Policy / Privacy
Privacy Policy
Effective and last updated: July 30, 2026
This policy applies to mcpserver.cc, its localized pages, submission forms, and related API-backed features.
1. Scope and roles
This Privacy Policy explains how MCP Server Directory (“we”, “us”, or “the Directory”) handles information when you browse the site, submit an MCP server, or contact us. The Directory is an independent index and is not affiliated with the projects it lists.
For information we determine how to use, the site operator acts as the data controller or equivalent responsible party under applicable law. Infrastructure providers may process information on our behalf.
2. Information we collect
We collect only information reasonably needed to operate, secure, and maintain the Directory.
- Technical and usage data: IP address, request time, requested URL, referrer, browser or device information, response status, and security signals recorded by hosting or delivery infrastructure.
- Submission data: server name, project or repository URL, description, category-related information, timestamps, review status, and other details you voluntarily submit.
- Public project data: names, descriptions, documentation, maintainer names, avatars, repository metadata, and other information made publicly available by project sources such as GitHub.
- Communications: information included in privacy, correction, removal, copyright, security, or other requests you send to us.
3. How information is collected
Information is collected directly from you, automatically when requests reach the site, and from public project sources. We do not ask users to create an account, provide payment information, or submit sensitive personal information through the public form.
4. How we use information
We use information to provide search and directory pages, review and publish submissions, synchronize public project information, maintain data accuracy, respond to requests, diagnose failures, measure service performance, prevent abuse, and comply with legal obligations.
We do not sell personal information. We do not use submitted contact information for unrelated direct marketing.
5. Legal bases where applicable
Where laws such as the GDPR or UK GDPR apply, processing may be based on our legitimate interests in operating and securing a public technical directory, performance of a service you request, your consent where required, and compliance with legal obligations. You may object to legitimate-interest processing as described below.
6. Cookies, local storage, analytics, and advertising
The core directory does not require an account cookie. Essential storage may be used for security, routing, language preferences, or form operation. If analytics or advertising services are enabled, they may set cookies or collect device and usage identifiers subject to their own notices and any consent requirements.
Where legally required, non-essential analytics or advertising technologies should not be activated until consent is obtained. Browser settings can block or remove cookies, although this may affect some functionality.
7. Service providers and disclosures
We may disclose information to providers that help operate the Directory, including Cloudflare for hosting, content delivery, security, and request processing; Supabase for database services; GitHub and other public project sources when retrieving repository information; and AI or content-processing providers when generating project summaries.
Each provider handles information under its own terms and privacy commitments. We may also disclose information when required by law, to protect rights or safety, to investigate abuse, or in connection with a reorganization of the service. We do not authorize providers to use Directory data for unrelated purposes.
8. Public listings and external links
Published listing information is publicly accessible and may be indexed, cached, quoted, or copied by search engines and third parties. Do not submit private credentials, private repository information, personal addresses, or other confidential data.
Links lead to independent third-party projects. Their privacy practices govern information you provide after leaving this site.
9. Data retention
Request and security logs are retained only as long as reasonably necessary for security, debugging, performance, legal, or abuse-prevention purposes and may be subject to infrastructure-provider retention periods.
Published listing data is generally retained while the listing remains useful and accurate. Rejected, duplicate, withdrawn, or deleted submissions may be retained for a limited period to document review decisions, prevent repeated abuse, resolve disputes, or satisfy legal duties. Backup copies may persist temporarily after deletion.
10. International transfers
The Directory and its providers may process information in countries other than your own. Where required, providers use recognized safeguards for international transfers, such as contractual protections or applicable adequacy mechanisms.
11. Security
We use reasonable technical and organizational measures intended to protect information, including encrypted transport, access controls, managed infrastructure, and abuse monitoring. No online service can guarantee absolute security. Do not send secrets, access tokens, or sensitive personal data through public forms.
12. Your choices and privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent; or complain to a data protection authority. You may also request correction or removal of inaccurate listing information.
We may ask for information needed to verify your identity and authority over a project. Some requests may be limited where retention is required by law, necessary for security or legal claims, or protected by freedom-of-expression and public-information exceptions.
13. Children
The Directory is intended for developers and a general technical audience, not children under 13 or the higher minimum age required in a user’s jurisdiction. We do not knowingly collect personal information from children. Contact us if you believe a child submitted personal information.
14. Do Not Track and automated privacy signals
Because there is no universally accepted standard for browser Do Not Track signals, the site may not respond to them consistently. Where applicable law requires recognition of a supported opt-out signal, we will take reasonable steps to honor it.
15. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. The updated date will appear on this page. Material changes may be highlighted on the site where appropriate.
16. Contact and requests
Use the site submission/contact channel for privacy, access, correction, deletion, listing removal, or complaint requests. Include the affected URL, a clear description of the request, and evidence that you are authorized to act for the relevant project where necessary. Do not include identity documents unless specifically requested through a secure channel.