Privacy Policy
This policy explains what personal data Burnbound processes, why, for how long and what rights you have. It applies to the website, the dashboard, the API and the @burnbound/mcp package.
1. Who is responsible
The data controller is [Nombre o razón social pendiente] (NIF [NIF pendiente]), [Domicilio pendiente]. For anything about your data, write to [Email de contacto pendiente].
2. What data we process
Account. Your email address, your password (we store only a bcrypt hash, never the password), your organization's name and your role in it. When you sign in, a session token whose hash we store.
Billing. If you subscribe to Pro: the Stripe customer and subscription identifiers, the plan and its status. Stripe collects your card details, and your billing address and tax ID when they are required; we never see or store card numbers.
Service data. What you and your agents create in Burnbound:
- agents, policies and the history of their changes;
- organization and agent keys, of which we store only a hash and a short prefix;
- wallet addresses; in Coinbase CDP mode, your CDP API credentials, encrypted; for an external signer, its URL, encrypted;
- for every payment your agent asks to make: the URL that answered
402(path and query string included), the price, network, asset, payee and paying address, the decision and its reasons, the seller's receipt and the on-chain transaction; - approvals: who decided (email address), when, and the note you add;
- notification settings: your Slack webhook, encrypted, and whether approval emails are on.
We do not see what your agent sends to the seller or what the seller returns: the MCP server sends us only the payment request and, after paying, the receipt.
Technical data. Your IP address, to limit the number of requests and prevent abuse; error reports from the dashboard and the API, with secrets and cookies removed; and server logs.
Website visits. Aggregate visit statistics from Cloudflare Web Analytics, which uses no cookies and does not track you across sites.
3. Why we process it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Create your account, apply your policies, record the audit log and send the approval notices you turn on | Performance of the contract (GDPR art. 6.1.b) |
| Charge the Pro subscription and keep invoices | Contract and legal obligation (art. 6.1.b and 6.1.c) |
| Keep the service secure: rate limits, abuse prevention, error monitoring, detecting payments outside your policy | Legitimate interest in a secure, working service (art. 6.1.f) |
| Measure visits to the website in aggregate | Legitimate interest in knowing how the site is used (art. 6.1.f) |
| Answer your requests and exercise your rights | Legal obligation (art. 6.1.c) |
We do not sell your data, use it for advertising, or make automated decisions about you with legal or similarly significant effects. The policy decisions Burnbound makes about payments are the rules you configured.
4. Who processes it for us
We use these providers, under contracts that oblige them to protect your data and use it only on our instructions:
| Provider | What for | Where |
|---|---|---|
| Hetzner | Servers and database | European Union |
| Cloudflare | DNS, CDN, network protection and Web Analytics | Global network; company in the US |
| Stripe | Subscription payments and invoices | Ireland and the US |
| Sentry | Error monitoring | European Union data region; company in the US |
| Resend | Approval emails, only when an organization turns them on | US |
Some services act on your behalf, under your own agreement with them:
- Slack, if you connect a webhook: approval notices go to your Slack workspace.
- Coinbase, if you choose Coinbase CDP: we send it signing requests with your credentials.
- Blockchain networks: payments settle on public blockchains, and we query public network nodes about the wallet addresses you register to detect payments outside your policy. On-chain data is public and permanent; nobody, including us, can delete it.
Where a provider processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework or on the European Commission's standard contractual clauses. We also share data when the law requires it.
5. How long we keep it
- Account and service data: while your account exists. When you close it, we delete it within 30 days, except what the law requires us to keep.
- Audit log: it is append-only so it can be trusted. Your plan sets how far back you can see it (30 days on Free, 365 on Pro); the records are kept while the account exists and deleted with it.
- Billing records: for the periods required by tax and commercial law (up to six years).
- Sessions: seven days, or until you sign out.
- IP addresses for rate limiting: at most 15 minutes, in memory.
- Error reports: at most 90 days.
- Server logs: rotated automatically; old entries are overwritten within days.
6. Cookies and local storage
Burnbound uses no advertising or tracking cookies, so there is no cookie banner. We use only:
| Name | What for | Duration |
|---|---|---|
apc_session |
Keeps you signed in to the dashboard. Strictly necessary. | 7 days |
NEXT_LOCALE |
Remembers the language you chose with the language switcher. Set only when you choose. | 1 year |
The dashboard also keeps the selected agent in your browser's local storage. Cloudflare may set strictly necessary security cookies (such as __cf_bm) to filter automated traffic.
7. Your rights
You can ask for access to your data, its rectification or erasure, the restriction of its processing, its portability, and object to processing based on legitimate interest. Write to [Email de contacto pendiente] from your account's email address; we answer within one month. If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (aepd.es).
8. Security
Connections use TLS. Passwords are hashed with bcrypt, keys and session tokens are stored as hashes, and wallet credentials and webhooks are encrypted with AES-256-GCM. Access to production systems is limited to the people who run the service.
9. Children
Burnbound is not meant for anyone under 18, and we do not knowingly collect their data.
10. Changes
If we change this policy in a way that matters, we will tell you by email or in the dashboard before the change takes effect.