01Data controller & contact
The data controller for personal data processed through Sitejump (the “Service”) is miPlug Oy, Business ID FI33419078, Helsinki, Finland.
For any privacy question or to exercise your rights, contact info@miplug.net.
02Scope
This policy applies to the Sitejump website (sitejump.dev), the Sitejump web application, and any related emails or support conversations with miPlug Oy. It does not cover third-party sites we link to, or the Lovable environment where your migrated site is rebuilt — those services have their own policies.
03What we collect
Account
When you sign in with Google we receive your email address, name, and profile picture. We do not receive your Google password.
Migration inputs
The URL you submit, the tier you purchase, and timestamps of activity on your migration.
Crawled content
Publicly reachable HTML, metadata, and referenced assets from the URL you provide. To deliver the migrated site, we may rehost images and other static assets referenced by those pages to our own Supabase Storage bucket so the rebuilt site can serve them reliably. We do not attempt to access authenticated or private areas.
MCP connector
When you connect an AI assistant to your personal MCP connector, we store the OAuth client registration, the authorisation grant, and the access/refresh tokens issued to that assistant (via Supabase Auth’s OAuth 2.1 authorisation server). We also log tool-call metadata — tool name, timestamp, and migration id — so we can operate, debug, and rate-limit the connector. We do not store the assistant’s prompt content except where it is passed to us as an explicit tool argument (for example the URL you ask the audit tool to scan).
Payments
Payments are handled by Stripe. We receive and store a Stripe customer ID, invoice ID, amount, currency, and billing country. We never see or store your full card number.
Chat
The prompts you send to the chat assistants on this site, plus the responses they return, are stored so we can display your session and improve the Service.
Technical data
IP address, user agent, and a coarse country signal (from Cloudflare’s CF-IPCountry header) used for currency display, security, and abuse prevention.
04Legal bases
We process personal data on the following GDPR Article 6 grounds:
- Contract — to deliver the migration you purchased and operate your account.
- Legitimate interest — to secure the Service, prevent abuse, debug issues, and improve the product.
- Consent — where required (e.g. optional marketing emails); you may withdraw consent at any time.
- Legal obligation — Finnish accounting and tax obligations require us to retain invoicing records.
05How we use data
- Deliver the migration and generate your SEO audit.
- Operate your personal MCP connector: authenticate connected AI assistants, authorise tool calls, and enforce per-account scope and quota.
- Process payments, issue invoices, and meet bookkeeping obligations.
- Provide support and respond to your requests.
- Prevent fraud, abuse, and security incidents.
- Improve the Service, evaluate performance, and fix bugs.
06Subprocessors
We rely on trusted subprocessors to run the Service. Each processes personal data on our behalf under a data processing agreement:
- Stripe — payments, invoicing (Ireland / United States).
- Google — authentication via Google OAuth.
- Supabase / Lovable Cloud — managed database and auth hosting (EU region). Supabase Auth also acts as the OAuth 2.1 authorisation server that issues and validates the tokens used by your MCP connector.
- Cloudflare — CDN, edge runtime, DDoS protection.
- Lovable AI Gateway — routes prompts to underlying language models used to produce the audit and migration plan.
07International transfers
Where a subprocessor processes personal data outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and supplementary measures where appropriate. You can request a copy of the transfer safeguards for a specific subprocessor by writing to info@miplug.net.
08Retention
- Account data — kept until you delete your account.
- Migration records, crawled content, and rehosted assets — retained for 90 days after the last activity on the migration, then permanently deleted.
- MCP OAuth clients & tokens — kept while the connector is active; revoked immediately on your request and on account deletion.
- Payment and invoicing records — retained for 6 years, as required by the Finnish Accounting Act (Kirjanpitolaki).
- Chat history — retained for 12 months, then deleted or anonymised.
- Support emails — retained for 24 months.
09Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”), subject to legal retention;
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your local supervisory authority.
To exercise any of these rights, email info@miplug.net. We respond within 30 days and may need to verify your identity before acting.
11Security
We use TLS for data in transit, encryption at rest via our platform providers, row-level security in the database, least-privilege service credentials, and Stripe-hosted card capture (keeping us in PCI SAQ-A scope). No system is perfectly secure — if you believe you’ve found a vulnerability, please email info@miplug.net.
12AI transparency (EU AI Act)
Sitejump uses artificial intelligence. Both chat assistants on this site — the site assistant and the audit assistant — are AI systems, not people, and they identify themselves as such at the start of every conversation. If you would prefer to speak with a human, email info@miplug.net.
Audits, improvement plans, rebuild prompts, SEO notes and the written reports in your migration package are generated by AI from a crawl of your live website. They are marked as AI-generated wherever you read them — in the chat, in the connector output relayed to your AI assistant, and in the exported files. They are suggestions, not professional advice: please review them before acting on them.
We do not use AI for emotion recognition, biometric categorisation, or automated decision-making that produces legal or similarly significant effects about you. We do not generate deepfakes or synthetic images or audio of real people; screenshots and assets in your package are captured from your own site, not synthesised.
Model providers are listed under Subprocessors. Your chat messages and crawled page content are sent to those providers only to produce your audit, and are not used by us to train models.
13Children
Sitejump is a professional tool intended for people who own or operate a website. It is not directed to children under 18, and we do not knowingly collect personal data from them. If you believe we hold data about a child, contact us and we will delete it.
14Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app and, where appropriate, by email to the address on your account. The “Last updated” date at the top of this page always reflects the current version.
15Contact
Privacy questions or requests: info@miplug.net. Postal address: miPlug Oy, Helsinki, Finland. Business ID: FI33419078.
