Privacy policy
What personal data mcp.tc handles, why, for how long, and what you can ask us to do about it.
read.updated
Who is responsible
The data controller is Marco Costantino, Italy. For anything about your data, write to privacy@mcp.tc. No data protection officer has been appointed, because the law doesn’t require one for a project of this kind.
What we process and why
| What | Data | Why, and on what basis | How long |
|---|---|---|---|
| Visiting the site | IP address, date and time, the page requested, response code, referring page and browser user agent, in our web server’s logs | Running the site and keeping it secure, and counting how often each listing is viewed. Legitimate interest, GDPR art. 6(1)(f). | 14 days, then deleted. To count each listing view once a day, a keyed hash of your IP address is kept in memory for up to 24 hours, then discarded. |
| An MCP client pointed at a quick link | Your MCP client connects to a listed server directly, without us. If a client is given a quick link instead, our server answers with an error that names the server’s own URL or install command, and passes nothing on to the listed server. These requests aren’t written to our access log; a failed request can appear in the error log with your IP address. | Telling the client where the server really is. Legitimate interest, art. 6(1)(f). | Nothing is kept. A failed request can appear in the error log, kept 14 days. |
| Seeing an mcp.tc badge, card or iframe on another site | Your browser fetches the file from mcp.tc, which sees your IP address like any web server. Cloudflare usually answers badge and card requests from its cache; the iframe comes from our server each time. Requests for these files aren’t written to our access log, the files set no cookies, and the badge and card load nothing else. | Showing the embed the site’s owner added. Legitimate interest, art. 6(1)(f). | Nothing is kept. A failed request can appear in the error log, kept 14 days. |
| Suggesting a server | The URL you submit, your optional note, the time, and a keyed hash of your IP address | Handling the suggestion and preventing abuse. Legitimate interest, art. 6(1)(f). | Up to 12 months, or as long as the listing it created exists |
| Verifying a listing | The listing, the domain you picked, the time, what our DNS lookups found, and a keyed hash of your IP address. We keep a request only when we find the DNS record. | Handling the request and preventing abuse. Legitimate interest, art. 6(1)(f). | The IP hash 30 days; the request up to 12 months after it’s decided, or as long as the checkmark it granted stays |
| Rate limiting | A keyed hash of your IP address and a counter | Stopping floods of submissions, verification attempts and requests to our MCP server at /mcp. Legitimate interest, art. 6(1)(f). | Up to 2 days |
| Checking a suggestion with AI | The URL you submitted, your note, and public information about the server (its manifest, tool list, repository and package pages). Never your IP address. | Drafting and reviewing the listing. Legitimate interest, art. 6(1)(f). | Sent to Anthropic for the check; retention on their side follows Anthropic’s terms |
| Analytics, only if you accept | Pseudonymous identifiers in cookies, pages viewed, rough location, device and browser details | Counting visits to see what people use. Your consent, art. 6(1)(a) and art. 122 of the Italian Privacy Code. | 14 months in Google Analytics; cookies as listed in the cookie policy |
| Writing to us | Your email address and what you write | Answering you, and keeping a record of reports and requests. Legitimate interest, art. 6(1)(f), or a legal obligation for reports under the Digital Services Act, art. 6(1)(c). | As long as the conversation needs, then up to 24 months |
We back up the database once a day and keep each backup for 14 days, so data deleted from it (suggestions, rate-limit hashes) can stay in a backup for up to 14 more days.
Your theme choice, your analytics choice and the setup tab you last picked are stored in your own browser, not on our server. The cookie policy explains them.
People named in listings
Listings describe software, but they can include personal data: the name or username of a server’s maintainer, links to their repository or website, and similar details. We take these from public sources only: the server’s own MCP metadata and server card, the official MCP Registry, GitHub, npm and PyPI. We publish them because a directory has to say who makes a server (legitimate interest, art. 6(1)(f)). They stay as long as the listing does. You can ask us to correct or remove them at any time, and you can object to the processing; see your rights.
Who else sees data
- OVH SAS (France) hosts the server that runs mcp.tc.
- Cloudflare, Inc. sits in front of the site as a content delivery network and firewall, so it sees every request, including your IP address.
- Anthropic PBC runs the AI model that reviews suggested servers and translates listings into other languages. It receives the data listed above for that check, and only the listings’ public text for the translations.
- Google Ireland Ltd and Google LLC receive analytics data, and only after you accept analytics. Google signals and ad personalization are turned off for our property.
We don’t sell data or share it with advertisers.
Transfers outside the EU
Cloudflare, Anthropic and Google are based in the United States or share data with US companies. Those transfers rely on the EU-US Data Privacy Framework (Commission decision 2023/1795) for certified companies, and on the European Commission’s standard contractual clauses otherwise.
Automated decisions
Whether a suggested server is listed is decided partly by automated checks and the AI reviewer, with a person reviewing anything they can’t confirm. The decision is about software, not about you, and has no legal or similarly significant effect on anyone, so art. 22 GDPR doesn’t apply. You can still ask a person to look at any decision.
Your rights
You can ask to see the personal data we hold about you, have it corrected or deleted, restrict how we use it, or receive it in a portable format. You can object to processing based on legitimate interest, and you can withdraw consent to analytics at any time with the Cookie settings link in the footer; withdrawing doesn’t affect what happened before. Write to privacy@mcp.tc. We answer within one month.
If you think we got something wrong, you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali, or to the authority where you live or work.
What you have to give us
Nothing. You can use the site without giving us any personal data. The submit form needs only a server URL; the note is optional, and since it goes to the AI reviewer, please leave personal details out of it.
Changes to this policy
When we change how we handle data, we update this page and the date at the top. If a change means we need your consent again, the cookie banner asks for it.