Privacy policy
Last updated September 29, 2026
Summary
- Searching, reading trust pages and using the MCP server need no account.
- When an agent calls our tools, we receive only the inputs to that tool call, such as a search query. We never receive, request or store the rest of your conversation.
- We use one functional cookie for sign-in, one for the pricing test, and local storage for your theme. No advertising or cross-site tracking.
- We don't sell or rent personal data.
What we collect
| Data | When | Why |
|---|---|---|
| Tool call inputs (search words, slugs, submitted addresses) | When you or your agent use the site, API or MCP server | To answer the request and improve search |
| IP address and user agent | Every request | Rate limits, abuse prevention, security logs |
| Install records (which tool, which app, how it was reached) | When install instructions are requested | Revocation alerts and aggregate install counts |
| Outcome reports (worked or not, an optional note) | When an agent reports an outcome | The Proven tier, shown only as totals |
| Account details from GitHub (username, name, avatar URL, email) or Google (name, verified email, profile picture URL) | When a publisher signs in | Account, tool claims, sync and billing |
| Billing details | When you pay | Processed by Stripe; we see the plan, status and last four card digits, never the full card number |
| Emails you send us | When you contact us | To reply |
What we never do
- Read, request or store your AI conversations, chat history, memory or files.
- Sell personal data, or use it for advertising.
- Tie outcome reports or installs to a named person in anything we publish.
- Send full page URLs or browsing history from any browser extension we offer; only a domain and a tool address are ever sent, and only when you opt in.
Who processes data for us
We use a small set of providers, each bound by a data processing agreement:
- Vercel for hosting, logs and cron jobs.
- Neon for the database.
- Upstash for rate-limit counters (keyed by IP or API key, expiring within a day).
- Anthropic for the LLM claims check. Only public tool descriptions are sent, never user data.
- GitHub and Google for publisher sign-in. We only receive the basic profile listed above, never access to your repositories, mail or files.
- Stripe for payments.
How long we keep it
- Request logs with IP addresses: 30 days.
- Tool call inputs: 90 days, then kept only in aggregate.
- Install records and outcome reports: while the tool is indexed, then deleted or aggregated.
- Account data: until you delete your account, plus up to 30 days in backups.
- Billing records: as long as tax law requires.
Your choices and rights
You can ask to access, correct, export or delete your personal data, or object to how we use it. Where the GDPR, UK GDPR or US state privacy laws such as the CCPA apply, you have those rights by law, and we won't treat you differently for using them. Email privacy@mcpvetted.com; we answer within 30 days.
Our legal bases, where the GDPR applies: providing the Service you asked for (contract), keeping it secure and improving it (legitimate interests), and billing records (legal obligation).
Security
Data is encrypted in transit and at rest. Access is limited to people who need it. See our Security page for how we isolate untrusted code and how to report a vulnerability.
International transfers
We and our providers process data in the United States and other countries. Where required, transfers use the European Commission's Standard Contractual Clauses or an equivalent safeguard.
Children
The Service is for developers and isn't directed at children under 16. We don't knowingly collect their data.
Changes and contact
We'll post changes here and update the date at the top; material changes are announced on the site first. Questions: privacy@mcpvetted.com. Controller: MCP Vetted.