GummbleGummble
AppsPricing
Share & Earn

Security & procurement

Your data stays yours.

Gummble connects through OAuth, operates with read-only tools, and encrypts all traffic in transit. Here is how we keep your information safe and what we are building next.

Send procurement requirementsRead the privacy policy

At a glance

Read-only tools, encrypted access, and transparent practices.

MCP tools
14
Write tools
0
MCP auth
OAuth
Reviewed
July 26, 2026

Controls in place

A narrow, account-bound research surface.

01

OAuth-protected access

Remote MCP access uses OAuth. Access tokens are signed, issuer-checked, audience-bound to the Gummble MCP resource, and associated with an individual Gummble account.

02

Read-only tool surface

All 14 MCP tools are declared read-only and non-destructive. They search and return Gummble library content; they cannot write to your codebase, design files, projects, or documents.

03

Encrypted in transit

Traffic to Gummble is encrypted in transit. Backend access is tied to the authenticated user so plan entitlements and rate limits can be enforced per account.

04

Scoped operational logging

For MCP requests, Gummble records the account, tool called, time, result metadata, and sanitized search terms. Common identifiers and secrets are redacted before analytics capture.

What the MCP service handles.

Gummble receives tool requests, not the surrounding conversation in your AI client. Search terms are operational data and should not contain secrets or confidential customer information.

AI conversation content
Not received or stored by Gummble.
Customer files and documents
Not uploaded or stored by the MCP server.
MCP usage data
Tool activity and sanitized search data; retained for up to 24 months.
Account deletion
Personal data is deleted within 30 days, except records retained for legal or billing reasons.

Service providers

Core subprocessors and infrastructure.

These providers support delivery, operations, analytics, and billing. The privacy policy controls if this summary and the policy ever differ.

CloudflareMCP edge runtime, content delivery, and storage
VercelWeb application hosting
RailwayAPI hosting
PostHogProduct analytics
SentryError monitoring
PolarSubscription billing and payment processing

Enterprise roadmap

Growing with you.

SOC 2 / ISO certification

Planned

Formal SOC 2 and ISO 27001 certification are on our roadmap. This page reflects the controls we follow today — reach out if you need details for your review.

SAML / enterprise SSO

Planned

The current Team plan supports account-based access and domain join. SAML and enterprise SSO are planned for a future release.

Standard DPA

Available on request

We can work with your data processing terms. Reach out at the address below and we will review your requirements directly.

Contractual uptime SLA

Coming soon

A contractual uptime commitment and public status page are in development. We are happy to share current availability data on request.

Questions? We are here to help.

Let us know what you need.

Whether it is a security questionnaire, a specific compliance requirement, or just a quick question — we are happy to help.

enterprise@gummble.com
Gummble

Browse thousands of curated UI screenshots from the world's best apps. Find design inspiration for your next project.

Browse

  • Browse Apps
  • App Design Inspiration
  • Browse Flows
  • Browse Screens
  • Browse Patterns

Categories

  • All Categories
  • Dating Apps
  • AI Photo Editors
  • AI Chatbots
  • Finance Apps
  • Budget Planners
  • Habit Trackers
  • Language Learning

UI Patterns

  • Onboarding
  • Login
  • Checkout
  • Empty States
  • Search
  • Settings

Company

  • Pricing
  • Gummble UI Design MCP
  • MCP for AI App Builders
  • Mobbin Alternative
  • Mobbin MCP Alternative
  • Refero Alternative
  • About
  • Blog
  • Support
  • Affiliate Program

© 2026 Gummble. All rights reserved.

SecurityPrivacyTerms