Privacy
This registry lists publicly available information about MCP servers and coding agents. Some of it can be attributed to a natural person, because the identifier of an entry may contain the account name of the person who published it. This page explains what that means.
Controller
The controller within the meaning of Article 4 (7) GDPR is the provider named in the legal notice. The contact route given there is also the addressee for every right described here (Article 12 (2) GDPR).
What data is processed
The identifier of an entry including its account part, the display name, the description published by the vendor itself, and technical properties of the package: status, execution location, whether credentials are required, whether a repository address is given, and comparable attributes.
Not processed: contact details, postal addresses, employment or payment information, or special categories under Article 9 GDPR. The data is not enriched, not combined with other sources, not condensed into profiles, and not rated.
Where the data comes from
From the public MCP registry at registry.modelcontextprotocol.io, endpoint /v0/servers, which is read in full once a day, and from a list of coding agents maintained within the service. The data therefore does not come from the data subjects themselves (Article 14 (2) (f) GDPR). The addresses named in the entries are never fetched.
Purpose and legal basis
Installing an MCP server or a coding agent grants it access to a development environment, often including the file system and credentials. This registry makes the properties that matter for that decision comparable: measured, with source and collection date, without registration and free of charge.
The legal basis is Article 6 (1) (f) GDPR. The legitimate interest is twofold: the operator has an interest in a findable information service, and the public has an interest in transparency about software that asks for credentials and file system access. The written balancing test is held by the operator and will be sent on request via the contact route.
How long the data is kept
An entry is kept for as long as the source lists it, or until it is deleted on request. There is no fixed period for it. The raw responses stored for traceability are deleted after 90 days; they are never served.
Your rights
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and objection (Article 21). You may also lodge a complaint with a supervisory authority (Article 77).
How to object
Informally, to the address given in the legal notice, stating the identifier concerned. No reason has to be given. The entry is then deleted and the identifier is blocked permanently, so that the next reconciliation run does not recreate it. The block is deliberately irreversible.
What deletion does not reach, and this belongs here: the raw source responses kept for 90 days, which are never served, and the source itself. An entry that the MCP registry continues to list remains there; its operator is responsible for that.
What happens when you visit these pages
This registry sets no cookies, embeds no third-party content, measures no audience, and has no login. There are no user accounts. If a page fails, the service writes the requested address and the HTTP method to its operational log in order to find the fault; an address may contain the identifier of an entry. The upstream web server establishes the connection and terminates the encryption.