Privacy Policy
Last updated: June 20, 2026
This document is an MVP template. It must be reviewed and adapted by qualified legal counsel before MCP Store launches publicly. It is not legal advice.
1. Introduction
This Privacy Policy explains how MCP Store (“we,” “us”) collects, uses, and protects information when you use our marketplace and gateway. We designed the service to collect as little as possible: usage is metered as metadata only, and we never log the payloads, prompts, or responses of your MCP calls.
2. Information we collect
- Account information. When you sign up, we store your name and email address, and (if you sign in with GitHub or Google) the basic profile your provider returns. Passwords are stored only as salted hashes by our authentication layer.
- API keys. We never store your raw API keys. We store a one-way hash of each key plus a short non-secret prefix and last four characters so you can identify it. The full key is shown only once, at creation.
- Usage events (metadata only). When a call passes through the gateway we record metadata such as a timestamp, the listing involved, the response status, and counts for metering and rate limiting. We do not record the request or response payloads, prompts, arguments, headers, or secrets.
- Billing information. Subscriptions and payments are handled by Stripe. We store subscription status and identifiers needed to manage your access; we do not store full card numbers.
- Developer listings. If you list an MCP, we store the listing details you provide, including the registered endpoint URL, pricing, and risk declarations.
- Reviews and reports. Content you submit when reviewing or reporting a listing, associated with your account.
3. Cookies and sessions
We use first-party, secure session cookies to keep you signed in and to operate the dashboard. These are essential for the service to function. We do not use third-party advertising cookies. If we add product analytics in the future, we will use privacy- respecting, aggregate measurement and update this policy accordingly. See our Cookie Notice for details.
4. How we use information
- to provide, secure, and operate the marketplace and gateway;
- to authenticate requests and enforce access, rate limits, and quotas;
- to meter usage and bill subscriptions;
- to detect abuse, fraud, and security threats;
- to respond to support requests and reports; and
- to comply with legal obligations.
5. Payment processing (Stripe)
We use Stripe as our payment processor. When you subscribe, your payment details are collected and processed directly by Stripe under its own terms and privacy policy. We receive limited information from Stripe (such as subscription status and the last four digits or brand of your card) needed to manage your access; the database record of your subscription is the source of truth for gateway access decisions.
6. How we share information
We do not sell your personal information. We share data only with service providers acting on our behalf (for example, Stripe for payments and our hosting and database providers), with developers to the limited extent needed to route and meter your gateway calls to their endpoint, or when required by law or to protect the platform and its users. When you connect through the gateway, your request is forwarded to the third-party developer’s endpoint; their handling of that request is governed by their own policies. The service providers we rely on are listed on our Subprocessors page.
7. Data retention
We retain account information for as long as your account is active and as needed to provide the service. Usage-event metadata is retained for operational, billing, and security purposes and then deleted or aggregated on a rolling basis. Billing records are retained as required for tax and accounting. When you close your account, we delete or anonymize your personal information within a reasonable period, except where retention is required by law.
8. Security
We hash API keys and passwords, redact secret-bearing fields from logs, restrict the gateway to registered HTTPS endpoints, and apply rate limits and access controls. No system is perfectly secure, but we work to protect your information using reasonable technical and organizational measures.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. You can manage your account, API keys, and subscriptions from your dashboard, or contact us to exercise these rights.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice.
11. Contact
Questions about this policy or your data can be sent to privacy@mcpstore.io. See also our Terms of Service.