Privacy Policy

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator: helpcode.ai GmbH, E-Mail: [email protected].

2. Hosting

This website is hosted on DigitalOcean. The servers are located in Frankfurt, Germany (EU). DigitalOcean is ISO 27001 certified. A data processing agreement (DPA) is in place.

3. General information and mandatory disclosures

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection regulations and this privacy policy.

4. Data collection on this website

Cookies and consent

This website uses cookies. When you first visit the site, a cookie consent banner is displayed. You can choose which categories of cookies to allow: essential (always active), analytics, functionality, and marketing. Your choice is stored in the "cc_cookie" cookie. You can change your preferences at any time via the "Cookie Settings" link in the footer or on our Cookie Policy page.

Contact form

When you send us inquiries via the contact form, your details from the form, including the contact details you provide, are stored by us for the purpose of processing the inquiry and for follow-up questions.

Error and performance monitoring (Sentry)

To detect and fix technical errors, this website uses Sentry, a service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. When an error occurs in your browser or on our server, a report is sent to Sentry; for about one in ten page visits, the loading times of the page are also measured. The legal basis is our legitimate interest in a stable, secure and error-free website (Art. 6(1)(f) GDPR). Sentry sets no cookies and is not used for analytics or advertising.

  • Transmitted: the address of the page (without personal URL parameters such as email addresses, keys or payment session IDs), browser, operating system and device type, the error message with its technical stack trace, the steps immediately before the error (pages visited, page elements clicked, requests made by the page) and, for measured visits, loading times.
  • Not transmitted: cookies, form contents, the contents of requests and responses, or information about you as a person. We do not pass your IP address on to Sentry, and storage of IP addresses is disabled in our Sentry account.
  • Reports are sent via our own domain (anythingmcp.com/monitoring) and stored in Sentry's EU region (Frankfurt, Germany). Sentry deletes error reports after 90 days at the latest; performance data is kept in full for 30 days and, depending on our plan, in sampled form for up to 13 months.
  • After an error, the page stores a timestamp in your browser's session storage (amcp_error_reload_at) so that it reloads itself at most once; it is deleted when you close the tab. This is technically necessary for the website to work (Section 25(2) no. 2 TDDDG).
  • Functional Software, Inc. is based in the USA, so this processing may involve a transfer to a third country. Sentry is certified under the EU-U.S. Data Privacy Framework; in addition, a data processing agreement (DPA) including the EU standard contractual clauses is in place. Privacy policy: https://sentry.io/privacy/.

5. Analytics and tracking

Google Tag Manager

This website uses Google Tag Manager (GTM) to manage tracking scripts. GTM itself does not collect personal data and does not set cookies. GTM operates with Google Consent Mode v2 – scripts are only activated after you give explicit consent via the cookie banner.

Google Analytics

If you accept analytics cookies, Google Analytics is loaded via Google Tag Manager. Google Analytics uses cookies (such as _ga, _gid) to collect anonymous usage statistics. IP anonymization is enabled. Data processing is based on your consent (Art. 6(1)(a) GDPR). You can revoke your consent at any time via the cookie settings.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

6. Marketing and advertising

If you accept marketing cookies, third-party services (such as Google Ads, Meta/Facebook) may be loaded via Google Tag Manager to serve relevant advertisements and measure campaign effectiveness. These services may set their own cookies (e.g. _gcl_*, _fbp). Data processing is based on your consent (Art. 6(1)(a) GDPR).

Google Ads Enhanced Conversions

We use the "Enhanced Conversions for Web" feature of Google Ads. If you have consented to marketing cookies and complete a conversion on our website (e.g. a registration or purchase), first-party data collected by us — such as your email address — is hashed using the SHA-256 procedure and transmitted to Google exclusively in this hashed (pseudonymised) form. Google uses the hash solely to match the conversion to Google accounts in a privacy-friendly way and to measure campaign performance; the plain-text data does not leave our systems. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can revoke at any time via the cookie settings. More information: https://business.google.com/privacy/products/enhanced-conversions/.

Google Ads conversion measurement for purchases

If you have consented to marketing cookies and reach our website through a Google ad, we store the Google click identifier contained in the link (gclid, gbraid or wbraid) in your browser's local storage (amcp_ad_click, deleted after 90 days) and, if you buy a subscription, pass it to our payment provider Stripe with the order. Once the purchase is completed, our server sends Google the click identifier, the order number, the time and value of the purchase, your consent status and your email address hashed with SHA-256. Google uses this data only to attribute the purchase to the ad click and to measure and optimise our campaigns; your email address is never transmitted in plain text. Without marketing consent neither the click identifier nor a hashed email address is stored or transmitted. We keep no plain email address for this purpose; the hash is deleted after a successful upload, or after 60 days at the latest. The legal basis is your consent (Art. 6(1)(a) GDPR; for storage on your device Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future via the cookie settings (link in the footer). Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A transfer to Google LLC in the USA cannot be ruled out; Google LLC is certified under the EU-U.S. Data Privacy Framework.

7. Payment provider

Stripe

We use Stripe (Stripe Inc.) for payment processing. Stripe processes payment data in accordance with PCI DSS Level 1. Data processing takes place in the EU. Privacy policy: https://stripe.com/privacy.

8. Email delivery

Resend

We use Resend for sending transactional emails. A data processing agreement (DPA) is in place.

Mailgun (EU)

Emails sent from the AnythingMCP Cloud application (invitations, email verification, system notifications) are delivered via Mailgun's EU region (Mailgun Technologies, Inc.). Delivery runs on EU infrastructure. A data processing agreement (DPA) is in place. If you configure your own SMTP server in your workspace, it is used instead and no email data reaches Mailgun.

9. AI-assisted features (Knowledge Graph and AI Skills)

Two optional features use a large language model provided by Anthropic PBC: Knowledge Graph enrichment, which proposes relationships between the entities your connectors expose, and AI Skills, which turns recurring tool usage into reusable rules. Both are switched off by default and require an explicit opt-in per workspace. While they are off, no data is transmitted to an AI provider.

  • Transmitted: connector and tool metadata (names, descriptions, parameters) and, where intent capture is enabled, the pattern of the requests made. The business records your connectors return are not transmitted.
  • Before transmission, captured request texts are automatically scrubbed of e-mail addresses, telephone numbers, IBANs, card-like numbers and long digit sequences.
  • The model's output is a suggestion. It becomes effective only once a person in your workspace approves it.
  • Model used: Claude Haiku (Anthropic PBC). If you host AnythingMCP yourself, you choose the provider and supply the key; nothing is transmitted until you do.
  • Anthropic PBC is based in the USA, so this processing involves a transfer to a third country. Anthropic's Data Processing Addendum, which its commercial terms incorporate by reference, applies. Under those terms Anthropic does not use content submitted through the API to train its models.

10. AnythingMCP Cloud and connections from AI assistants

When you use AnythingMCP Cloud (cloud.anythingmcp.com) and connect it to an AI assistant such as ChatGPT or Claude, we process the following data to provide the service. We do not sell it, do not use it for advertising and do not use it to train AI models.

  • Account data: name, email address, password hash or single sign-on identity, workspace memberships and roles. Purpose: sign-in, access control and support. Kept until you delete your account or workspace.
  • Workspace configuration: connectors, MCP servers, roles, workspace notes and approved skills. Credentials for the systems you connect (API keys, tokens) are stored encrypted (AES-256-GCM) and deleted together with the connector.
  • Tool calls: when an AI assistant calls a tool, we record the time, the tool, the user, the result status, the duration, the input and an excerpt of the output, as the workspace's audit log and for troubleshooting. Inputs and outputs are shortened to excerpts after 14 days, and the records are deleted after 90 days.
  • Data from your connected systems is fetched only when a tool is called and is passed to the AI assistant you use; apart from the call record above it is not stored.
  • Recipients: the systems you connect (called with your credentials), the AI assistant you connect (which processes the results under its own terms), our hosting provider DigitalOcean (Frankfurt, Germany), our email providers (Section 8) and Stripe for payments (Section 7). Payment, banking and trading connectors are not offered to AI assistants on the shared endpoint.
  • Your controls: you choose which workspace or server an AI assistant may reach when you connect it and can change or revoke this at any time; administrators set roles per person; you can delete connectors, the workspace and your account in the settings, or ask us at [email protected].
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR).

11. Your rights

You have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing, as well as the right to rectification or deletion of this data. You can contact us at any time for this purpose and for further questions regarding personal data.