Skip to main content

legal

Sub-processors

Last updated 2026-09-17

Under GDPR Article 28 we disclose every third party that may process customer personal data on our behalf. The list below is kept current; we notify account holders by email before adding a new sub-processor that handles personal data.

Sub-processorPurposeDataRegion
Lovable Cloud (Supabase)Database, authentication and file storage for accounts, agents, policies, call logs and scan reportsAccount email, gateway configuration, call metadata, scan reportsEuropean Union
CloudflareEdge hosting, CDN, TLS termination and DDoS protection for bouncer.runIP address, request metadataGlobal edge network
SentryError monitoring so broken pages and failed requests can be diagnosedStack traces, browser and request metadata, account identifierEuropean Union
Google (Sign in with Google)Optional identity provider for account sign-inEmail address, name, avatar URLGlobal
x402 facilitator (x402.org)Settlement of optional per-call USDC payments between caller and API ownerPayment amount, wallet addresses, on-chain receiptGlobal / public blockchain
npm registry, OSV.dev and the MCP servers you checkSources queried when you run a Security Check on a package or serverThe package name or MCP address you submittedGlobal

Data Processing Agreement

We sign a DPA incorporating the European Commission's Standard Contractual Clauses for transfers outside the EEA. Request a copy at privacy@bouncer.run.

One-time tokens are not processed by anyone

When you check a private MCP server, the token you supply is used for that single request and is never written to our database or passed to any sub-processor. See the Security Check for how that works.

See also: Privacy Policy · Terms of Service