Privacy
This registry lists publicly available information about MCP servers and coding agents. Some of it can be attributed to a natural person, because the identifier of an entry may contain the account name of the person who published it. This page explains what that means.
Controller
The controller within the meaning of Article 4 (7) GDPR is the provider named in the legal notice. The contact route given there is also the addressee for every right described here (Article 12 (2) GDPR).
This notice applies to tracevero.com, tracevero.de and api.tracevero.com. All of these names lead to the same service and are run by the same controller; the processing is identical under all of them.
What data is processed
The identifier of an entry including its account part, the display name, the description published by the vendor itself, and technical properties of the package: status, execution location, whether credentials are required, whether a repository address is given, and comparable attributes.
This registry does not itself collect contact details, postal addresses, employment or payment information, or special categories under Article 9 GDPR. The data is not enriched, not combined with other sources, not condensed into profiles, and not rated.
One exception belongs here: the description of an entry comes from the vendor and is reproduced unchanged. It may contain a contact detail, for example an email address the vendor wrote into it. Such a detail is neither analysed nor used for any other purpose; anyone who wants it removed can take the route described under “How to object”.
Where the data comes from
From the public MCP registry at registry.modelcontextprotocol.io, endpoint /v0/servers, which is read in full once a day, and from a list of coding agents maintained within the service. The data therefore does not come from the data subjects themselves (Article 14 (2) (f) GDPR). The addresses named in the entries are never fetched.
Purpose and legal basis
Installing an MCP server or a coding agent grants it access to a development environment, often including the file system and credentials. This registry makes the properties that matter for that decision comparable: measured, with source and collection date, without registration and free of charge.
The legal basis is Article 6 (1) (f) GDPR. The legitimate interest is twofold: the operator has an interest in a findable information service, and the public has an interest in transparency about software that asks for credentials and file system access. The written balancing test is held by the operator and will be sent on request via the contact route.
How long the data is kept
An entry is kept for as long as the source lists it, or until it is deleted on request. There is no fixed period for it. The raw responses stored for traceability are deleted after 90 days; they are never served.
Who receives the data
The registry hands its stock to anyone; that is its purpose. The data is available without registration and free of charge by four routes: as pages under tracevero.com and tracevero.de, as an interface under https://api.tracevero.com/v1 with JSON, CSV and a full dump, as an Atom feed under /aenderungen.atom on tracevero.com and tracevero.de, and as the file /llms.txt. Whoever calls one of these addresses receives the data; there is no restriction on who that may be (Article 14 (1) (e) GDPR).
Search engines are expressly included: /robots.txt permits them to crawl, and /sitemap.xml lists the addresses of the entry pages for them. The address of an entry page contains the identifier of the entry.
The server is provided by Hetzner Online GmbH and stands in Falkenstein, Germany. It therefore processes the data on behalf of the controller (Article 28 GDPR). The upstream web server, which establishes the connection and terminates the encryption, runs on the same machine as the registry and not at a further provider.
Beyond that, the service passes the data on to no one. It sends no email, embeds no third-party content and uses no external delivery network. Of its own accord it calls exactly one foreign address, the source named under “Where the data comes from”: it fetches there, it hands over nothing.
Audience measurement runs on the same machine as the registry; what it collects is described under “What happens when you visit these pages”. No measurement service of another provider is involved.
Countries outside the EU
The server this registry runs on stands in Falkenstein, Germany, and therefore in the European Union. No processor outside the EU is involved; the only processor is Hetzner Online GmbH with this server.
Access is open worldwide. The registry requires no registration and blocks no origin; pages, interface, feed and /llms.txt can be retrieved from any country. The service does not evaluate which country a request comes from and does not record it.
The service does not, of its own accord, transfer the data to any body in a third country; it keeps it available for retrieval (Article 14 (1) (f) GDPR). What stands here is the description of that process, not its legal classification.
Your rights
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and objection (Article 21). You may also lodge a complaint with a supervisory authority (Article 77).
How to object
Address an objection under Article 21 GDPR, an erasure request under Article 17 and a request to restrict processing under Article 18 to the controller, the provider named in the legal notice. The route is an email to: German.saas@web.de
The objection is informal, stating the identifier concerned. No reason has to be given. The entry is then deleted and the identifier is blocked permanently, so that the next reconciliation run does not recreate it. The block is deliberately irreversible.
This also works before an entry exists: an identifier can be blocked in advance, and the next reconciliation run will then not create it in the first place.
Anyone who does not want deletion can ask for processing to be restricted under Article 18 GDPR, for example while the accuracy of a value is contested. The entry then stays stored but is no longer served. Unlike the block, a restriction can be lifted again (Article 18 (3) GDPR).
What deletion does not reach, and this belongs here: the raw source responses kept for 90 days, which are never served, and the source itself. An entry that the MCP registry continues to list remains there; its operator is responsible for that.
What happens when you visit these pages
This registry sets no cookies, embeds no third-party content, and has no login. There are no user accounts. There is no consent banner because there is nothing to consent to.
Audience measurement uses self-hosted, cookieless software (Plausible) running on the same machine; it counts page views without recognising individual people and passes nothing on to third parties. The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in measurement without personal data.
Verifiable: the measurement snippet is loaded from stats.postpilot-app.de, that is under a second name. That name points to the same machine as tracevero.com and is run by the same operator; no further provider is involved.
If a page fails, the service writes the requested address and the HTTP method to its operational log in order to find the fault; an address may contain the identifier of an entry. The upstream web server establishes the connection and terminates the encryption.
tracevero · https://tracevero.com/datenschutz