Privacy Policy

Effective Date: July 11, 2025

This Privacy Policy explains how openapi2mcp ("we", "us", "our") collects, uses, and protects your information while you use our open-beta service located at openapi2mcp.com (the "Service").

1. Information We Collect

Information you provide. Email address, password, and any contact details you submit when creating an account, plus API specifications or other files you intentionally upload.

Usage data. Metadata about how you interact with the Service (e.g., log-ins, tool execution counts, browser type, and IP address).

Cookies & analytics. We use privacy-respecting analytics (Cloudflare Web Analytics – no cookies) to understand aggregate traffic.

2. How We Use Information

We process your information to:

  • Provide, maintain, and improve the Service;
  • Secure the platform, detect abuse, and debug issues;
  • Communicate with you about updates or support requests;
  • Produce anonymous, aggregate insights to guide product decisions.

3. Legal Basis (GDPR)

Where the EU GDPR applies, our legal bases are performance of a contract (Art. 6(1)(b)) and legitimate interests in operating and improving the Service (Art. 6(1)(f)). We rely on consent only when strictly required (e.g., marketing emails).

4. Sharing & Disclosure

We never sell your data. We disclose information solely to:

  • Infrastructure providers (e.g., Cloudflare, Supabase) who process it on our behalf under strict confidentiality; and
  • Authorities when required by law.

5. Security

Data in transit is encrypted via TLS. Credentials and secrets are stored encrypted-at-rest. Despite our efforts, no system is 100 % secure.

6. Retention

We retain account data until you delete your account or for as long as necessary to fulfill the purposes described above. Back-ups may persist for up to 30 days.

7. Your Rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, email privacy@openapi2mcp.com.

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect information from minors.

9. Changes

We will post any Privacy Policy updates on this page and revise the “Effective Date” above. Significant changes will be communicated by email.

10. Contact

Questions? Reach out to privacy@openapi2mcp.com.