Privacy Policy
Last updated: 2026.09.14
1. Controller
The controller of your personal data is Metadev S.L., Bormujos, Sevilla, Spain. For any privacy question or to exercise your rights write to: support@structura.tools. This policy is self-contained and does not incorporate any other Metadev privacy policy.
2. Scope
This policy covers personal data processed through the Structura web application, the Structura MCP server at https://mcp.structura.tools, and related APIs and tools.
3. Data we process
- Account data — name, email, organisation, authentication identifiers, and (for paid tiers) billing details processed by our payment provider.
- Your models and projects — the domain models and configuration you create. The MCP connector reads and writes the same account data as the web app; there is no separate or sandboxed copy.
- Generation inputs and outputs — the model and options submitted for a generation job and the artifacts produced, stored in object storage while the job and its result exist.
- Model content submitted through the connector — domain-model or text your MCP client or agent sends to the connector's tools.
- Operational data — request logs (timestamp, tool or endpoint, account id, outcome, IP, user-agent) for security, debugging, abuse prevention and service metering.
- Authentication tokens — the OAuth 2.1 access token issued to your MCP client is validated per request and is not persisted by the server. Your client stores it; treat it as a password. Disconnecting the connector in your client stops further access.
4. Why we process it and legal bases (GDPR Art. 6)
- To provide the Service and perform our contract with you — performance of a contract.
- To secure the Service, prevent abuse, meter usage and debug — legitimate interests.
- To improve the Service using aggregated, de-identified statistics — legitimate interests.
- To send service and security notices — legitimate interests / contract.
- For billing and tax records (paid tiers) — legal obligation / contract.
- Any optional analytics or marketing — only with your consent, withdrawable at any time.
5. Your MCP client and its AI provider
When you use an MCP client (for example Claude, an IDE agent or a CLI), that client and its AI provider are operated by you or by that vendor, not by Metadev. Any model content your agent chooses to send through the connector also passes through that client and provider under their terms and privacy policies. We do not control that processing and are not a processor for it.
6. Sub-processors
We use service providers to run Structura, under data-processing agreements and instructions:
- social login: Google / EU;
- logs and service hosting: Amazon Web Services / EU;
- transactional email: Acumbamail S.L. / Spain;
- payment processing (paid tiers): Stripe / Ireland.
A current list is available on request at support@structura.tools. We will give notice of material changes to this list.
7. International transfers
Where a provider processes data outside the EEA (European Economic Area), we rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards. Details on request.
8. Retention
- Account data — for the life of the account, then deleted or anonymised within 12 months, except records we must keep for legal reasons (e.g. invoices).
- Models and projects — until you delete them (in the web app or via the connector's
delete_projecttool). - Generation artifacts — while the job record exists, then removed within 3 months.
- Operational logs — 12 months.
We do not sell personal data.
9. Your rights
Subject to GDPR, you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests; and withdraw consent where processing is consent-based. Contact support@structura.tools. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local authority.
10. Security
We use OAuth 2.1, encryption in transit, access controls, rate limiting and logging. No system is perfectly secure; we will notify you and the relevant authority of a qualifying personal-data breach as required by law.
11. Cookies
The web application uses strictly necessary cookies for authentication and security. Any non-essential cookies (analytics) are used only with your consent via the cookie banner. The MCP server itself does not use cookies.
12. Children
The Service is not directed to children under 18 (or the local age of digital consent, if higher) and we do not knowingly process their data.
13. Changes
We will post updates at https://structura.tools/legal/privacy with a new "last updated" date and, for material changes, a notice on the Structura documentation and the connector landing page.
14. Contact
Write to support@structura.tools, Metadev S.L., Bormujos, Sevilla, Spain.
See also the Terms of Service.