Skip to content
MCP Vetted

Privacy policy

We collect as little as the Service needs. We never read your AI conversations, and we don't sell data.

Last updated September 29, 2026

Summary

  • Searching, reading trust pages and using the MCP server need no account.
  • When an agent calls our tools, we receive only the inputs to that tool call, such as a search query. We never receive, request or store the rest of your conversation.
  • We use one functional cookie for sign-in, one for the pricing test, and local storage for your theme. No advertising or cross-site tracking.
  • We don't sell or rent personal data.

What we collect

DataWhenWhy
Tool call inputs (search words, slugs, submitted addresses)When you or your agent use the site, API or MCP serverTo answer the request and improve search
IP address and user agentEvery requestRate limits, abuse prevention, security logs
Install records (which tool, which app, how it was reached)When install instructions are requestedRevocation alerts and aggregate install counts
Outcome reports (worked or not, an optional note)When an agent reports an outcomeThe Proven tier, shown only as totals
Account details from GitHub (username, name, avatar URL, email) or Google (name, verified email, profile picture URL)When a publisher signs inAccount, tool claims, sync and billing
Billing detailsWhen you payProcessed by Stripe; we see the plan, status and last four card digits, never the full card number
Emails you send usWhen you contact usTo reply

What we never do

  • Read, request or store your AI conversations, chat history, memory or files.
  • Sell personal data, or use it for advertising.
  • Tie outcome reports or installs to a named person in anything we publish.
  • Send full page URLs or browsing history from any browser extension we offer; only a domain and a tool address are ever sent, and only when you opt in.

Who processes data for us

We use a small set of providers, each bound by a data processing agreement:

  • Vercel for hosting, logs and cron jobs.
  • Neon for the database.
  • Upstash for rate-limit counters (keyed by IP or API key, expiring within a day).
  • Anthropic for the LLM claims check. Only public tool descriptions are sent, never user data.
  • GitHub and Google for publisher sign-in. We only receive the basic profile listed above, never access to your repositories, mail or files.
  • Stripe for payments.

Cookies and local storage

  • authjs.session-token: keeps publishers signed in. Set only after sign-in.
  • sync_offer: remembers which publisher sync price you were shown, so it doesn't change between visits.
  • theme (local storage): your light or dark choice. It never leaves your browser.

How long we keep it

  • Request logs with IP addresses: 30 days.
  • Tool call inputs: 90 days, then kept only in aggregate.
  • Install records and outcome reports: while the tool is indexed, then deleted or aggregated.
  • Account data: until you delete your account, plus up to 30 days in backups.
  • Billing records: as long as tax law requires.

Your choices and rights

You can ask to access, correct, export or delete your personal data, or object to how we use it. Where the GDPR, UK GDPR or US state privacy laws such as the CCPA apply, you have those rights by law, and we won't treat you differently for using them. Email privacy@mcpvetted.com; we answer within 30 days.

Our legal bases, where the GDPR applies: providing the Service you asked for (contract), keeping it secure and improving it (legitimate interests), and billing records (legal obligation).

Security

Data is encrypted in transit and at rest. Access is limited to people who need it. See our Security page for how we isolate untrusted code and how to report a vulnerability.

International transfers

We and our providers process data in the United States and other countries. Where required, transfers use the European Commission's Standard Contractual Clauses or an equivalent safeguard.

Children

The Service is for developers and isn't directed at children under 16. We don't knowingly collect their data.

Changes and contact

We'll post changes here and update the date at the top; material changes are announced on the site first. Questions: privacy@mcpvetted.com. Controller: MCP Vetted.