Privacy Policy

Last updated: September 23, 2026

1. Controller

Nubri GmbH
Liebenowzeile 22
12167 Berlin, Germany
Email: info@nubri.co
VAT ID: DE332956472
Registration: HRB 217794 B, Amtsgericht Charlottenburg

2. What we process and why

a. Account data

Email address, name, a bcrypt hash of your password (never the password itself), plan, email-verification status, timestamps. Purpose: providing your account.

b. API keys

We store only a SHA-256 hash and a short non-secret prefix of each key, plus when it was last used.

c. MCP server registrations

Name, slug, upstream URL, authentication type; upstream credentials are encrypted at rest with AES-256-GCM.

d. Gateway traffic

Requests and responses are relayed between your agents and your upstream servers in transit; we do not store their bodies. For each request we store a usage record: server, JSON-RPC method, HTTP status, latency, and time — used for quotas, billing, and your usage dashboard.

e. Memory store

The keys, namespaces, content, and metadata you write, stored until you delete them or your account.

f. Playground

The messages you send, model replies, and tool inputs/outputs are stored as a session transcript that anyone with the session link can view; a random visitor ID kept in your browser's localStorage; a salted SHA-256 hash of your IP address used for abuse limits (raw IP addresses are not stored in our database). If you sign up from the same browser, your earlier playground sessions are linked to your account.

g. First-party analytics

When you visit, we record simple funnel events (landing, playground run, signup page view, signup, checkout start) together with the random visitor ID, UTM parameters, referrer, and page path. We use no third-party analytics, advertising trackers, or tracking cookies.

h. Payments

Processed by Stripe; we store only your Stripe customer and subscription IDs, never card details.

i. Emails

We send transactional emails only (email verification, password reset) through Amazon SES.

j. Server logs

Our reverse proxy and API log IP address, user agent, request path, and status code for security and troubleshooting; these logs are kept for a limited period.

3. Legal bases (GDPR Art. 6)

Art. 6(1)(b) contract: account, gateway, memory store, billing, transactional email; Art. 6(1)(f) legitimate interests: security, abuse prevention and rate limiting, the anonymous playground, first-party analytics to improve the service; Art. 6(1)(c) legal obligation: tax and accounting records.

4. Recipients and processors

Amazon Web Services (hosting in the US region us-east-1, email delivery via Amazon SES, and model inference for the playground via Amazon Bedrock); Anthropic's Claude models are accessed through Amazon Bedrock; Stripe (payments); the upstream MCP servers you configure receive the requests your agents send to them, as directed by you, under their own terms. Transfers to the US rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the EU Standard Contractual Clauses.

5. Storage on your device

We do not use cookies. We use your browser's localStorage for: your sign-in token (tb_token), your theme preference (tb_theme), a random visitor ID (tb_visitor_id), and first-touch attribution (tb_first_touch, containing UTM parameters and referrer); and sessionStorage to count a visit only once (tb_landed). Clearing your browser storage removes them.

6. Retention

Account data is kept while your account exists. When you delete your account in Settings, we immediately delete your account, API keys, MCP server registrations and credentials, memory items, usage records, and the playground sessions linked to your account; anonymous funnel events are kept without any link to you. Playground sessions that are not linked to an account are kept so that their share links keep working; email info@nubri.co with a session link to have it deleted. Stripe retains payment records as required by law.

7. Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21, in particular to processing based on legitimate interests); contact info@nubri.co; right to lodge a complaint with a supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

8. Security

TLS in transit; bcrypt-hashed passwords; hashed API keys; AES-256-GCM encryption for upstream credentials; blocking of requests to private networks.

9. Children

The service is not directed at people under 18.

10. Changes

We will post updates here and change the "Last updated" date; material changes are announced by email.