← Legal

Privacy Policy

Last updated 5 September 2026

How BotKelp collects, uses, and stores personal data, and the rights you have under the GDPR.

Who we are

BotKelp (“we”, “us”) is the controller of personal data processed through this website, your account, and related API-key and credit services. This policy explains what we process, why, how long we keep it, and how you can exercise your rights.

Questions and data-subject requests: use the contact form at https://www.botkelp.com/contact.

What we collect

We only collect what we need to run the service:

  • Identity from Google or X when you sign in: name, email address, and profile image if the provider supplies them.
  • Account profile: credit balance, premium flag, and created date.
  • API keys: a lookup prefix and a one-way hash. The raw key is shown once at creation and is not stored.
  • Projects you link: name, repository URL, and base branch.
  • Credit purchases: pack, credit amount, price, and time.
  • On-chain single-use payments: wallet address (payer), transaction hash, quote id, amount, and settlement time. These are public on Base; we keep them to match a quote to a generate and to prevent replay.
  • Knowledge queries from a signed-in account or API key: tool name, query text (truncated), retrieved catalog ids, and time. We do not log API keys or source file contents.
  • Session data: a session cookie, and the IP address and user-agent your browser sends while you are signed in.

What we do not collect

We do not run advertising pixels, do not sell personal data, and do not use non-essential analytics cookies. We never store the full API key after the one-time reveal.

Why we process it (legal bases)

Under the GDPR we rely on these bases:

  • Contract (Art. 6(1)(b)): creating an account, issuing and revoking keys, linking projects, adding credits, and providing the dashboard.
  • Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse of keys and credits, and debugging faults. You may object to this processing.
  • Legal obligation (Art. 6(1)(c)): retaining enough purchase information to meet accounting or tax rules where they apply.

Who we share it with

We do not sell your data. We share it only with processors and providers who help us run the service:

  • Google and X, as identity providers for sign-in.
  • Our hosting and database providers, who store account data under contract.
  • The hosted MCP server, which receives an API key you supply as a tool argument so it can check that the key is valid and debit credits.

International transfers

Identity providers and hosting may process data outside the EEA or UK. Where that happens we rely on an adequacy decision or standard contractual clauses, plus the provider’s own transfer tools.

How long we keep it

Account, key, project, and session data are kept while your account is open. If you delete the account we erase that data from the live systems. Purchase rows may be retained in anonymised or legally required form if accounting rules demand it. Session cookies expire with the session.

Your rights

If GDPR or UK GDPR applies to you, you can ask us to:

  • Access a copy of your data (portability: a JSON export from Account).
  • Correct inaccurate data.
  • Erase your account and associated data.
  • Restrict or object to processing based on legitimate interests.
  • Lodge a complaint with your supervisory authority. In Ireland that is the Data Protection Commission; in the UK, the ICO. You may use the authority where you live or work.

How to exercise them

Signed-in users can export or delete their account from the Account page. You can also use the contact form. We will respond within one month, or tell you if we need more time (up to two further months for complex requests).

We may need to confirm it is you before we act. We will not charge for a reasonable request.

Children

The service is for people aged 16 or over. We do not knowingly collect data from children under 16. If you believe we have, contact us and we will delete it.

Automated decisions

We do not make solely automated decisions that produce legal or similarly significant effects. Credit checks and key validation are operational, not profiling of that kind.

Changes

If we change this policy in a material way we will update the date above and, where the change affects you, post a notice on the site or email the address on the account.