Privacy Policy
Last updated: 24 July 2026
1. Who we are (data controller)
This service ("Context Engineer MCP", the "Service") is operated by Context Engineer, registered in the Netherlands with the Dutch Chamber of Commerce (KvK) under number 99945274. For any privacy question, or to exercise your rights, contact us at joris@context-engineer.nl.
2. What the Service does
Context Engineer MCP is a hosted gateway (an "MCP server") that lets your AI client connect to third-party tools you own, currently a Craft CMS site, Google BigQuery, Google Analytics 4, Google Ads, Google Search Console and Google Merchant Center. You authorize a connection once, and we then relay requests from your AI client to that service on your behalf. We are the data controller for the account, connection and billing data described below. For the content you access through a connection (your Craft entries, your BigQuery data, your analytics and advertising reports, your Search Console query and index data, your Merchant Center product data), you remain the controller. We only process that content briefly to fulfil your request, and we do not store it.
3. What personal data we process, and why
| Data | Why | Legal basis |
|---|---|---|
| Email address — verified via Google sign-in for Google connectors, or entered by you on the connect form for Craft CMS (and then confirmed by a verification e-mail). Your chosen language (Dutch or English) is also stored with your account, for the site and our e-mail | To identify your account, manage your subscription, and send transactional e-mail (address verification, trial reminders, payment notices and invoices) and support | Performance of a contract |
| Billing details you provide at checkout: name or company name, address, country and (for EU businesses) VAT number. A snapshot of these details is kept on each invoice | To determine the correct VAT rate and issue legally valid invoices | Performance of a contract, and legal obligation (tax law) |
| Connection credentials: your Google OAuth tokens (BigQuery, Google Analytics 4, Google Ads, Google Search Console, Google Merchant Center), or your Craft site URL plus GraphQL token. Stored encrypted at rest (AES-256-GCM) | To access the third-party service you connected, on your behalf, when your AI client makes a request | Performance of a contract, and your consent given at authorization |
| Billing data: a Mollie customer ID, subscription ID and mandate ID, plus your plan and trial status | To run the per-server monthly subscription (the price, excl. VAT, is shown at checkout) and recurring payments | Performance of a contract, and legal obligation (tax records) |
| Technical data: server logs with request metadata (timestamp, endpoint, status) and usage counters per connection (which tool was called, on which day, how often — never the tool's content or results). Access and refresh tokens are stored only as irreversible hashes, and we do not log secrets | To operate, secure and debug the Service | Legitimate interest (security and reliability) |
We do not store your payment-card or bank details (these are handled by Mollie), and we do not store the content of your BigQuery queries, your Google Analytics or Google Ads reports, your Search Console data, your Merchant Center product data or your Craft data. That content flows through the Service transiently, to your own AI client. Google OAuth data is used solely to provide the connector functionality you see; we never use it for anything else.
4. Google user data and Limited Use
When you connect a Google service, you grant the Service access to a specific set of Google API scopes belonging to that one connector. Each connector is authorized separately and requests only the scopes its own tools need: a BigQuery connection therefore gives us no access to your Google Ads data, and vice versa.
| Connector | Google API scopes | Google user data accessed |
|---|---|---|
| Google BigQuery | bigquery.readonly | Project, dataset, table and schema metadata, plus the rows returned by the read-only SQL query you run |
| Google Analytics 4 | analytics.readonly, analytics.edit | Aggregated report and realtime data from the GA4 Data API, and configuration from the GA4 Admin API (properties, data streams, annotations, audiences, custom dimensions). analytics.edit is required only for the create and delete tools you explicitly invoke |
| Google Ads | adwords | Reporting data on accounts, campaigns, ad groups, keywords, search terms and ads, keyword ideas, and the status and budget fields you explicitly change |
| Google Search Console | webmasters.readonly | Your verified sites, search analytics (queries, pages, clicks, impressions), the index status of a URL and the status of sitemaps |
| Google Merchant Center | content | Account details, product catalog, product issues and performance reports (read-only) |
| All Google connectors | email, profile | Your Google account e-mail address and basic profile, solely to identify your account |
Use. Google user data — raw as well as aggregated or anonymized — is used for one purpose only: to provide the connector functionality you see, by relaying a request from your AI client to the Google API and returning the result to that same client. We do not use it for anything else.
Transfer. The response to your request flows through the Service to the AI client you connected (for example Claude or Cursor) — that is, after all, the feature you asked for. We never sell Google user data, and we never transfer it to data brokers, advertisers or any other third party. We do not use it for advertising purposes, nor for credit or lending purposes.
AI and ML models. We do not use Google user data to develop, improve or train AI or machine-learning models, and we do not transfer it to third-party services for that purpose. Your AI client processes the data at your request under that provider's own terms; the Service itself trains nothing.
Storage. We do not store the Google user data these APIs return; it flows through transiently. Your OAuth tokens are stored encrypted (see section 5) and are deleted together with your connection or your account (see section 8).
Limited Use. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Where your data is stored, and security
Your account, connection and billing data are stored in a PostgreSQL database hosted on servers located within the European Union (Hetzner Online GmbH, Germany). Connection credentials are encrypted at rest with AES-256-GCM, and all traffic to and from the Service is encrypted in transit with TLS (HTTPS). The database is backed up automatically; backups are stored encrypted at rest in Cloudflare R2 with a Western Europe data location. Access to production systems is restricted to authorized operators.
6. Third parties and sub-processors
- Mollie B.V. (Amsterdam, the Netherlands) handles payment processing for subscriptions. See Mollie's privacy statement at mollie.com/privacy.
- Google LLC / Google Ireland Ltd. When you connect a Google service, we use Google OAuth and the relevant Google APIs — BigQuery, the Google Analytics Data and Admin APIs, the Google Ads API, the Search Console APIs (including URL inspection) or the Merchant API — to act on your own Google account. The data you access stays under your Google account and Google's terms.
- Hetzner Online GmbH (Germany) provides the EU servers on which the Service and database run.
- Cloudflare, Inc. (United States) stores our encrypted database backups in Cloudflare R2 with a Western Europe data location, under Standard Contractual Clauses. See cloudflare.com/privacypolicy.
- Resend, Inc. (United States) delivers our transactional e-mail (address verification, trial reminders, payment notices, invoices). Resend receives the recipient address and the message content, and processes them under Standard Contractual Clauses. See resend.com/legal/privacy-policy.
- European Commission (VIES): if you enter an EU VAT number at checkout, we send it to the Commission's VIES service to validate it, as required for reverse-charged invoicing.
- Your AI client (for example Anthropic's Claude, or Cursor) connects to the Service. Its handling of your data is governed by that provider's own privacy policy.
7. International transfers
Account, connection and billing data are kept within the EU. Three exceptions involve a transfer element outside the EU/EEA, all covered by Standard Contractual Clauses: if you connect a Google service (BigQuery, Google Analytics 4, Google Ads, Search Console or Merchant Center), processing may involve Google infrastructure and also depends on your own Google configuration; transactional e-mail is delivered by Resend, Inc. in the United States; and database backups are stored with Cloudflare, Inc. (a US company) with a Western Europe data location. We do not otherwise transfer your personal data outside the EU/EEA.
8. How long we keep your data
- Connection credentials: until you delete the connection or your account, or shortly after.
- Account and subscription records: for the life of your account.
- Invoicing and payment records: retained for 7 years where required by Dutch tax law, then deleted.
- Server logs: kept only briefly for security and debugging, then deleted.
When you delete your account we erase your personal data, except records we are legally required to keep, such as invoices.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (the "right to be forgotten"), subject to legal retention;
- restrict or object to processing;
- data portability;
- withdraw consent at any time, for example by disconnecting a connection.
To exercise any of these, email joris@context-engineer.nl. You can also cancel subscriptions yourself via the management link provided in your AI client. If you believe we mishandle your data, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
10. Cookies
The public site sets no tracking or analytics cookies. We use a single, strictly necessary cookie only on the operator admin page, to keep an authenticated session. The OAuth and billing flows use short-lived, signed tokens rather than tracking cookies. Your language choice travels via the URL and is stored with your account — not in a cookie.
11. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects for you.
12. Changes to this policy
We may update this policy as the Service evolves. The "Last updated" date above reflects the latest version, and material changes will be announced on this page.