Privacy Policy
Last updated: 2026-05-21
This Privacy Policy explains what personal data paddle-mcp ("we", "us") collects, how we use it, and your rights.
1. Data we collect
- Account data: your email address, password hash (PBKDF2-SHA256, if you set one), or Google account id if you signed in with Google; and the date you created your account.
- Paddle API keys: the API credentials you paste into the dashboard. Stored AES-GCM encrypted at rest in Cloudflare KV; decrypted only in-memory during a single tool call.
- Audit log: for each tool invocation we record timestamp, tool name, target environment (sandbox/production), the SHA-256 hash of parameters, success/failure and any error code. We do not store raw parameter values.
- Operational logs: IP address, user agent, and request metadata retained by Cloudflare for up to 7 days for abuse prevention and debugging.
- Billing data: handled by Paddle.com as our merchant of record. We receive only subscription status and the customer id; we do not see card numbers.
2. Why we collect it
- To authenticate you and route MCP calls to your Paddle account (account data, API keys).
- To enforce quotas and rate limits (audit log).
- To investigate abuse, debug failures, and meet legal obligations (operational logs).
- To bill you for paid plans (billing data, via Paddle).
3. Legal basis (GDPR)
For EEA/UK residents, we process your data under (a) contract performance (Article 6(1)(b)) for account, billing, and audit data, and (b) legitimate interests (Article 6(1)(f)) for abuse prevention and operational logging.
4. Sharing
We do not sell personal data. We share data only with these processors:
- Cloudflare — hosting (Workers), KV storage, Durable Objects, DNS.
- Paddle.com Market Ltd — payment processing, taxation, invoicing.
- Resend — transactional email (sign-in links, password resets).
- Google — only if you choose to sign in with Google; we exchange an OAuth code for your verified email and Google user id.
We may disclose data when required by law or to protect our rights and the safety of users.
5. Retention
- Account data: while your account is active. Hard-delete from the dashboard removes the record immediately.
- API keys: until you remove them from the dashboard or delete your account; immediately purged on key rotation.
- Audit log: 7 days on Free and Starter, 90 days on Pro.
- Operational logs: 7 days (Cloudflare default).
6. Your rights
You can access, correct, export, or delete your data at any time from the dashboard or by emailing support@3vlbn.com. If you are in the EEA/UK you may lodge a complaint with your local data protection authority.
7. Security
Transport is TLS 1.3. API keys are encrypted with AES-256-GCM using a master key held only as a Cloudflare Workers Secret. Passwords are stored as PBKDF2-SHA256 hashes with per-user salts (100,000 iterations). Session cookies are HMAC-signed and marked HttpOnly and Secure. Login is rate-limited per IP and per email. We follow the principle of least privilege internally.
8. International transfers
The Service runs on Cloudflare's global edge network. Data may be processed in any region Cloudflare operates. Cloudflare maintains GDPR-compliant data processing agreements and Standard Contractual Clauses.
9. Children
The Service is not intended for individuals under 16. We do not knowingly collect data from children.
10. Changes
We will announce material changes at the email associated with your account at least 14 days before they take effect.
11. Contact
Privacy questions: support@3vlbn.com.