Privacy Policy
Last updated 23 July 2026
This explains what MCP Commons collects, why and who we share it with. It covers the service operated by [company legal entity].
What we collect
- Your email address, used to sign you in and to reach you about your account.
- Your GitHub identity and an access token, if you connect GitHub to submit a repo for review. The token is encrypted at rest.
- Tool credentials you add for a purchased tool. These are encrypted at rest and injected only at dispatch.
- Usage and metering records: which tools you call and how often, for billing and rate limiting.
- Product analytics about how the site is used (pages viewed and key actions like sign-up or checkout). Backend events are captured server-side for our internal metrics. Browser analytics run only after you accept the consent banner.
- Payment details, which are handled and stored by Stripe. We keep identifiers, not card numbers.
How we use it
To operate the directory, run reviews, host and dispatch tools, meter and bill usage, pay out creators, measure usage to improve the platform, prevent abuse and send transactional email about your account. We do not sell your personal data and we do not use analytics for advertising.
Who we share it with
We use these processors to run the service: Cloudflare (hosting and database), Stripe (payments and payouts), GitHub (source access you authorize), Anthropic (the review model), Resend (transactional email) and PostHog (product analytics). Each receives only what it needs for its function.
Cookies
We set one essential cookie to keep you signed in and one to remember your analytics choice. If you accept analytics, PostHog sets cookies to measure how the site is used. We serve PostHog through our own domain and it stays off until you accept the banner. We do not use advertising cookies.
Retention and security
We keep account and billing records for as long as your account is active and as required for legal and accounting purposes. Access tokens and tool secrets are encrypted at rest. No system is perfectly secure, but we work to protect your data and to unroute affected tools quickly if needed.
Your choices
You can disconnect GitHub and delete stored tool secrets from your account at any time. To access or delete your account data, email team@mcpcommons.com. Depending on where you live you may have additional rights under [applicable law].
Contact
Privacy questions: team@mcpcommons.com. Security reports: security@mcpcommons.com.