MCPbundler
DiscoverMCP
GitHub
MCPbundler

Privacy Policy

This policy explains what personal data MCP Bundler collects, why, and the rights you have over it under the EU General Data Protection Regulation (GDPR).
  • Who we are
  • What we collect, and why
  • Legal basis for processing
  • Storage and encryption
  • Retention
  • Sub-processors and data location
  • Cookies
  • Supervisory authority
  • Changes to this policy
  • Your rights

Who we are

The data controller for the personal data described in this policy is [Company Legal Name], [Registered Address].

For any question about this policy or your data, contact our privacy team at privacy@mcpbundler.com.

What we collect, and why

We collect only the data each feature needs to function, and use it only for the purpose it was collected for - the GDPR principle of purpose limitation (doelbinding). We do not repurpose data collected for one feature to serve an unrelated one.

  • Account data (name, email, organisation) - to authenticate you and operate your account, via our identity provider Keycloak.
  • Billing data (payment method, invoices, subscription tier) - to process payments and provide support, via our payment processor Stripe.
  • Usage and health metrics (which MCP servers you run, request volumes, error rates) - to operate the bundler, enforce plan limits, and diagnose incidents.

Legal basis for processing

  • Contract performance - account data and usage metrics, because we cannot provide the service without them.
  • Contract performance - billing data, to fulfil our contract with you.
  • Legitimate interest - aggregated health metrics used to keep the platform reliable, weighed against your right to privacy and limited to what operating the service requires.

Storage and encryption

Stored credentials and other sensitive fields are encrypted at rest using AES-256-GCM before they ever reach disk. Data in transit is encrypted with TLS. Encryption keys are managed separately from the data they protect.

See our Security page for more detail on how these protections are implemented.

Retention

We keep account and billing data for as long as your account is active, and for the period afterwards required by EU tax and accounting law. Usage metrics are retained for 13 months on a rolling basis, then deleted.

Sub-processors and data location

We use a small number of sub-processors to run the service, each bound by a data processing agreement, and our infrastructure is hosted within the EU:

  • Keycloak (self-hosted on our own EU infrastructure) - authentication and identity.
  • Stripe (EU entity) - payment processing.

Cookies

We use only strictly necessary cookies to keep you signed in and to remember your session. We do not use advertising or cross-site tracking cookies, and we do not sell or share your data with third parties for advertising.

Supervisory authority

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection authority. If you are unsure which authority applies to you, the European Data Protection Board maintains a directory of national authorities.

Changes to this policy

We will update the "last updated" date above whenever we make a material change to this policy, and where required by law, notify account holders directly.

Your rights

Under the GDPR, you have the right to:

  • Access - get a copy of the personal data we hold about you.
  • Rectification - correct data that is inaccurate or incomplete.
  • Erasure - have your data deleted, subject to our legal retention obligations.
  • Portability - receive your data in a structured, machine-readable format.
  • Object - object to processing based on legitimate interest.
Request my dataDelete my data
We handle these requests manually to make sure a human reviews each one, and respond within 30 days, in line with GDPR Article 12.
Last updated 5 August 2026
MCPbundler
The MCP management platform - discover, configure, control, and share your AI tool stack.
Platform
Bundle registryDocumentationChangelogRoadmap
Community
GitHubDiscordBlogUpdatesContributing
Company
AboutPrivacyTermsSecurity
© 2026 MCPbundler. Open-source under MIT.