Privacy policy
This is a translation for convenience. The binding version of this policy is the Spanish one: Política de privacidad. In case of discrepancy, the Spanish text prevails.
<p>
MicroLab is a desktop application that orchestrates microservices
<strong>on your machine</strong>. Most of the product works without sending anything
anywhere. This policy explains the four cases in which information does leave, exactly
what leaves in each, and how to control it.
</p>
<h2>1. Data controller</h2>
<ul>
<li><strong>Controller:</strong> Juan García Valero.</li>
<li><strong>Contact:</strong> [email protected]</li>
</ul>
<h2>2. First things first: what NEVER leaves your machine</h2>
<p>Applies to <strong>all</strong> of the product, on every plan:</p>
<ul>
<li>The <strong>code</strong> of your microservices and the contents of your repositories.</li>
<li>The <strong>output and logs</strong> of the services you orchestrate.</li>
<li>The <strong>data</strong> in your databases, neither their contents nor their dumps.</li>
<li>
Your <strong>credentials, tokens and secrets</strong>. Before anything is sent, a
scrubbing mechanism redacts your home folder path and the values of known credentials.
</li>
<li>
The <strong>values</strong> of the arguments you call a tool with (their
<strong>names</strong> do travel; see §4.2).
</li>
<li>
Your <strong>conversations with the copilot</strong>. They go straight from your
machine to the AI provider you choose, with <strong>your</strong> key: MicroLab
neither brokers nor stores them. That provider's policy governs them, not this one.
</li>
</ul>
<h2>3. A clarification about the word “anonymous”</h2>
<p>
Earlier versions of this policy described the installation identifier as
<strong>anonymous</strong>. It is more accurate to call it
<strong>pseudonymous</strong>: it is a random value that contains neither your name nor
your email, but it does allow one installation to be told from another and its events to
be grouped. Under the GDPR that is still <strong>personal data</strong> (recital 26) and
it is treated as such here. This is corrected because a policy that calls anonymous
something that is not protects nobody. The same applies to your account identifier when
you sign in.
</p>
<h2>4. What processing takes place</h2>
<h3>4.1 Error diagnostics (Sentry)</h3>
<div class="legal-table-wrap">
<table>
<tbody>
<tr><th>What</th><td>Exception message and trace, version, operating system, pseudonymous installation identifier, IP address during transmission</td></tr>
<tr><th>What for</th><td>Fixing defects</td></tr>
<tr><th>Legal basis</th><td>Legitimate interest (art. 6(1)(f)), with one-click objection</td></tr>
<tr><th>Processor</th><td>Functional Software, Inc. (Sentry)</td></tr>
<tr><th>Where</th><td><strong>European Union</strong> region (Germany)</td></tr>
<tr><th>How long</th><td>90 days</td></tr>
<tr><th>Turn off</th><td>Settings → Send diagnostics, or <code>microlab telemetry off</code></td></tr>
</tbody>
</table>
</div>
<p>
Sentry's automatic collection of personal data is not enabled
(<code>sendDefaultPii</code> is off).
</p>
<h3>4.2 Usage records for the AI surface</h3>
<p>
Only if you use the MCP server or the copilot, and <strong>only with telemetry on</strong>:
the same switch governs both.
</p>
<div class="legal-table-wrap">
<table>
<tbody>
<tr><th>What</th><td>Operation name, whether it succeeded, error class, first line of the error (scrubbed), duration, response size, argument <strong>names</strong>, installation identifier, and account identifier if you are signed in</td></tr>
<tr><th>What for</th><td>Tuning which tools are offered to agents and which ones fail</td></tr>
<tr><th>Legal basis</th><td>Legitimate interest (art. 6(1)(f)), with one-click objection</td></tr>
<tr><th>Processor</th><td>Cloudflare, Inc.</td></tr>
<tr><th>Where</th><td>Database in <strong>Western Europe</strong></td></tr>
<tr><th>How long</th><td><strong>90 days</strong>, with automatic daily deletion</td></tr>
</tbody>
</table>
</div>
<p>
Argument <strong>values</strong>, results, paths, and scenario or microservice names
never travel.
</p>
<h3>4.3 Account and free-allowance control</h3>
<p>
Only if you sign in. It is needed for the paid surfaces and for the daily free
allowance; <strong>not</strong> to use the application or the CLI.
</p>
<div class="legal-table-wrap">
<table>
<tbody>
<tr><th>What</th><td>Email, name and the identifier assigned by the identity provider; and your organisation if you belong to one</td></tr>
<tr><th>What for</th><td>Authenticating you, applying your plan and keeping the free-allowance counter <strong>per account</strong> (not per installation: otherwise reinstalling would hand out quota)</td></tr>
<tr><th>Legal basis</th><td>Performance of a contract (art. 6(1)(b))</td></tr>
<tr><th>Processors</th><td>Kinde Inc. (identity) and Cloudflare, Inc. (counter)</td></tr>
<tr><th>How long</th><td>As long as the account exists; the counter, 90 days</td></tr>
</tbody>
</table>
</div>
<h3>4.4 Team scenario catalogue (Team plan, hosted option)</h3>
<p>
Only if your organisation subscribes to the Team plan <strong>and</strong> chooses the
hosted option. With the own-git-repository option, MicroLab stores nothing. Here
MicroLab acts as <strong>processor</strong> and your organisation as controller: it is
governed by the <a href="/dpa">data processing agreement</a>, which prevails over this
policy for that data.
</p>
<div class="legal-table-wrap">
<table>
<tbody>
<tr><th>What is stored encrypted</th><td>The complete scenario, <strong>end-to-end encrypted</strong> with a key belonging to your team that never leaves your machines</td></tr>
<tr><th>What is stored in the clear</th><td>Scenario name and description, organisation code, who published it, date and size</td></tr>
<tr><th>Where</th><td>Storage under <strong>European Union jurisdiction</strong>: Cloudflare guarantees that objects are stored and processed within the EU</td></tr>
<tr><th>How long</th><td>For the duration of the contract; deleted on request or at the end</td></tr>
</tbody>
</table>
</div>
<blockquote>
<p>
<strong>MicroLab cannot read the contents of your scenarios.</strong> This is not a
promise of good behaviour: we do not have the key, and we could not hand them over
readable under a legal request either. <strong>What we do see</strong> is your
organisation's name and the scenario titles: encrypting those too would leave a
useless list of opaque identifiers, and we would rather say so than have it discovered.
</p>
</blockquote>
<h2>5. Processors and international transfers</h2>
<div class="legal-table-wrap">
<table>
<thead><tr><th>Processor</th><th>What for</th><th>Where</th></tr></thead>
<tbody>
<tr><td>Functional Software, Inc. (Sentry)</td><td>Error diagnostics</td><td>EU (Germany)</td></tr>
<tr><td>Cloudflare, Inc.</td><td>Usage records, counter, hosted catalogue</td><td>EU (Western Europe; storage under EU jurisdiction)</td></tr>
<tr><td>Kinde Inc.</td><td>Identity</td><td>See their documentation</td></tr>
</tbody>
</table>
</div>
<p>
Sentry and Cloudflare are US companies. Although storage is in the EU, access by their
staff may constitute an international transfer; both rely on <strong>Standard
Contractual Clauses</strong> and on the <strong>EU-US Data Privacy Framework</strong>.
Up-to-date list at <a href="/en/subprocessors">sub-processors</a>.
</p>
<h2>6. How to exercise your rights</h2>
<p>
You have the right of <strong>access, rectification, erasure, objection, restriction and
portability</strong>.
</p>
<p>
<strong>Erasure, without writing to anybody.</strong> The service exposes an endpoint
that deletes your data on the spot:
</p>
<ul>
<li>
Signed in:
<code>curl -X POST -H "authorization: Bearer <your id_token>" https://mcp.micro-lab.dev/erase</code>
</li>
<li>
Without an account, by installation identifier (given by <code>microlab telemetry info</code>):
<code>curl -X POST "https://mcp.micro-lab.dev/erase?install=<id>"</code>
</li>
</ul>
<p>
It is built this way on purpose: a right that requires opening a ticket and waiting a
month is a right almost nobody exercises.
</p>
<p>
For the other rights, or if you prefer to write: [email protected]. You may also
complain to the Spanish Data Protection Agency
(<a href="https://www.aepd.es" rel="noopener">www.aepd.es</a>).
</p>
<h2>7. Minors</h2>
<p>
MicroLab is a professional development tool, is not aimed at people under 16, and we do
not knowingly collect their data.
</p>
<h2>8. Security</h2>
<p>
Encryption in transit (TLS) for everything sent; end-to-end encryption in the hosted
team catalogue; credential scrubbing before anything is sent; token-restricted access to
the usage dashboard; and the principle that <strong>what does not leave your machine
cannot leak from ours</strong>.
</p>
<p>
In the event of a security breach posing a risk to your rights, we will inform you and
notify the supervisory authority within the GDPR deadlines (72 hours).
</p>
<h2>9. Changes</h2>
<p>
We will publish the version in force with its date. If a change materially affects how
we process your data, we will say so in the application before applying it.
</p>