Privacy policy
Last updated 20 September 2026
This policy explains what data Reddibee collects, why, how long we keep it, and the choices you have. Reddibee is operated by Reddibee (“Reddibee”, “we”, “us”). We are the data controller for the account and usage data described here.
What Reddibee is
Reddibee is a read-only MCP server. It reads public posts on Reddit, X, Hacker News and Product Hunt through their official APIs and returns them, classified and with permalinks, to the AI agent you connect. It never posts, replies, votes, or messages anyone on your behalf. Every tool is read-only and returns structured data plus links back to the original source.
Data we collect about you
- Account details
- Your name, email address and a hashed password when you create an account. We never store your password in plain text.
- API keys
- We store a SHA-256 hash of each key and a short display prefix (for example
rb_live_…), never the key itself. The full key is shown to you once, at creation. - Usage log
- One record per tool call: the tool name, a short summary of the arguments (for example a subreddit or a query), status, and timing. This powers your usage dashboard and enforces the daily cap.
- Watches and alerts
- The saved queries you create, their schedule, and the email address alerts are sent to.
- Billing
- Handled by Stripe. Stripe shares a customer ID, plan, and payment status with us. We never see or store your full card number.
- Support
- Emails you send us and our replies, kept so we can help you and keep a record of the request.
Data about other people
Reddibee returns only public content, fetched through official platform APIs, and only at the thread and community level. We do not build profiles of individual Reddit, X, Hacker News or Product Hunt users, and no tool returns aggregates about a single person beyond the public thread they posted in. We follow the Reddit Public Content Policy and Responsible Builder Policy, and the equivalent terms of the other platforms.
How we use your data
- To run the service and return the results your agent requests.
- To enforce plan limits and the daily request cap.
- To send the watch alerts you asked for.
- To take payment and manage your subscription through Stripe.
- To answer support requests and, rarely, to email you about material changes to the service or these terms.
We do not sell your data, and we do not share it with advertisers or use it to train third-party models.
Legal basis (GDPR)
If you are in the UK or EEA, we process your data on these bases:
- Contract — to provide the service you signed up for (account, keys, usage, watches, billing).
- Legitimate interests — to secure the service, prevent abuse, and understand aggregate usage.
- Legal obligation — to keep the records tax and accounting law requires.
- Consent — where we ask for it, such as optional product emails. You can withdraw it at any time.
Who we share with
We share data only with the sub-processors listed below, and only as needed to run Reddibee. We may also disclose data if the law requires it, to enforce our terms, or to protect the rights and safety of our users. If Reddibee is ever involved in a merger or acquisition, we will tell account holders before their data moves to a new controller.
Sub-processors
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payments and subscriptions | Name, email, billing details, card (held by Stripe) |
| Hosting & database provider | Runs the app and stores account data | All account and usage data |
| Email provider | Sends alerts and account email | Email address, message content |
| Reddit, X, Hacker News, Product Hunt | Source of public content (read-only) | Your queries are sent to their APIs |
Retention
- Request logs are kept for 13 months, then deleted.
- Cached social content is refreshed and pruned on a rolling window.
- Account data is kept while your account is open.
- Deleting your account deletes your keys, watches and log entries within 30 days, except records we must keep by law (such as invoices).
Security
Passwords are hashed. API keys are stored only as SHA-256 hashes. Traffic is encrypted in transit (TLS). Access to production data is limited to the people who need it. No system is perfectly secure, but if a breach ever affects your data we will notify you and the relevant regulator as the law requires.
Your rights
Depending on where you live, you can ask us to:
- Access the data we hold about you, or receive a copy of it.
- Correct data that is wrong or out of date.
- Delete your data (you can delete your account from your dashboard).
- Restrict or object to certain processing, or withdraw consent.
- Export your data in a portable format.
Email privacy@reddibee.com and we will respond within one month. You also have the right to complain to your local data protection authority (in the UK, the ICO).
Cookies
We use one session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
Children
Reddibee is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
International transfers
Our providers may process data outside your country, including in the United States. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses or an equivalent safeguard to protect it.
Changes
We may update this policy. If a change is material, we will email account holders at least 14 days before it takes effect. The date at the top always shows the current version.
Contact
Email privacy@reddibee.com for anything about your data. We answer within five working days.