Privacy policy
Last updated 5 September 2026. Applies to Nexlab MCP at http://mcp.nexlab.net/
What we store, and why
- Account: your email address, a password hash (never the password) or, if you sign in with GitHub or Google, the identifier and email that provider gives us. Needed to run your account.
- Sessions: a hashed session token, its expiry and your browser's user-agent string. Expired sessions are deleted.
- API keys and OAuth clients: keys are stored only as a hash plus a short prefix so you can recognise them; OAuth client registrations and hashed tokens for the agents you connect.
- Orders and wallet: what you bought, when, for how much, which payment method, and the provider's reference. We never see or store card numbers or PayPal credentials — Stripe and PayPal hold those. Cryptocurrency payments record the address and transaction, which are public on the network anyway.
- Usage: for each call, which server, when, the outcome and how long it took — needed for quotas and billing. We do not store the content of your queries or of the answers.
- Web server logs: IP address, requested URL and time, kept for 14 days for security and abuse handling.
- Visit statistics: for each request, the page, time, outcome, referring site (host only) and a coarse client type, with a visitor token that is a hash of address and client salted with a value that changes daily - so visitors can be counted for a day but not followed, and the address itself is never stored. Where a request carries your API key or your session, the record notes that it was authenticated and which account it belonged to, so that the servers' own usage can be told apart from the automated crawlers that poll a public endpoint. Kept 90 days.
There is no advertising, no analytics service and no tracking. The site sets two cookies, both strictly necessary: your session and a CSRF token.
Where your queries go
To answer a call, a server sends the arguments you gave it to the public data source it draws on — Wikipedia, the NVD, Open-Meteo, CourtListener and the others named on each server's page. Those providers see the query and your call's origin at our servers, not your IP address. Some of them are outside the EU. Do not put personal data in a query unless you intend the source to receive it.
Legal bases
Running your account, metering and billing: performance of our contract with you. Security logs, abuse prevention and backups: our legitimate interest in operating the service safely. Invoices and payment records: our legal obligations. We do not use your data for anything else and we do not sell it.
Who else processes it
- Stripe and PayPal for payments, under their own privacy terms; both transfer data outside the EU under standard contractual clauses.
- OVH (France), which hosts our servers, and our own mail server for password resets and receipts.
- Our own git server, which holds encrypted database backups.
How long
- Account data: until you ask us to close the account, then deleted within 30 days.
- Orders, invoices and wallet ledger: 10 years, as tax law requires.
- Usage events: 24 months, then deleted or aggregated.
- Backups: daily copies for 30 days and a monthly copy for one year, all encrypted; a deletion reaches the backups as they expire.
Your rights
You can ask for a copy of your data, have it corrected or deleted, receive it in a portable form, or object to a processing based on legitimate interest. Write to the contact above; we answer within one month. You can also complain to your data protection authority — for Italy, the national supervisory authority.
Security
Everything travels over TLS. Passwords, API keys, session and OAuth tokens are stored hashed. Third-party credentials we hold (payment provider keys, mail passwords) are encrypted at rest with a key that lives outside the database. Backups are encrypted before they leave the server.
Children
The service is not directed at anyone under 18 and we do not knowingly hold their data.
Changes
Updates appear here with a new date. A change that reduces your rights is announced 14 days ahead.
See also Terms of service · Privacy policy · Refund policy.