MCPVault

Legal

Privacy Policy

Last updated: August 14, 2026

1. Who we are

MCPVault (mcpvault.io) is an independent directory of Model Context Protocol servers, operated from Stockholm, Sweden. For anything in this policy, contact hello@mcpvault.io.

2. What we collect

Directory data: listings are built from information that is already public, primarily GitHub repository metadata such as repository name, description, author, star count, license and commit activity. This is public data about software projects, not private personal data.

Account data: if you create an account to claim a server, we store your email address, authentication identifiers (for example your GitHub username when you sign in with GitHub) and the listings you manage.

Technical data: our hosting providers keep standard server logs (IP address, user agent, requested pages) for security and abuse prevention.

3. What we do not do

We do not run third-party advertising trackers. We do not sell personal data. We do not send marketing email to account holders without consent, and every such email includes a working unsubscribe link.

4. How data is used

Account data is used to operate the service: authenticating you, connecting you to your claimed listings and contacting you about your account. Public repository data is used to build and grade directory listings.

If we contact the maintainer of an unclaimed listing, we use contact information the maintainer has published publicly (for example in a repository or on a project website), and only to inform them about their listing. Every such email includes a way to opt out permanently.

5. Where data lives

Application data is stored with Supabase in the EU (Ireland). The site is served by Vercel. Both providers process data under their respective data processing agreements.

6. Your rights

Under the GDPR you can request access to, correction of or deletion of your personal data. Deleting your account removes your personal data; public repository metadata may remain in the directory because it is public information about a software project, not about you as a person. If you are a maintainer and want your listing removed entirely, contact us and we will handle it.

7. Cookies

We use only functional cookies and local storage: your theme preference and, if you sign in, your authentication session. No cross-site tracking cookies.

8. Changes

We will update this page when practices change and adjust the date below. Material changes affecting account holders will be announced by email.