Skip to content
Rubric

Privacy Policy

Last updated 15 August 2026.

Rubric is operated by Things Reklam ve Bilişim Hizmetleri Tic Ltd Şti, a limited liability company incorporated in the Republic of Türkiye, which is the controller of the personal data described here. Write to rubric.designmcp@gmail.com about anything on this page.

The short version

We collect what running a metered API requires and nothing else. There are no analytics on this site, no advertising, no third-party trackers and no tracking cookies — which is why you have never seen a cookie banner here. We do not sell or share personal data, and we do not use your audits to train anything.

What we collect

What Where it comes from Why
Email address, name and avatar URL Google or GitHub, when you sign in To identify your account and contact you about it
API keys, stored only as a hash Created by you in the panel To recognise a key on a call. The key itself is shown once and never stored, so we cannot recover it for you or for anyone else
Usage events — which tool, when, what it cost Your calls Metering, billing, the free-tier limit, and abuse detection
Audits — the URL, vertical and label you give You, via create_audit To store the audit and produce its report
Observations you submit against an audit You, via submit_findings To resolve them into findings and keep the report readable later
Annotated screenshots your agent captures and uploads against a finding You, via create_annotations To show the evidence for a finding in your panel and in the report you download
Payment records — amount, currency, provider identifiers The payment provider, after a payment To credit your balance and to keep the accounts
Connected applications, if you sign in an agent with OAuth The authorisation you gave So you can see and revoke them

A screenshot is a copy of whatever was on the screen. If your agent captures a page while signed in to an account, or a page showing someone’s name, address or order, that appears in the image and is then stored with your audit. Your agent decides what to capture; we store what it sends. Capture the evidence for the finding and not the surrounding data, and never let an agent enter a password — sign in yourself, in your own browser, and let it look at the result.

What we do not collect

Why we are allowed to hold it

Where Türkiye's Personal Data Protection Law (KVKK, Law 6698) applies, we process personal data because performing the contract makes it necessary, because a legal obligation requires it, and on our legitimate interests where they do not override your rights and freedoms. Where the UK GDPR or EU GDPR applies to you, our lawful bases are performance of a contract (running the service you asked for, and billing it), legal obligation (keeping financial records) and legitimate interests (keeping the service secure and working out what to fix).

Who else processes it

We use a small number of providers, each for one job. They act on our instructions and may not use your data for their own purposes.

Provider What it does Where
Supabase Database, authentication and file storage for screenshots EU (Frankfurt)
Netlify Hosting, CDN and the serverless functions USA, served from edge locations worldwide
Google / GitHub Sign-in, if you choose that provider USA

We are a Turkish company and our database is in the EU, so your data is processed in Türkiye, the EU and the United States. Where transfers out of the UK or EEA need a safeguard, we rely on the standard contractual clauses our providers offer; transfers out of Türkiye rest on the grounds Article 9 of the KVKK allows.

How long we keep it

How it is protected

No system is perfectly secure. If a breach affects you we will tell you, and any regulator we must, without undue delay.

Your rights

You can ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or portability, and you may object to processing based on legitimate interests. Deleting your account from the panel does most of this immediately: it revokes your keys and connected applications and removes your audits and findings.

For anything else, write to rubric.designmcp@gmail.com and we will answer within 30 days. If you are in Türkiye, you may apply to us first under Article 13 of the KVKK and then complain to the Personal Data Protection Authority (KVKK). If you are in the UK or EEA and think we have got it wrong, you may complain to your data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising a right.

Cookies and storage

The landing page sets nothing. The panel keeps your sign-in session in your browser’s local storage so you are not asked to sign in on every visit, and stores the short-lived verifier that makes the sign-in round trip safe. That is all of it — strictly necessary, no analytics, no advertising identifiers.

Children

Rubric is a developer tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.

Changes

We will update this page when what we do changes, and change the date at the top. If a change is material we will tell you at the email on your account before it takes effect.