NL · EN

Back to Context Engineer MCP

Privacy Policy

Last updated: 24 July 2026

1. Who we are (data controller)

This service ("Context Engineer MCP", the "Service") is operated by Context Engineer, registered in the Netherlands with the Dutch Chamber of Commerce (KvK) under number 99945274. For any privacy question, or to exercise your rights, contact us at joris@context-engineer.nl.

2. What the Service does

Context Engineer MCP is a hosted gateway (an "MCP server") that lets your AI client connect to third-party tools you own, currently a Craft CMS site, Google BigQuery, Google Analytics 4, Google Ads, Google Search Console and Google Merchant Center. You authorize a connection once, and we then relay requests from your AI client to that service on your behalf. We are the data controller for the account, connection and billing data described below. For the content you access through a connection (your Craft entries, your BigQuery data, your analytics and advertising reports, your Search Console query and index data, your Merchant Center product data), you remain the controller. We only process that content briefly to fulfil your request, and we do not store it.

3. What personal data we process, and why

We do not store your payment-card or bank details (these are handled by Mollie), and we do not store the content of your BigQuery queries, your Google Analytics or Google Ads reports, your Search Console data, your Merchant Center product data or your Craft data. That content flows through the Service transiently, to your own AI client. Google OAuth data is used solely to provide the connector functionality you see; we never use it for anything else.

4. Google user data and Limited Use

When you connect a Google service, you grant the Service access to a specific set of Google API scopes belonging to that one connector. Each connector is authorized separately and requests only the scopes its own tools need: a BigQuery connection therefore gives us no access to your Google Ads data, and vice versa.

Use. Google user data — raw as well as aggregated or anonymized — is used for one purpose only: to provide the connector functionality you see, by relaying a request from your AI client to the Google API and returning the result to that same client. We do not use it for anything else.

Transfer. The response to your request flows through the Service to the AI client you connected (for example Claude or Cursor) — that is, after all, the feature you asked for. We never sell Google user data, and we never transfer it to data brokers, advertisers or any other third party. We do not use it for advertising purposes, nor for credit or lending purposes.

AI and ML models. We do not use Google user data to develop, improve or train AI or machine-learning models, and we do not transfer it to third-party services for that purpose. Your AI client processes the data at your request under that provider's own terms; the Service itself trains nothing.

Storage. We do not store the Google user data these APIs return; it flows through transiently. Your OAuth tokens are stored encrypted (see section 5) and are deleted together with your connection or your account (see section 8).

Limited Use. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Where your data is stored, and security

Your account, connection and billing data are stored in a PostgreSQL database hosted on servers located within the European Union (Hetzner Online GmbH, Germany). Connection credentials are encrypted at rest with AES-256-GCM, and all traffic to and from the Service is encrypted in transit with TLS (HTTPS). The database is backed up automatically; backups are stored encrypted at rest in Cloudflare R2 with a Western Europe data location. Access to production systems is restricted to authorized operators.

6. Third parties and sub-processors

7. International transfers

Account, connection and billing data are kept within the EU. Three exceptions involve a transfer element outside the EU/EEA, all covered by Standard Contractual Clauses: if you connect a Google service (BigQuery, Google Analytics 4, Google Ads, Search Console or Merchant Center), processing may involve Google infrastructure and also depends on your own Google configuration; transactional e-mail is delivered by Resend, Inc. in the United States; and database backups are stored with Cloudflare, Inc. (a US company) with a Western Europe data location. We do not otherwise transfer your personal data outside the EU/EEA.

8. How long we keep your data

When you delete your account we erase your personal data, except records we are legally required to keep, such as invoices.

9. Your rights

Under the GDPR you have the right to:

To exercise any of these, email joris@context-engineer.nl. You can also cancel subscriptions yourself via the management link provided in your AI client. If you believe we mishandle your data, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

10. Cookies

The public site sets no tracking or analytics cookies. We use a single, strictly necessary cookie only on the operator admin page, to keep an authenticated session. The OAuth and billing flows use short-lived, signed tokens rather than tracking cookies. Your language choice travels via the URL and is stored with your account — not in a cookie.

11. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects for you.

12. Changes to this policy

We may update this policy as the Service evolves. The "Last updated" date above reflects the latest version, and material changes will be announced on this page.

Back to Context Engineer MCP

Privacy Policy | Context Engineer MCP