Last updated: July 24, 2026. This policy is a working draft — have legal counsel review before relying on it commercially.
Account data (email address, salted password hash — never your plaintext password); content you create (blueprint descriptions, blueprints, connector configurations); operational data (deployment invocation logs: tool name, status, timing — not payload contents; credit usage; billing events); and basic technical data (IP address for rate limiting and abuse prevention).
API keys and tokens you store for connector bridges are encrypted at rest with AES-256-GCM and are decrypted only in memory, at execution time, to authenticate calls to the systems you configured. We never log or display them after entry.
To operate the Service: authentication, running your deployed MCP servers, billing, usage alerts, abuse prevention, and support. Blueprint generation runs in your browser; your descriptions are not sent to any AI model by us. We do not sell personal data and do not use your content to train models.
Cloudflare, Inc. (hosting, CDN, database — data processed at the network edge); Finix Payments, Inc. (subscription payments — we never see full card numbers); Resend (transactional email delivery). Each processes data under their own terms and security programs.
One first-party session cookie (HttpOnly, Secure) keeps you signed in. No advertising or cross-site tracking cookies.
Account and content data persist while your account is active. Deleting a deployment deletes its invocation logs; deleting your account removes your personal data within 30 days except records we must retain for legal or billing purposes. Request deletion at admin@smepro.app.
Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to processing. Contact admin@smepro.app and we will respond within 30 days.
Material changes will be announced via the Service or email. Contact: admin@smepro.app.