Privacy Policy
Last updated: May 27, 2026
1. Information We Collect
When you use BoltSchema, we collect the following types of information:
- Account Information: Your email address and hashed password when you register.
- MCP Server Data: Database connection strings and API configurations you provide to create hosted MCP servers. These are encrypted at rest.
- Usage Data: Request logs, server metrics, and analytics to improve our service.
- Device Information: Browser type, IP address, and general location for security and analytics purposes.
2. How We Use Your Information
- To provision and maintain your hosted MCP servers.
- To authenticate your identity and secure your account.
- To send transactional emails (verification, security alerts).
- To monitor service health and prevent abuse.
- To improve BoltSchema through aggregated, anonymized analytics.
3. Data Security
All database credentials and API keys are encrypted using AES-256-GCM before storage. Connections to our servers use TLS 1.3. We never store your passwords in plain text — they are hashed with bcrypt. Access to production infrastructure is restricted to authorized personnel with multi-factor authentication.
4. Data Sharing
We do not sell your personal data. We may share information only in the following circumstances:
- With infrastructure providers (hosting, email delivery) to operate the service.
- When required by law or to respond to valid legal processes.
- To protect the rights, property, or safety of BoltSchema and its users.
5. Data Retention
We retain your account data for as long as your account is active. MCP server configurations are deleted within 30 days of account deletion. Aggregated analytics data may be retained indefinitely.
6. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Export your MCP server configurations.
7. Cookies & Analytics
We use Google Analytics to understand how visitors interact with our site. We use essential cookies for authentication (session tokens). We do not use advertising cookies or third-party tracking pixels.
8. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes via email. Continued use of BoltSchema after changes constitutes acceptance.
9. Contact
If you have questions about this privacy policy, contact us at privacy@boltschema.com.