← Smia

Privacy Policy

Last updated: 8 August 2026

Smia Technologies AS (“Smia”, “we”, “us”) provides a platform for building, hosting, and running governed MCP tools (“Service”). This Privacy Policy explains how we process personal data when you use smia.io, app.smia.io, our MCP connectors, and related services.

Controller for account, billing, product analytics, and support data: Smia Technologies AS, Tormods vei 19B, 1184 Oslo, Norway. For Customer Content processed inside a hub (tool inputs, outputs, connected-app data you cause the Service to process), the hub (acting through its owner/admin) is the controller and Smia is the processor — see Roles below.

1. Roles (controller vs processor)

Smia is primarily a processor: we take input you or your agents supply, run it through your tool graphs, and return output. We do not decide the purposes of Customer Content beyond providing the Service you configure.

Smia is the controller for: account profiles; authentication; hub membership metadata; billing and subscription records; security logs; support communications; and aggregated product metrics.

The hub owner (or admin acting for the hub) is the contracting customer and controller of Customer Content in that hub. Hub members process Customer Content under that hub’s instructions and policies.

2. What we collect

Account & identity: email, name, password hash (if email signup), social-login identifiers (Google, GitHub, Microsoft), email verification status, Terms acceptance time, marketing-email preference, and session/auth tokens.

Hub & configuration: hub and server settings, roles/grants, tool graphs and metadata, hub environment variable keys (values stored encrypted), Connected App / MCP source connection metadata, and billing plan.

Usage & runs: invocation metering (who called what, when, success/failure, duration). On Pro plans we may also store detailed run history (arguments, results, per-node traces) subject to redaction below. Free/Hobby store metering and may retain the latest test-run detail for debugging.

Customer Content: data you or authorized users/agents send into tools, data retrieved from integrations you connect, and outputs your graphs produce. Ownership of Customer Content remains with the hub (customer).

Marketing site: essential cookies and, only if you accept, analytics cookies (for example Google Analytics) on smia.io.

Support: messages you send to us (including privacy@smia.io).

3. How we use data

We use personal data to: provide and secure the Service; authenticate users; operate hubs, tools, and MCP servers; meter usage and enforce plan limits; bill and collect payment (via Stripe); diagnose errors; provide support; send transactional account email (for example verification and welcome); send occasional product emails only if you opt in; comply with law; and improve the Service as described below.

We do not sell personal data. We do not use Customer Content to serve third-party advertising. We do not use Customer Content to train third-party foundation models.

4. Service improvement and model training

We may use tool graphs, node configurations, prompts and similar structural content, and aggregated or de-identified usage metadata to improve Smia — including reliability, safety, documentation, and Smia’s own tool-creation or assistance models.

We do not use hub environment secrets, OAuth tokens, or fields marked sensitive in stored runs for training. Pro hubs may request an opt-out of using their tool graphs and related structural content for Smia model training (contact privacy@smia.io). Free and Hobby plans include this improvement use as part of the Service.

5. Runs, redaction, and your responsibilities

Tool runs may be stored so you can debug and (on Pro) replay history. Before persistence we redact: keys that look like secrets (for example password, token, api_key, authorization); tool input fields you mark as sensitive; and certain Connected App content fields (for example email/calendar body text) which are stored as metadata-oriented summaries where applicable. Live tool results returned to the caller are not altered by storage redaction.

It is your responsibility to mark sensitive tool inputs and to avoid placing secrets in unmarked fields. Unmarked data in stored runs may be retained on our systems according to plan features. Prefer hub environment variables and OAuth connections for credentials rather than embedding secrets in tool arguments.

6. Secrets and credentials

Hub environment values and OAuth / connection tokens are stored encrypted at rest. They are used only to execute the workflows you configure. They are not intentionally written into run history; secret-like keys and Bearer tokens are redacted if they appear in traced payloads.

7. Legal bases (GDPR)

Where GDPR applies, we rely on: performance of a contract (providing the Service); legitimate interests (security, product improvement as described, fraud prevention — balanced against your rights); consent (non-essential cookies/analytics, and optional product emails); and legal obligation (tax, accounting, lawful requests).

When we act as processor, we process Customer Content on documented instructions from the hub (including your configuration of tools and integrations). A Data Processing Addendum (DPA) is available on request.

8. Sharing and subprocessors

We share data with providers that help us run the Service, for example: cloud hosting in the EU/EEA; Stripe (payments); email delivery (for example Resend); LLM providers you cause the Service to call where configured; object storage for uploads where enabled; OAuth providers you choose (Google, GitHub, Microsoft, and Connected Apps); and marketing-site analytics after consent (for example Google Analytics). We may add providers such as Mixpanel or Sentry later; we will update this Policy when material new subprocessors are added.

When your tools call third-party APIs or MCP servers you configure, those providers receive whatever data your graph sends. Their terms and privacy notices apply to that processing; Smia does not control those services.

We may disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset transfer (with appropriate safeguards).

9. International transfers

Primary hosting is intended in the EU/EEA. Some providers (for example payment, analytics, or social login) may process data outside the EEA. Where required, we use appropriate safeguards such as the EU Standard Contractual Clauses.

10. Retention

Account and hub configuration data are kept while your account/hub is active. After deletion of an account or hub, we aim to delete or irreversibly anonymize associated Customer Content and configuration within 30 days, except data we must retain (billing/tax records, security logs, or dispute records) for longer as required by law or legitimate interests.

Invocation metering rows are stored to operate billing and usage views. Detailed run payloads (args/results/traces) are stored when your plan enables run detail (currently Pro for ongoing product runs; limited test-run detail may exist on other plans). Planned retention windows may be shortened by plan; we may delete or aggregate older telemetry over time.

Backup copies may persist for a limited period after deletion before being overwritten.

11. Your rights

Subject to GDPR and applicable law, you may request access, correction, deletion, restriction, portability, and objection to certain processing, and you may withdraw cookie consent and marketing-email consent (profile toggle, or the unsubscribe link in those emails). Hub-level Customer Content is primarily managed by hub admins (for example by editing/deleting tools or hubs). You can copy tool graphs as JSON from the product.

To exercise rights, email privacy@smia.io. You may lodge a complaint with Datatilsynet (Norway) or your local supervisory authority.

12. Cookies

Essential cookies are required for the Service and marketing site to function (for example session and security). Analytics cookies on smia.io load only after you accept via our banner. We do not use marketing/advertising cookies today. You can reset choice by clearing site data for smia.io.

13. Children

The Service is not directed to children under 18. Do not create an account if you are under 18.

14. Changes

We may update this Policy. Material changes will be posted on this page with an updated date. Continued use after the effective date constitutes acceptance where permitted by law.

15. Contact

Privacy requests: privacy@smia.io. Smia Technologies AS, Tormods vei 19B, 1184 Oslo, Norway.