Privacy Policy
Last updated: 24 August 2026
MyDepot is a web application. This page explains which personal data the service needs, why it needs it, where it lives, and how you can ask for it to be corrected or deleted.
If you connect Google, the disclosures that Google OAuth verification requires are in section 3 (Google user data): what is accessed, how it is used, with whom it is shared, how it is protected, and retention and deletion.
1. Controller
The controller of personal data processed through MyDepot is:
Antonio Molinari
Via Caselle 6
26032 Ostiano (CR), Italy
Email: support@m6i.it
Site: https://m6i.it
Service: https://app.MyDepot.it
In this document “MyDepot”, “I”, and “the service” refer to that person acting as a natural person, not as a company.
2. What MyDepot does
MyDepot lets you create an account, sign in with email or Google, call an HTTP API, and connect an assistant through the Model Context Protocol (MCP). A command-line tool may also be available for the same backend.
A free plan is available. A paid plan with extra features is planned. When billing starts, this policy and the terms will say which payment provider is used. Card numbers will not be stored on MyDepot’s servers.
3. Google user data
This section describes Google user data accessed through Google Sign-In for authentication only. MyDepot’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
MyDepot uses Google only to sign you in. It does not request access to Google Calendar or other Google products beyond the basic profile information needed for login.
3.1 What Google user data is accessed
When you choose Google Sign-In, MyDepot requests only these OAuth scopes:
https://www.googleapis.com/auth/userinfo.email(also requested asemail) — the email address of the Google account you sign in with.https://www.googleapis.com/auth/userinfo.profile(also requested asprofile) — basic profile such as display name and profile picture URL.
From those APIs MyDepot may receive, and in some cases store:
- Identity: Google account email, display name, and profile picture URL used to create or match your MyDepot account.
- Provider identifier: the Google account id used to link sign-in to your MyDepot user record.
MyDepot does not request Gmail, Drive, Calendar, Contacts, or other Google products. It does not access Google user data until you complete Google’s consent screen.
3.2 How Google user data is used
Google user data is used only to operate MyDepot for you:
- sign you in (or link an existing MyDepot account) with Google;
- show your name and avatar in the interface when you are logged in;
- diagnose faults that affect sign-in (for example an expired token), including error reports that may contain identifiers such as user id or email.
MyDepot does not use Google user data to:
- serve advertising or build advertising profiles;
- sell or rent the data;
- determine creditworthiness or lend it to others for that purpose;
- train, develop, or improve generalized or non-personalized artificial intelligence or machine-learning models.
Human access by the operator is limited to providing the service, support you request, and security or abuse investigation.
3.3 With whom Google user data is shared, transferred, or disclosed
I do not sell Google user data. I do not share it with advertisers or data brokers. It is disclosed only as follows:
- You — in the MyDepot web app when you are signed in.
- The operator (Antonio Molinari) — as controller, with access limited to running the service, support, and security.
- Hetzner Online GmbH — hosting in Germany. The application database (including account data linked to Google Sign-In) and operational logs live on that server.
- Google — during the OAuth sign-in flow. Google remains the independent controller of your Google account.
- Functional Software, Inc. (Sentry) — error monitoring. Crash reports may include user identifiers, request path, and, incidentally, fragments of request data. They are used to fix faults.
- MCP or API clients you authorise — those clients receive the responses you ask for through the HTTP API or MCP interface. After data leaves MyDepot, that client’s own terms apply.
- Legal obligation — if a competent authority lawfully requires disclosure, or if it is strictly necessary to protect the service or users against abuse or crime.
Google Fonts may receive your IP address when the web interface loads typefaces. That is ordinary page delivery, not a transfer of Google Sign-In data.
3.4 Data protection for Google user data
MyDepot treats Google Sign-In data as confidential account data and applies these measures:
- Encryption in transit: HTTPS/TLS between your browser and MyDepot, and between MyDepot and Google’s OAuth endpoints.
- Access control: production server and database access is limited to the operator. Your account data is tied to your MyDepot account; other users cannot read it through the product.
- Credential hygiene: account passwords and API keys are stored hashed. Sign-in secrets are not published.
- Minimisation: only the scopes listed above are requested.
- Environment: the app runs on a dedicated Hetzner server in Germany, with PostgreSQL and TLS at the reverse proxy.
- Revocation: you can sign out of MyDepot and revoke access in your Google Account permissions.
No method of storage or transmission is perfectly safe. If a breach affecting Google user data is confirmed, I will notify you and the authorities when the law requires it.
3.5 Retention and deletion of Google user data
While your account exists: email, name, avatar URL, and the Google provider link are kept so you can sign in with Google again.
How to delete Google user data from MyDepot without closing the Google account itself:
- Optionally revoke MyDepot in Google Account → Third-party access.
- To erase the MyDepot account and remaining copies (profile data, API keys), contact an administrator or email support@m6i.it from the address on the account. After identity checks (when you write in), deletion from live systems starts without undue delay.
Residual backups of the server disk may hold copies for a short technical window; they are not put back into ordinary use and expire with the backup cycle.
4. Other categories of data
Account
Email address, name, password hash (if you register with email), profile picture URL if Google Sign-In provides one, language preference, and role metadata (for example whether the account is an administrator).
Google Sign-In
See section 3. In short: email, name, and profile picture from Google when you choose Google Sign-In.
API keys, CLI, and MCP
Hashed API keys if you create them. OAuth client registrations, authorisation codes, and access or refresh tokens if you connect an MCP client.
Technical and security data
IP address, browser and device information, requested URLs, timestamps, and diagnostic logs needed to run and protect the service. Invitation codes may be stored in a technical cookie while you sign up.
MyDepot is not meant for health data, judicial data, biometric data, or data about children as an ordinary use of the product. Do not upload that kind of material.
5. Purposes and legal bases
- Running the account and the product (sign-in, CLI, API, MCP): performance of a contract, Art. 6(1)(b) GDPR.
- Google Sign-In: you start that connection yourself; processing follows from the contract and from the permission you grant in Google’s consent screen.
- Security, abuse prevention, error diagnosis: legitimate interest in keeping the service usable and safe, Art. 6(1)(f) GDPR.
- Answering support requests: contract and, where needed, legitimate interest.
- Legal duties (for example tax records once paid plans exist): Art. 6(1)(c) GDPR.
- Optional tracking: none is active today. If non-essential cookies are added later, they will run only with consent, Art. 6(1)(a) GDPR. See the cookie policy.
Google Sign-In data is used only to authenticate you and show your profile in the app. It is not used for advertising, resale, or training general-purpose models. Details for Google user data are in section 3.2.
6. Where data is processed
The application runs on a dedicated server in Germany, operated by Hetzner. The stack is a containerised Ruby on Rails app with a local SQLite database on disk, TLS at the reverse proxy, and background jobs on the same host. There is no separate analytics warehouse.
Some processing happens at other providers because the product cannot work without them, as listed below. I prefer to keep the primary copy of account data in the EU.
7. Recipients and processors
I do not sell personal data. Access is limited to me, to you (for your own account), and to the providers needed to deliver MyDepot. Those providers act as processors or as independent controllers, depending on the service. Recipients of Google user data are listed in section 3.3.
Hetzner Online GmbH
Role: hosting and infrastructure in Germany.
Data: the application database, files, and operational logs.
Location: Germany (EU).
Role: Sign-In only. Google is an independent controller of your Google account. MyDepot uses Google as a source of identity when you authorise it.
Data: profile and email on sign-in. See section 3.1.
Location: processing may occur in the EEA and in other countries, under Google’s terms and the transfer tools Google publishes (including adequacy decisions or standard contractual clauses where they apply).
Functional Software, Inc. (Sentry)
Role: error monitoring so crashes can be fixed.
Data: stack traces, request path, and, with personally identifiable information enabled, identifiers such as user id, email, IP address, and user agent. Request parameters may be included; they are minimised where practical.
Location: the project is configured to send events to Sentry’s European ingest endpoint. Residual processing outside the EEA cannot be excluded and, if it occurs, relies on the safeguards Sentry documents for that transfer.
Google Fonts
The web interface may load typefaces from Google’s font servers. Those requests can expose your IP address and user agent to Google. They are used only to render the interface, not to profile you for MyDepot.
Assistants you connect (MCP)
If you authorise a third-party client (for example a desktop assistant) to call MyDepot over MCP, that client receives the API responses you ask for. After the data leaves MyDepot, that provider’s own terms apply. Disconnect the client if you no longer want it to have access.
Future payment provider
When a paid plan is offered, checkout will be handled by a specialised billing provider. MyDepot will receive status of the subscription, not the full card number. This section will name the provider before paid checkout goes live.
8. International transfers
Hosting is in Germany. Google Sign-In, font delivery, and error monitoring may involve processing outside the EEA. Where that happens, the transfer rests on an adequacy decision, standard contractual clauses, or another mechanism allowed by Chapter V GDPR, as published by the relevant provider.
9. Retention
- Account and Google Sign-In link: kept while the account exists. Google-specific retention and deletion are in section 3.5.
- API keys and MCP tokens: kept until you revoke them or the account is closed.
- Technical logs and error events: kept only as long as useful for security and debugging, then overwritten or deleted.
- Invitation cookie: until it is used or you clear site data.
- Backups of the server disk may retain copies for a short technical window after deletion from the live database.
You can revoke Google access in your Google account settings, or delete the whole account by contacting support. To delete the account another way, write to support@m6i.it from the address on the account. After identity checks, erasure from live systems starts without undue delay. Residual backup copies are not put back into ordinary use and disappear when the backup cycle ends. Legal retention (for example invoices, once billing exists) is limited to that purpose.
10. Your rights
If GDPR applies to you, you may request access, rectification, erasure, restriction, objection, and portability, and you may withdraw consent where processing is based on consent, without affecting earlier lawful use. You may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or with the authority of your EU/EEA country of residence.
Use support@m6i.it. I will answer within one month, with the extensions GDPR allows for complex cases.
11. Children
MyDepot is not directed at people under 16. I do not knowingly collect their data. If you think a child created an account, contact me and I will delete it.
12. Security
Traffic to the app is encrypted in transit (HTTPS). Passwords are stored as hashes. API keys are stored hashed. Production access is limited to the operator. Error reports help detect failures. Measures specific to Google user data are in section 3.4. No method of storage or transmission is perfectly safe.
13. Related documents
Use of the product is also governed by the terms and conditions. Cookies and similar storage are described in the cookie policy.
14. Changes
This page will change when the product, the hosting, or the law requires it. The date at the top is the current version. Continued use after an update means you have seen the new text; if a change is material, I will try to flag it in the app or by email when I have an address for you.