Privacy Policy

How we collect, use, and protect your information

Last updated: February 27, 2026

1. Introduction

MCP-Hub ("we", "us", or "our") operates the website mcp-hub.info and related services (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are based in the European Union (Spain) and are committed to complying with the General Data Protection Regulation (GDPR) and applicable data protection laws. By using our Service, you acknowledge that you have read and understand this Privacy Policy.

2. Information We Collect

We collect information in the following ways:

Account Information

When you create an account, we collect your name, email address, and profile information provided through our authentication provider (Auth0). If you subscribe to a paid plan, payment information is processed by Stripe and is not stored on our servers.

Usage Data

We automatically collect information about how you interact with our Service, including pages visited, features used, search queries, and the date and time of your visits.

Device and Browser Information

We may collect information about the device and browser you use to access our Service, including IP address, browser type, operating system, and screen resolution. IP addresses are anonymized where possible.

MCP Server Data

When you publish an MCP server, we collect the source code repository URL, metadata, and the results of our security analysis. This data is used to provide certification and distribution services.

3. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Service:

Essential Cookies

Always active. Required for security (CSRF protection), session management, and basic functionality. These cannot be disabled.

Analytics Cookies

Optional. We use Google Analytics (GA4) and PostHog to understand how visitors interact with our website, identify popular features, and improve the user experience. These cookies collect anonymized usage data.

Marketing Cookies

Optional. We use the Facebook Pixel to measure the effectiveness of our advertising campaigns and to deliver relevant advertisements. These cookies may track your browsing activity across websites.

You can manage your cookie preferences at any time through the cookie consent banner or by clicking "Cookie Settings" in the footer of any page.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our Service
  • Process your MCP server submissions and deliver security analysis
  • Manage your account, subscriptions, and billing
  • Improve and personalize the user experience
  • Communicate with you about service updates, security alerts, and support
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations

5. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Consent: For analytics and marketing cookies. You can withdraw consent at any time through the cookie settings.
  • Contract: For processing account data and providing the services you have subscribed to.
  • Legitimate Interest: For essential cookies, security measures, fraud prevention, and improving our Service.
  • Legal Obligation: Where required to comply with applicable laws and regulations.

6. Data Sharing and Third Parties

We share data with the following third-party service providers who process data on our behalf:

  • Local Authentication — Secure email/password authentication managed directly by MCP Hub
  • Stripe — Payment processing and subscription management
  • Google Analytics — Website usage analytics (with consent)
  • PostHog — Product analytics (with consent)
  • Facebook (Meta) — Advertising measurement (with consent)
  • Hetzner — Cloud infrastructure and hosting

We do not sell your personal data. We only share data with third parties as described above, to comply with legal obligations, or to protect our rights and safety.

7. Data Retention

We retain your account data for as long as your account is active or as needed to provide you services. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.

Analytics data is aggregated and anonymized after 26 months. Marketing data is retained according to the respective platform's policies (Google, Facebook, PostHog).

8. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing of your data
  • Right to Data Portability: Request your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for analytics and marketing cookies at any time

To exercise any of these rights, please contact us at hello@mcp-hub.info. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority.

9. International Data Transfers

Some of our third-party service providers are located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS) and at rest, access controls, regular security audits, and secure development practices. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

11. Children's Privacy

Our Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this page periodically.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

MCP-Hub

Email: hello@mcp-hub.info

Website: mcp-hub.info