Privacy Policy

Last updated: January 5, 2026

At Exciting, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.

Exciting (“Exciting”, “we”, “us”, or “our”) is operated by Stackars AB (company registration number 559511-1971).

This Policy applies to users in the European Union, United States, and other jurisdictions, subject to applicable law.

1. Information We Collect

a. Information You Provide

We collect information you voluntarily provide, including:

  • Name and email address
  • Account credentials and authentication information
  • Project configuration, MCP server settings, and usage preferences
  • Billing and payment-related information when payments are enabled

b. Automatically Collected Information

When you use the Service, we collect:

  • IP address
  • Device, browser, and operating system information
  • Logs related to MCP server requests, responses, errors, and performance

c. API Keys and OAuth Tokens

To enable third-party integrations (e.g. GitHub, Slack, Notion), Exciting processes:

  • API keys
  • OAuth access and refresh tokens

These credentials are:

  • Encrypted at rest and in transit
  • Access-controlled on a least-privilege basis
  • Used solely to provide the requested functionality

2. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain the Service
  • Authenticate users and secure MCP server access
  • Process payments and manage billing
  • Monitor reliability, performance, and security
  • Prevent abuse, fraud, and unauthorized access
  • Communicate with users regarding service updates or support
  • Comply with legal and regulatory obligations

For users in the EU/EEA, we process personal data based on:

  • Contractual necessity
  • Consent
  • Legitimate interests, including security, service reliability, and improvement
  • Legal obligations

4. Data Sharing

We do not sell personal data.

We may share data with:

  • Cloud hosting and infrastructure providers
  • Logging, monitoring, and analytics providers
  • Payment processors
  • Legal or regulatory authorities where required by law

All vendors are subject to confidentiality and data protection obligations.

5. International Data Transfers

Personal data may be processed in countries outside your country of residence, including the United States and the European Union.

Where required, we rely on appropriate safeguards such as:

  • Standard Contractual Clauses
  • Equivalent lawful transfer mechanisms

6. Data Retention

We retain personal data only for as long as necessary to:

  • Provide the Service
  • Meet contractual, legal, and regulatory requirements

7. Security Measures

Exciting maintains administrative, technical, and organizational security measures aligned with SOC 2 Trust Services Criteria, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Audit logging and monitoring
  • Incident response procedures

No system is completely secure, but we continuously improve our controls.

8. Your Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete personal data
  • Object to or restrict processing
  • Request data portability

Requests can be submitted to legal@exciting.dev.

9. Third-Party Services

The Service integrates with third-party platforms. Their data practices are governed by their own privacy policies.

Exciting is not responsible for third-party privacy practices.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised “Last updated” date.

11. Contact

Stackars AB
Email: legal@exciting.dev

Questions about our privacy practices?

Contact us at legal@exciting.dev

Contact Us