legal
Sub-processors
Last updated 2026-09-17
Under GDPR Article 28 we disclose every third party that may process customer personal data on our behalf. The list below is kept current; we notify account holders by email before adding a new sub-processor that handles personal data.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Lovable Cloud (Supabase) | Database, authentication and file storage for accounts, agents, policies, call logs and scan reports | Account email, gateway configuration, call metadata, scan reports | European Union |
| Cloudflare | Edge hosting, CDN, TLS termination and DDoS protection for bouncer.run | IP address, request metadata | Global edge network |
| Sentry | Error monitoring so broken pages and failed requests can be diagnosed | Stack traces, browser and request metadata, account identifier | European Union |
| Google (Sign in with Google) | Optional identity provider for account sign-in | Email address, name, avatar URL | Global |
| x402 facilitator (x402.org) | Settlement of optional per-call USDC payments between caller and API owner | Payment amount, wallet addresses, on-chain receipt | Global / public blockchain |
| npm registry, OSV.dev and the MCP servers you check | Sources queried when you run a Security Check on a package or server | The package name or MCP address you submitted | Global |
Data Processing Agreement
We sign a DPA incorporating the European Commission's Standard Contractual Clauses for transfers outside the EEA. Request a copy at privacy@bouncer.run.
One-time tokens are not processed by anyone
When you check a private MCP server, the token you supply is used for that single request and is never written to our database or passed to any sub-processor. See the Security Check for how that works.
See also: Privacy Policy · Terms of Service