Privacy Policy
Last updated 15 August 2026.
Rubric is operated by Things Reklam ve Bilişim Hizmetleri Tic Ltd Şti, a limited liability company incorporated in the Republic of Türkiye, which is the controller of the personal data described here. Write to rubric.designmcp@gmail.com about anything on this page.
The short version
We collect what running a metered API requires and nothing else. There are no analytics on this site, no advertising, no third-party trackers and no tracking cookies — which is why you have never seen a cookie banner here. We do not sell or share personal data, and we do not use your audits to train anything.
What we collect
| What | Where it comes from | Why |
|---|---|---|
| Email address, name and avatar URL | Google or GitHub, when you sign in | To identify your account and contact you about it |
| API keys, stored only as a hash | Created by you in the panel | To recognise a key on a call. The key itself is shown once and never stored, so we cannot recover it for you or for anyone else |
| Usage events — which tool, when, what it cost | Your calls | Metering, billing, the free-tier limit, and abuse detection |
| Audits — the URL, vertical and label you give | You, via create_audit |
To store the audit and produce its report |
| Observations you submit against an audit | You, via submit_findings |
To resolve them into findings and keep the report readable later |
| Annotated screenshots your agent captures and uploads against a finding | You, via create_annotations |
To show the evidence for a finding in your panel and in the report you download |
| Payment records — amount, currency, provider identifiers | The payment provider, after a payment | To credit your balance and to keep the accounts |
| Connected applications, if you sign in an agent with OAuth | The authorisation you gave | So you can see and revoke them |
A screenshot is a copy of whatever was on the screen. If your agent captures a page while signed in to an account, or a page showing someone’s name, address or order, that appears in the image and is then stored with your audit. Your agent decides what to capture; we store what it sends. Capture the evidence for the finding and not the surrounding data, and never let an agent enter a password — sign in yourself, in your own browser, and let it look at the result.
What we do not collect
- Card details. The payment provider holds those. They never touch our servers.
- The sites you audit, on our own account. We never crawl, fetch or open them. Your agent does the looking, and only what it chooses to send reaches us: the URL, the observations, and any screenshot it uploads.
- Your password. There isn’t one; sign-in is delegated to Google or GitHub.
-
Test runs. A synthetic URL — localhost, a private IP, a
.test/.local/.examplehost — is never written to the database at all. Not the audit, not the findings, not even the usage event.
Why we are allowed to hold it
Where Türkiye's Personal Data Protection Law (KVKK, Law 6698) applies, we process personal data because performing the contract makes it necessary, because a legal obligation requires it, and on our legitimate interests where they do not override your rights and freedoms. Where the UK GDPR or EU GDPR applies to you, our lawful bases are performance of a contract (running the service you asked for, and billing it), legal obligation (keeping financial records) and legitimate interests (keeping the service secure and working out what to fix).
Who else processes it
We use a small number of providers, each for one job. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and file storage for screenshots | EU (Frankfurt) |
| Netlify | Hosting, CDN and the serverless functions | USA, served from edge locations worldwide |
| Google / GitHub | Sign-in, if you choose that provider | USA |
We are a Turkish company and our database is in the EU, so your data is processed in Türkiye, the EU and the United States. Where transfers out of the UK or EEA need a safeguard, we rely on the standard contractual clauses our providers offer; transfers out of Türkiye rest on the grounds Article 9 of the KVKK allows.
How long we keep it
- Account, audits, findings and screenshots: until you delete the account. Deleting it removes the uploaded image files as well as the rows that point at them.
- Usage events: up to 24 months, because they are what a billing dispute is settled from.
- Payment records: as long as Turkish tax and commercial law requires, which can run to ten years. These survive account deletion because they must.
How it is protected
- Every customer table is closed by default at the database level. The browser never queries the database directly — every read goes through our own server, which applies the account boundary in one place.
- API keys are stored as hashes. A stolen database yields no usable key.
- Two-factor authentication is available on your account and required for administrative access.
- Everything is served over TLS.
No system is perfectly secure. If a breach affects you we will tell you, and any regulator we must, without undue delay.
Your rights
You can ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or portability, and you may object to processing based on legitimate interests. Deleting your account from the panel does most of this immediately: it revokes your keys and connected applications and removes your audits and findings.
For anything else, write to rubric.designmcp@gmail.com and we will answer within 30 days. If you are in Türkiye, you may apply to us first under Article 13 of the KVKK and then complain to the Personal Data Protection Authority (KVKK). If you are in the UK or EEA and think we have got it wrong, you may complain to your data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising a right.
Cookies and storage
The landing page sets nothing. The panel keeps your sign-in session in your browser’s local storage so you are not asked to sign in on every visit, and stores the short-lived verifier that makes the sign-in round trip safe. That is all of it — strictly necessary, no analytics, no advertising identifiers.
Children
Rubric is a developer tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
Changes
We will update this page when what we do changes, and change the date at the top. If a change is material we will tell you at the email on your account before it takes effect.