku 4.5, USA).
  • Team: prompts are sent to Anthropic (Claude Sonnet 4.6, USA).
  • Enterprise: Anthropic (Claude Sonnet + Opus, USA) with EU-data-residency opt-in available on request.

Retention

  • Active account: all workspace data kept while subscribed.
  • Cancelled account: 30-day grace period, then full deletion (servers, builds, logs, audit).
  • Audit log: 1 year on Team+, 30 days on Pro/Hobby.
  • Tool-call metrics: 30 days, then aggregated to daily counts.

Your rights (GDPR)

  • Access — export everything in JSON via the settings page (Sprint 4) or by email.
  • Deletion — delete your organization in settings; everything goes within 30 days.
  • Rectification — change name and email yourself; everything else is editable on request.
  • Portability — the generated TypeScript source of every server is yours, downloadable.

Contact

Data controller: BuildMyMCPServer. Email [email protected] for any of the above.