Skip to main content

Privacy Policy

This policy describes how ExplorerHub handles the personal data of website visitors, in compliance with Regulation (EU) 2016/679 (GDPR).

Data controller

The data controller is IDCERT S.r.l. (Institute for Digital Certification), with registered office in Italy. For any request regarding the processing of personal data, please write to:

privacy@explorerhub.eu

Data collected

ExplorerHub collects technical browsing data (anonymised IP address, browser type, operating system, pages visited) through technical cookies necessary for the website's operation. Registration is optional: if the user creates an account, email address, display name and preferences are collected. Registered users can also save bookmarks, search history and browsing preferences. Through the contact form, name, email, subject and message are collected. Activity logs (logins) retain the last 50 events per user with anonymised IP. Users who enable MCP access from the account area create API keys, of which only a cryptographic fingerprint is stored, and every call to the MCP server is logged with tool invoked, framework, request parameters, anonymised IP address, client type, outcome and duration. Users who activate the Pro subscription pay through Stripe: payment data stays with Stripe, and ExplorerHub stores only the Stripe customer identifier, the subscription identifier and status, the chosen plan and the end of the current period, plus the identifier and type of the events Stripe notifies to it. To limit the rate of requests to public forms, APIs and the MCP server, the IP address is also used in clear as the key of a temporary counter, without being linked to any other data.

Purpose of processing

Technical data collected during browsing is processed for the following purposes: (a) ensuring the proper functioning of the website, (b) storing user preferences (language, theme, cookie consent), (c) collecting anonymous and aggregated statistics on website usage (only with explicit consent). MCP access data is processed to (d) provide the MCP service, measure its use per key and apply the limits of the subscribed tier, and (e) prevent abuse and ensure the security of the service. Pro subscription data is processed to (f) activate, renew and manage the subscription and to issue the related invoices.

Legal basis

Data processing is based on the following legal bases under the GDPR: (a) Legitimate interest of the controller (Art. 6.1.f) for technical cookies necessary for the website's operation; (b) Consent of the data subject (Art. 6.1.a) for analytics and marketing cookies, which can be withdrawn at any time through the cookie settings accessible from the website footer. (c) Performance of the contract (Art. 6.1.b) for the user account, for the MCP service requested by the user and for the Pro subscription; (d) Legitimate interest of the controller (Art. 6.1.f) for the MCP call log, for the rate-limit counters, for the security of the service and abuse prevention; (e) Compliance with a legal obligation (Art. 6.1.c) for the retention of the tax documents relating to the Pro subscription.

Cookies

The website uses only technical cookies necessary for its operation (e.g., language preference, theme, cookie consent). With the user's explicit consent, anonymous analytical cookies may be activated for statistical purposes. No profiling or third-party cookies are used without prior consent.

Data retention

Data is retained for the time strictly necessary for the purposes for which it is collected. Specifically: cookie and theme preferences up to 365 days; technical browsing data no longer than 12 months; GDPR consent logs for 5 years (regulatory obligation); user account data until account deletion (with cascading deletion of all associated data: profile, bookmarks, history, preferences, activity logs); contact requests for 12 months; login activity logs: last 50 events per user. MCP service API keys: the key fingerprint is kept until revocation, then for 12 months, then deleted automatically; MCP call log: 12 months, with daily automatic purge; rate-limit counters (IP address): from one minute to one hour depending on the function, then they expire on their own; events notified by Stripe (identifier and type only): 12 months; Pro subscription data (Stripe identifiers, status, plan, period end): until account deletion; tax documents of the subscription (invoices and billing data): 10 years at Stripe and in IDCERT's accounting records, as required by law. Deleting the account cancels the Pro subscription and deletes keys and call log: only the tax documents that the law requires to be kept remain.

Data subject rights

In accordance with the GDPR, users have the right to access, rectification, erasure, restriction of processing, data portability, and objection. To exercise these rights, please send a request to:

privacy@explorerhub.eu

Consent logging

In compliance with the GDPR, ExplorerHub securely records every expression of user consent. Recorded data includes: an anonymous identifier, date and time of consent, preferences chosen (necessary, analytics, marketing), version of the privacy and cookie policy in effect at the time of consent, and action performed (acceptance, rejection, customisation, revocation). This data is retained for 5 years solely for the purpose of demonstrating regulatory compliance and is not used for any other purpose.

Third-party services

ExplorerHub uses the following third-party services: (1) Google Analytics 4, provided by Google Ireland Ltd (Gordon House, Barrow Street, Dublin 4, Ireland), for anonymous traffic analysis — activated exclusively with the user's explicit consent, with IP address anonymisation (privacy policy: https://policies.google.com/privacy); (2) Vercel Analytics and Vercel Speed Insights, provided by Vercel Inc., for aggregate performance metrics — operate without cookies and without collecting personally identifiable data; (3) Sentry, provided by Functional Software Inc. (San Francisco, USA), for error monitoring and session replay to improve service quality — legal basis: legitimate interest (Art. 6.1.f) — collected data includes stack traces, visited URL, user-agent and partial session replays in case of errors (privacy policy: https://sentry.io/privacy/); (4) Cloudflare Turnstile, provided by Cloudflare Inc. (USA), for CAPTCHA protection of forms — legal basis: legitimate interest (Art. 6.1.f) (privacy policy: https://www.cloudflare.com/privacypolicy/); (5) Resend, provided by Resend Inc. (USA), for transactional emails (registration, password recovery) — legal basis: contract performance (Art. 6.1.b) (privacy policy: https://resend.com/legal/privacy-policy); (6) Supabase, provided by Supabase Inc. (USA), for database and authentication — data is stored on EU servers (eu-west-1 region) (privacy policy: https://supabase.com/privacy); (7) Stripe, provided by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland), for the payment of the Pro tier subscription of the MCP service — legal basis: performance of the contract (Art. 6.1.b) — payment data (card, billing address) is collected and stored by Stripe on its own pages; ExplorerHub stores only the customer identifier, the subscription identifier and its status, the plan and the period end, plus the identifier and type of the notified events; invoices and billing data are kept by Stripe for 10 years, in compliance with a legal obligation (privacy policy: https://stripe.com/privacy); (8) Upstash, provided by Upstash, Inc. (a Delaware corporation, United States), for the Redis database with which ExplorerHub counts the requests received by public forms, APIs and the MCP server and enforces rate limits — legal basis: legitimate interest (Art. 6.1.f) — it receives the IP address in clear, or the API key identifier, as the sole counting key, for the duration of the limit window (from one minute to one hour), after which the counter expires and is deleted automatically; no other personal data is sent to it (privacy policy: https://upstash.com/trust/privacy.pdf).

Extra-EU transfers

The database servers (Supabase) are located in the EU (eu-west-1 region). The following services may transfer data to the United States under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023): Google Analytics 4 (only with consent to analytics cookies), Sentry (error monitoring, legal basis: legitimate interest), Cloudflare (CAPTCHA protection), Resend (transactional emails), Vercel (hosting and performance metrics), Upstash (rate-limit counters: IP address only for the duration of the counting window). Vercel Inc. and Upstash, Inc. have certified their adherence to the Framework with the U.S. Department of Commerce and, as a fallback, apply the standard contractual clauses (SCCs) adopted by the European Commission. Without consent to analytics cookies, extra-EU transfers are limited to technical services strictly necessary for the website's operation. Stripe (payments) processes data in the EU through Stripe Payments Europe, Ltd. and may transfer it to Stripe, LLC in the United States under the EU-US Data Privacy Framework, to which Stripe has certified its adherence, and the standard contractual clauses.

Changes to the policy

ExplorerHub reserves the right to modify this policy at any time. In the event of substantial changes, the cookie consent banner will be automatically re-displayed to allow users to express their preferences again. Previous versions can be consulted on the Legal Document Archive page.

Registration and user account

Registration on ExplorerHub is optional. By creating an account, the user provides their email address and may indicate a display name. Data associated with the account includes: user profile, saved bookmarks, search history, preferences (theme, language, notifications) and login logs (last 50 events with anonymised IP). Users can delete their account at any time from the Account Settings page: deletion results in the immediate and irreversible removal of all associated data (Art. 17 GDPR — right to erasure). From the account area the user can also create and revoke API keys for the MCP service and activate the Pro subscription: when the account is deleted, the keys and their usage log are deleted and any Pro subscription is cancelled at Stripe. The only exception is the tax documents of the subscription, which are kept for 10 years at Stripe and in IDCERT's accounting records in compliance with a legal obligation (Art. 17.3.b GDPR).

Contacts and DPO

For any request regarding the processing of personal data or to exercise your rights, you can contact the data controller at the email address indicated above. Pursuant to Art. 37 of the GDPR, the appointment of a DPO (Data Protection Officer) is not currently mandatory for ExplorerHub. Should this change in the future, this section will be updated.

privacy@explorerhub.eu

Last updated: September 2026