Privacy Policy

The short version: the software sends nothing anywhere, and the website knows your email address and what you have paid for.

Last updated:

1. Who is responsible

nextjs-mcp-architecture, trading as nextjs-mcp-architecture, İstanbul, Türkiye, is the data controller for this website. Write to [email protected] about anything in this document, including a request to exercise the rights in section 9.

2. What the software does with your code

Nothing leaves your machine. The package makes no network requests at all: no telemetry, no usage counters, no error reporting, no phoning home. Your source code, file names, project structure and prompts are never transmitted to us or to anyone else.

The index it builds is written to your operating system’s cache directory, keyed by a hash of the project path — never into your repository. Deleting that directory deletes everything the software has stored. Licence verification is done offline against a public key embedded in the package, which is why it also works on a plane.

3. What the website collects

  • Your email address, when you sign in. It is the account identifier and the only way we can reach you.
  • Your subscription: tier, status, renewal date, and the reference the payment provider gave it.
  • Licence keys issued to you, and a hash of any private-registry token, so a lost one can be replaced and a leaked one revoked.
  • Payment records passed to us by the merchant of record: amount, currency, status, date, and any coupon used. We never see or store card numbers.
  • Anything you write to us in a support email, for as long as it takes to resolve it.

We do not use third-party analytics, advertising or tracking of any kind. There is no Google Analytics, no pixel, no session recorder. The only cookies this site sets are the sign-in session and its CSRF token, both strictly necessary — which is why there is no cookie banner asking for consent we do not need.

4. Why we are allowed to hold it (GDPR Art. 6)

  • Performance of a contract — your account, subscription and licence keys. Without them there is nothing to deliver.
  • Legal obligation — invoices and tax records.
  • Legitimate interests — keeping the service working and preventing fraud and licence abuse, balanced against the fact that the data involved is an email address and a subscription status.

5. Who else processes it

  • Paddle.com Market Ltd — payments, invoicing and tax, as merchant of record.
  • Resend — delivery of sign-in emails.
  • MongoDB Atlas — the database holding accounts, subscriptions and licences.
  • Our hosting provider — serving this site and its logs.

Each is bound by a data-processing agreement and may use your data only to provide that service to us. We do not sell personal data, and we do not share it for anyone else’s marketing.

6. Where it is stored

Data is hosted in the European Union where the provider offers it. Where a transfer outside the EEA or the UK is involved, it relies on the European Commission’s standard contractual clauses or an adequacy decision.

7. How long we keep it

  • Sign-in sessions: 30 days, then they expire on their own.
  • Account and subscription records: while your account exists, and for as long afterwards as tax law requires us to keep the invoices they relate to.
  • Expired licence keys: 12 months, so a support question about one can still be answered.
  • Support email: until the matter is closed, plus a short period in case you write again.

8. Security

There is no password to breach: sign-in is a single-use link and sessions are held in the database, so revoking access is deleting a row rather than waiting for a token to expire. Registry tokens are stored hashed; only a short hint is kept so you can tell which one you are looking at. Access to the control panel is limited to a small allow-list of addresses and every administrative write is recorded.

9. Your rights

You can ask for a copy of your data, its correction, its deletion, a portable export, or that we stop processing it; where processing rests on legitimate interests you may object. Write to us and we will answer within 30 days.

Deleting your account removes the account and its licences. Invoice records are kept where the law requires it, and cancelling a subscription is done through the billing portal.

If you think we have handled your data badly, you may complain to your local supervisory authority — in Türkiye the Personal Data Protection Authority (KVKK), in the EU the authority in your country of residence.

10. Children

This is a developer tool sold to businesses and professionals. It is not directed at children, and we do not knowingly collect data from anyone under 16.

11. Changes

A new version is posted here with a new date. If a change affects how we use data you have already given us, subscribers are told by email before it takes effect.

Questions about this document: [email protected]