These terms sit on top of the business terms you already agreed to. They are written to be read. Where they and the business terms differ about the API, these win.
MyBookr LTD (“Bookr”, “we”), registered in England & Wales, and the business that holds the Bookr account whose key is being used (“you”). If a developer, agency or AI assistant uses a key on your behalf, you are responsible for what they do with it.
mybookr.app/api/v1 — read and, with the right scopes, manage your own business's data.mybookr.app/mcp — the same operations, for AI assistants that speak the Model Context Protocol.All three are part of the Pro plan. A key for a business on a lower plan is refused until the plan changes. Everything is documented at mybookr.app/developers; the documented behaviour is what we commit to.
read:catalog, read:bookings, read:reviews) may be placed on a public website. A key with read:customers, write:customers or any other write scope must be kept server-side or in a tool you control.Customer details your key reads through read:customers — names, emails, phones, your notes — are personal data of which you are the controller under UK GDPR, and Bookr is your processor, exactly as in the app. You must have a lawful basis for what you do with them, keep them safe wherever your systems put them, honour customers' rights, and not use them for marketing they have not consented to. Do not pass them to a third party (including an AI service) unless you are satisfied that doing so is lawful and your customers would expect it.
We run the API on the same infrastructure as Bookr itself and aim for it to be available whenever Bookr is; we do not promise a specific uptime. We may add endpoints and fields at any time. We will not remove or rename an endpoint, or narrow what a scope allows, without at least 30 days' notice on the developer page — except where security requires it, in which case we will tell you afterwards.
We are not responsible for what your own website, tools or an AI assistant do with the data or the operations the API gives them, for bookings they create or cancel on your instruction, or for a key you did not protect. Our liability to you for the API, the MCP server and the embed is limited in the same way as under the business terms.
You can stop using the API at any time by revoking your keys. Closing your Bookr account revokes every key. We can suspend a key immediately where we reasonably believe it is being misused, and will tell you why.
Email support@mybookr.app. For anything about how we handle data, see the privacy policy.