1. What We Collect
MQTTBridge collects the minimum information needed to run the service reliably and securely.
Account information: Your email address and hashed password when you register. Provided and managed by Supabase Auth.
Subscription configuration: MQTT broker URLs, topics, optional usernames and passwords (stored AES-256-CBC encrypted), and display labels you choose.
Device messages: The payloads published to your subscribed MQTT topics. Stored so you can view history, build dashboards, and trigger alerts. The number of messages stored and how long they are retained depends on your plan (7 days on Free, 60 days on Builder, 1 year on Pro).
Alert rules and logs: Threshold conditions you configure, and a log of when those conditions were triggered.
API keys: Labels and SHA-256 hashes of keys you generate. Raw key values are shown once and never stored.
Telegram chat IDs: If you enable Telegram alert notifications, the numeric chat IDs you provide to route alerts to your bot.
Billing information: If you subscribe to a paid plan, Polar (polar.sh) processes and stores your payment details as the Merchant of Record. MQTTBridge stores only your Polar subscription ID, current plan name, billing period, and renewal date — never raw card details.
Usage data: Standard server-side logs including IP addresses, request timestamps, and HTTP status codes for security monitoring. No third-party analytics trackers are used.
2. How We Use Your Data
Data collected is used solely to operate and improve MQTTBridge:
- Authenticating you and keeping your session secure
- Maintaining live MQTT broker connections on your behalf
- Storing and displaying your device message history within your plan limits
- Evaluating your alert rules and sending Telegram and email notifications
- Serving shared dashboard views to recipients you authorise
- Processing API key authentication for programmatic access
- Processing payments and managing your subscription plan via Polar
- Enforcing plan limits and notifying you when limits are approached
- Debugging errors and detecting abuse or security incidents
Your data is never used for advertising, profiling, or sale to third parties.
3. Your MQTT Data
Your sensor payloads, broker credentials, and device configuration are yours. MQTTBridge acts as a processor, not a controller, of that data — it is only accessed to deliver the service you configured.
Broker credentials (usernames and passwords) are encrypted at rest using AES-256-CBC before storage. The encryption key is held separately from the database.
Shared view links expose live dashboard data from a subscription or group to anyone with the link. The volume of data visible depends on your plan. You control when links are generated and can revoke them at any time. Active viewers lose access within 30 seconds of revocation.
4. Storage & Security
All data is stored in a Supabase-managed PostgreSQL database with encryption at rest and in transit. All connections between MQTTBridge and your browser are TLS-encrypted.
Application-layer protections include:
- AES-256-CBC encryption for broker credentials
- SHA-256 hashing for API keys (raw values are never persisted)
- bcrypt hashing for shared dashboard link passwords
- Session tokens validated server-side on every request
- Input sanitisation and output encoding on all user-supplied content
- SSRF protection blocking connections to private network ranges
- Rate limiting on all routes with three sensitivity tiers
If you believe you have found a security vulnerability, please report it here.
6. Data Retention
Data is retained for as long as your account is active, subject to the following:
- Messages: rolling window based on your plan (7 days / 60 days / 1 year). Oldest messages are pruned automatically.
- Alert logs: last 50 entries on Free, 200 on Builder, unlimited on Pro
- Billing records: Polar retains payment history as required by financial regulations
- Account data: retained until you delete your account
- Server logs: purged on a rolling 30-day basis
When you delete your account, all associated data — subscriptions, messages, alert rules, logs, API keys, and settings — is permanently deleted in cascade. Active paid subscriptions should be cancelled before deletion. This action is irreversible.
7. Your Rights
You have the right to:
- Access the personal data held about you
- Correct inaccurate information in your account settings
- Export your message data (JSON or CSV) directly from the dashboard
- Delete your account and all associated data from Settings → Danger Zone
- Withdraw consent for Telegram notifications by removing your chat ID from Settings
- Cancel a paid subscription at any time from Settings → Plan & Billing
To exercise any right not covered by in-app controls, contact us here. Responses are provided within 14 days.
9. Third-Party Services
MQTTBridge integrates with the following external services:
- Supabase — database, authentication, and real-time infrastructure (supabase.com/privacy)
- Polar — payment processing and Merchant of Record for paid plans. Card details are handled entirely by Polar and never seen by MQTTBridge (polar.sh/legal/privacy)
- Resend — transactional email delivery for alert notifications (resend.com/privacy)
- Telegram — optional alert delivery via your own bot (telegram.org/privacy)
MQTTBridge connects to MQTT brokers you specify, including public brokers like HiveMQ. No control over or responsibility for the privacy practices of those brokers is held.
10. Changes to This Policy
This policy may be updated as the service evolves. Material changes will be communicated by updating the effective date at the top of this page and by emailing your registered address for significant changes.
Continued use of MQTTBridge after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
Questions about this policy or your data: