Privacy Policy
Last updated: September 23, 2026
1. Controller
Nubri GmbH
Liebenowzeile 22
12167 Berlin, Germany
Email: info@nubri.co
VAT ID: DE332956472
Registration: HRB 217794 B, Amtsgericht Charlottenburg
2. What we process and why
a. Account data
Email address, name, a bcrypt hash of your password (never the password itself), plan, email-verification status, timestamps. Purpose: providing your account.
b. API keys
We store only a SHA-256 hash and a short non-secret prefix of each key, plus when it was last used.
c. MCP server registrations
Name, slug, upstream URL, authentication type; upstream credentials are encrypted at rest with AES-256-GCM.
d. Gateway traffic
Requests and responses are relayed between your agents and your upstream servers in transit; we do not store their bodies. For each request we store a usage record: server, JSON-RPC method, HTTP status, latency, and time — used for quotas, billing, and your usage dashboard.
e. Memory store
The keys, namespaces, content, and metadata you write, stored until you delete them or your account.
f. Playground
The messages you send, model replies, and tool inputs/outputs are stored as a session transcript that anyone with the session link can view; a random visitor ID kept in your browser's localStorage; a salted SHA-256 hash of your IP address used for abuse limits (raw IP addresses are not stored in our database). If you sign up from the same browser, your earlier playground sessions are linked to your account.
g. First-party analytics
When you visit, we record simple funnel events (landing, playground run, signup page view, signup, checkout start) together with the random visitor ID, UTM parameters, referrer, and page path. We use no third-party analytics, advertising trackers, or tracking cookies.
h. Payments
Processed by Stripe; we store only your Stripe customer and subscription IDs, never card details.
i. Emails
We send transactional emails only (email verification, password reset) through Amazon SES.
j. Server logs
Our reverse proxy and API log IP address, user agent, request path, and status code for security and troubleshooting; these logs are kept for a limited period.
3. Legal bases (GDPR Art. 6)
Art. 6(1)(b) contract: account, gateway, memory store, billing, transactional email; Art. 6(1)(f) legitimate interests: security, abuse prevention and rate limiting, the anonymous playground, first-party analytics to improve the service; Art. 6(1)(c) legal obligation: tax and accounting records.
4. Recipients and processors
Amazon Web Services (hosting in the US region us-east-1, email delivery via Amazon SES, and model inference for the playground via Amazon Bedrock); Anthropic's Claude models are accessed through Amazon Bedrock; Stripe (payments); the upstream MCP servers you configure receive the requests your agents send to them, as directed by you, under their own terms. Transfers to the US rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the EU Standard Contractual Clauses.
5. Storage on your device
We do not use cookies. We use your browser's localStorage for: your sign-in token (tb_token), your theme preference (tb_theme), a random visitor ID (tb_visitor_id), and first-touch attribution (tb_first_touch, containing UTM parameters and referrer); and sessionStorage to count a visit only once (tb_landed). Clearing your browser storage removes them.
6. Retention
Account data is kept while your account exists. When you delete your account in Settings, we immediately delete your account, API keys, MCP server registrations and credentials, memory items, usage records, and the playground sessions linked to your account; anonymous funnel events are kept without any link to you. Playground sessions that are not linked to an account are kept so that their share links keep working; email info@nubri.co with a session link to have it deleted. Stripe retains payment records as required by law.
7. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21, in particular to processing based on legitimate interests); contact info@nubri.co; right to lodge a complaint with a supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
8. Security
TLS in transit; bcrypt-hashed passwords; hashed API keys; AES-256-GCM encryption for upstream credentials; blocking of requests to private networks.
9. Children
The service is not directed at people under 18.
10. Changes
We will post updates here and change the "Last updated" date; material changes are announced by email.