Privacy policy

What personal data mcp.tc handles, why, for how long, and what you can ask us to do about it.

read.updated

Who is responsible

The data controller is Marco Costantino, Italy. For anything about your data, write to privacy@mcp.tc. No data protection officer has been appointed, because the law doesn’t require one for a project of this kind.

What we process and why

WhatDataWhy, and on what basisHow long
Visiting the siteIP address, date and time, the page requested, response code, referring page and browser user agent, in our web server’s logsRunning the site and keeping it secure, and counting how often each listing is viewed. Legitimate interest, GDPR art. 6(1)(f).14 days, then deleted. To count each listing view once a day, a keyed hash of your IP address is kept in memory for up to 24 hours, then discarded.
An MCP client pointed at a quick linkYour MCP client connects to a listed server directly, without us. If a client is given a quick link instead, our server answers with an error that names the server’s own URL or install command, and passes nothing on to the listed server. These requests aren’t written to our access log; a failed request can appear in the error log with your IP address.Telling the client where the server really is. Legitimate interest, art. 6(1)(f).Nothing is kept. A failed request can appear in the error log, kept 14 days.
Seeing an mcp.tc badge, card or iframe on another siteYour browser fetches the file from mcp.tc, which sees your IP address like any web server. Cloudflare usually answers badge and card requests from its cache; the iframe comes from our server each time. Requests for these files aren’t written to our access log, the files set no cookies, and the badge and card load nothing else.Showing the embed the site’s owner added. Legitimate interest, art. 6(1)(f).Nothing is kept. A failed request can appear in the error log, kept 14 days.
Suggesting a serverThe URL you submit, your optional note, the time, and a keyed hash of your IP addressHandling the suggestion and preventing abuse. Legitimate interest, art. 6(1)(f).Up to 12 months, or as long as the listing it created exists
Verifying a listingThe listing, the domain you picked, the time, what our DNS lookups found, and a keyed hash of your IP address. We keep a request only when we find the DNS record.Handling the request and preventing abuse. Legitimate interest, art. 6(1)(f).The IP hash 30 days; the request up to 12 months after it’s decided, or as long as the checkmark it granted stays
Rate limitingA keyed hash of your IP address and a counterStopping floods of submissions, verification attempts and requests to our MCP server at /mcp. Legitimate interest, art. 6(1)(f).Up to 2 days
Checking a suggestion with AIThe URL you submitted, your note, and public information about the server (its manifest, tool list, repository and package pages). Never your IP address.Drafting and reviewing the listing. Legitimate interest, art. 6(1)(f).Sent to Anthropic for the check; retention on their side follows Anthropic’s terms
Analytics, only if you acceptPseudonymous identifiers in cookies, pages viewed, rough location, device and browser detailsCounting visits to see what people use. Your consent, art. 6(1)(a) and art. 122 of the Italian Privacy Code.14 months in Google Analytics; cookies as listed in the cookie policy
Writing to usYour email address and what you writeAnswering you, and keeping a record of reports and requests. Legitimate interest, art. 6(1)(f), or a legal obligation for reports under the Digital Services Act, art. 6(1)(c).As long as the conversation needs, then up to 24 months

We back up the database once a day and keep each backup for 14 days, so data deleted from it (suggestions, rate-limit hashes) can stay in a backup for up to 14 more days.

Your theme choice, your analytics choice and the setup tab you last picked are stored in your own browser, not on our server. The cookie policy explains them.

People named in listings

Listings describe software, but they can include personal data: the name or username of a server’s maintainer, links to their repository or website, and similar details. We take these from public sources only: the server’s own MCP metadata and server card, the official MCP Registry, GitHub, npm and PyPI. We publish them because a directory has to say who makes a server (legitimate interest, art. 6(1)(f)). They stay as long as the listing does. You can ask us to correct or remove them at any time, and you can object to the processing; see your rights.

Who else sees data

  • OVH SAS (France) hosts the server that runs mcp.tc.
  • Cloudflare, Inc. sits in front of the site as a content delivery network and firewall, so it sees every request, including your IP address.
  • Anthropic PBC runs the AI model that reviews suggested servers and translates listings into other languages. It receives the data listed above for that check, and only the listings’ public text for the translations.
  • Google Ireland Ltd and Google LLC receive analytics data, and only after you accept analytics. Google signals and ad personalization are turned off for our property.

We don’t sell data or share it with advertisers.

Transfers outside the EU

Cloudflare, Anthropic and Google are based in the United States or share data with US companies. Those transfers rely on the EU-US Data Privacy Framework (Commission decision 2023/1795) for certified companies, and on the European Commission’s standard contractual clauses otherwise.

Automated decisions

Whether a suggested server is listed is decided partly by automated checks and the AI reviewer, with a person reviewing anything they can’t confirm. The decision is about software, not about you, and has no legal or similarly significant effect on anyone, so art. 22 GDPR doesn’t apply. You can still ask a person to look at any decision.

Your rights

You can ask to see the personal data we hold about you, have it corrected or deleted, restrict how we use it, or receive it in a portable format. You can object to processing based on legitimate interest, and you can withdraw consent to analytics at any time with the Cookie settings link in the footer; withdrawing doesn’t affect what happened before. Write to privacy@mcp.tc. We answer within one month.

If you think we got something wrong, you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali, or to the authority where you live or work.

What you have to give us

Nothing. You can use the site without giving us any personal data. The submit form needs only a server URL; the note is optional, and since it goes to the AI reviewer, please leave personal details out of it.

Changes to this policy

When we change how we handle data, we update this page and the date at the top. If a change means we need your consent again, the cookie banner asks for it.