Privacy Policy
DatenschutzerklÀrung
This policy explains what personal data MCP Thesaurus processes, why, on what legal basis, for how long, and who else sees it. It is written to satisfy Articles 12 to 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, âGDPRâ) and the German Digital Services Data Protection Act (TDDDG), and to be readable by someone who is not a lawyer.
1. Who is responsible
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
Ole Nepomuk MaiGoethestrasse 70
10625 Berlin
Germany
privacy@mcpthesaurus.com
Full provider details are in the Imprint.
Data protection officer. We have not appointed one. None of the triggers in Art. 37(1) GDPR or § 38 BDSG apply: we are not a public authority, our core activity is not regular and systematic monitoring of people on a large scale, we do not process special categories of data as a core activity, and fewer than twenty people are permanently engaged in automated processing here. Data protection questions go to the address above and are answered by a person.
Our competent supervisory authority is Berliner Beauftragte fĂŒr Datenschutz und Informationsfreiheit.
2. The short version
Not a substitute for the sections below, but an honest précis of them:
- You can read this entire directory without an account, without consenting to anything, and without us learning who you are.
- We set no advertising cookies, run no ad network, and sell no personal data to anyone. There is nothing here to opt out of on that front.
- Fonts are served from our own domain. No request goes to Google Fonts from your browser, so your IP address is never disclosed that way.
- Popularity counters â impressions, clicks, install copies â are stored as a single number per item per day. They carry no identifier, no IP address and no cookie, so they are not personal data at all.
- An account is only needed to submit, claim or buy. Signing in uses an emailed code, or Google, or GitHub â your choice.
- If you buy a placement, your contract and your payment details go to Digistore24, which is the seller of record. We never see a card number.
- The application database and its backups sit in Frankfurt. Hosting is on a global edge network, which is the one place data may leave the EU.
3. Visiting the site
Every page and API response is delivered by our hosting provider, Netlify. Delivering a request over the internet means the server necessarily receives, and logs for a short period:
- your IP address;
- the date and time of the request;
- the URL requested and the HTTP status returned;
- the amount of data transferred;
- the referring URL, if your browser sent one;
- your browser and operating system, as reported by the user agent.
Purpose. Delivering the site, keeping it available, defending it against attack and abuse, and diagnosing faults.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is running a website that works and is not trivially knocked over; there is no way to serve a page without processing the request that asked for it. We do not merge these logs with any other data and do not use them to identify individuals.
Retention. We keep no server logs of our own. Netlify retains its access and edge logs for a limited period under its own policy and then deletes them.
Fonts. The typefaces used here are downloaded at build time and served from this domain. Your browser makes no connection to Google Fonts, and no IP address is transmitted to Google for that purpose.
4. Cookies and local storage
Storing information on your device, or reading information already stored there, is governed by § 25 TDDDG. Anything that is not strictly necessary for a service you have expressly requested needs your prior consent. Here is everything this site stores, and why:
MCPT_LOCALEâ cookie, up to 12 months- Remembers which language you chose, so the switcher is not a decision you have to make on every visit. Strictly necessary for the language-selection function you requested, § 25(2) No. 2 TDDDG. No consent required, and it contains a language code, nothing else.
themeâ local storage, until you clear it- Remembers light or dark mode. Never sent to our server â it is read by your own browser to avoid a flash of the wrong theme. Strictly necessary for the display preference you set, § 25(2) No. 2 TDDDG.
- Session cookie â only once you sign in, expires with the session
- Holds the secret that keeps you signed in. It is
httpOnly,SecureandSameSite=Lax, so scripts cannot read it and it is not sent along on cross-site requests. Strictly necessary for the sign-in you requested, § 25(2) No. 2 TDDDG. Signing out deletes it.
Everything in that list is strictly necessary, which is why this site shows no consent banner: there is nothing to consent to. A banner asking permission for cookies that are exempt from consent would be theatre, and a dishonest kind. If that ever changes, this section and the site will change with it, and consent will be asked before anything is set â not after.
You can delete cookies and local storage in your browser at any time, and block them for this site. The language and theme preferences will simply stop being remembered, and signing in will stop working.
5. Measurement and analytics
Aggregate counters â no personal data
We count how often a listing is viewed, how often an install command is copied, how often an outbound link is followed, and how often a sponsored placement is shown or clicked. Sponsors are entitled to know whether the slot they paid for was seen, and we would rather report a real number than an estimate.
These counters are stored as one integer per item per day. There is no visitor identifier, no IP address, no cookie, no user agent and no session attached â the record is literally the item, the kind of event, the date and a count. Individual visits cannot be reconstructed from it, by us or by anyone else, so this is not personal data within the meaning of Art. 4(1) GDPR and the rest of this policy does not apply to it.
Product analytics
None are currently running. This site loads no analytics script, no tag manager and no third-party pixel. We plan to add privacy-respecting product analytics (PostHog, EU Cloud, hosted in Frankfurt); when we do, it will load only after you have consented, this section will describe it in full before it goes live, and it will appear in the recipients list in section 11.
6. Accounts and signing in
Reading the directory needs no account. One is required only to submit a listing, to claim one, or to buy a placement â because an entitlement has to belong to somebody, and an email address typed into a form is not an identity.
Signing in with an emailed code
You give an email address; we send a six-digit code to it; entering the code creates the session. There is no password, so there is no password to leak and no reset flow to abuse. Getting the code out of the inbox also proves the address is real.
- Data: email address, account identifier, the times you signed in, and technical session metadata.
- Legal basis: Art. 6(1)(b) GDPR â performing the agreement to give you an account and the functions attached to it.
- Retention: for as long as the account exists. The code itself is short-lived and single-use.
Signing in with Google or GitHub
If you press the Google or GitHub button, you are sent to that provider, you authenticate there, and it tells us who you are. If you do not press it, nothing at all is sent to Google or GitHub â the buttons are ordinary links, not embedded scripts.
- What they learn: that you are signing in to MCP Thesaurus. Their handling of that is their own, under their own privacy policy; for this step they act as independent controllers, not on our instructions.
- What we receive: your email address, your display name or username, and a stable account identifier. Not your password, not your contacts, and â in GitHubâs case â no access to your repositories.
- Legal basis: Art. 6(1)(b) GDPR for creating and running the account. Choosing this route rather than the emailed code is entirely up to you.
Deleting your account
Write to privacy@mcpthesaurus.com from the address on the account. We delete the account and its session records. Two things survive, and you should know which: order records we are required to keep for tax purposes (section 13), and the directory entries themselves, which describe published software rather than you, and which stay unless the entry is removed on its own merits.
7. Submissions, claims and moderation
Submitting a listing
A submission carries the URL of the project and an email address. We use the address to tell you whether the entry was published or rejected, and to ask a question if the submission is ambiguous.
Legal basis: Art. 6(1)(b) GDPR â you asked us to review something and to write back. Retention: the submission record is kept while the resulting listing is live, and for up to twelve months after a rejection, so that a resubmission of the same project can be handled consistently rather than argued about from memory.
Claiming a listing
Claiming proves that you control a project. You place a token in the repository, in a DNS TXT record, or at a well-known URL on the project domain, and we check for it. We store the token, the verification method, the target checked, the outcome, the number of attempts and your email address and account identifier.
Legal basis: Art. 6(1)(b) GDPR to perform the verification you requested, and Art. 6(1)(f) GDPR for keeping the record afterwards â our legitimate interest being an audit trail for why a particular person was granted control of a particular entry, which matters if the claim is ever disputed. Retention: unverified claims expire and are cleared; verified claims are kept for as long as the claim underpins the ownership of the listing.
Moderation and abuse
We review submissions before publishing, and act on reports about published entries. Where a submission or a report is abusive, fraudulent or automated, we keep enough of a record to recognise a repeat. Legal basis: Art. 6(1)(f) GDPR â keeping the directory usable and its contents trustworthy â and, for notices about illegal content, Art. 6(1)(c) GDPR together with Art. 16 of the Digital Services Act.
8. Payments and paid placements
What we never receive: card numbers, bank details, or any other payment instrument. Those are handled by Digistore24 and its payment partners and do not touch our servers at any point.
What we do store. Before you are sent to checkout we create a pending order row, and when Digistore24 confirms payment it sends us a signed notification. Together these give us: your account identifier, the package bought, the Digistore24 order and event identifiers, the buyer email address Digistore24 reports, the amount and currency, the billing type, the payment status, and the notification payload itself.
Purpose. Granting the thing you paid for, attaching it to the right account, honouring refunds and cancellations, and keeping proper books.
Legal basis. Art. 6(1)(b) GDPR for granting and running the entitlement, and Art. 6(1)(c) GDPR for the commercial and tax record retention imposed by § 147 of the German Fiscal Code (AO) and § 257 of the Commercial Code (HGB).
Retention. Order and invoice records are kept for the statutory period â currently ten years from the end of the calendar year in which the transaction fell. This is an obligation, not a preference: we cannot delete these earlier on request, and a deletion request for an account does not reach them (Art. 17(3)(b) GDPR).
Sponsor material. A sponsorship stores what appears in the slot â product name, headline, logo, target URL â and per-day impression and click counts, which are aggregate numbers as described in section 5.
9. Personal data inside the directory
This section exists because most privacy policies quietly skip it. A directory of open-source software unavoidably processes personal data about people who never visited it: a repository ownerâs username is personal data, and so is a maintainerâs name in a licence header. Where we obtained that data from a source other than you, Art. 14 GDPR requires us to say so, and this is us saying so.
Categories of data. Account and organisation names on code hosts, repository owner handles, project and package names, public repository metadata such as star counts, commit dates, licences and release versions, and text that project authors published themselves, such as README content and tool descriptions.
Sources. Public code hosts (chiefly GitHub), public package registries, the official Model Context Protocol registry, project websites and documentation, and submissions from readers. All of it is information the publisher chose to make public.
Purpose and legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is running a catalogue that lets people find, compare and evaluate MCP software, and attribute it correctly. We think the balancing test comes out clearly: the data is professional rather than private, it was published deliberately in a professional context, we add nothing that was not already public, and correct attribution generally serves the author as well as the reader. It is not used for advertising, for profiling individuals, or for building contact lists, and it is never sold.
Why we did not write to you individually. Art. 14(5)(b) GDPR relieves a controller of individual notification where it would take disproportionate effort. Contacting every maintainer of every indexed project would take exactly that, and many publish no address at all. This policy is the public information Art. 14(5)(b) calls for instead, and every listing names the source it was built from.
10. Email we send
We send transactional email only: sign-in codes, the outcome of a submission, the result of a claim, and confirmations relating to something you bought. These are sent through Appwrite, our backend provider, and are necessary to perform what you asked for (Art. 6(1)(b) GDPR).
There is no newsletter and no marketing mail. If that ever changes it will be a separate, explicit opt-in under Art. 6(1)(a) GDPR and § 7 UWG, with an unsubscribe link in every message â never an automatic consequence of having an account. Our email contains no tracking pixels, so we do not know whether you opened it.
11. Who receives data
We use a small number of service providers, and we name them rather than hiding behind âcategories of recipientsâ. Those marked as processors act only on our documented instructions under a contract meeting Art. 28(3) GDPR. Those marked as independent controllers decide for themselves and answer for their own processing â you deal with them directly, under their own policy.
Netlify
Processor (Art. 28 GDPR)Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA
- Purpose
- Website hosting, CDN and edge delivery of every page and API response.
- Data
- IP address, user agent, requested URL, referrer, timestamp (server and edge logs).
- Processing location
- Global edge network, including servers in the EU and the United States.
- Transfer safeguard
- EUâUS Data Privacy Framework, backed by the EU Standard Contractual Clauses in Netlify's Data Processing Addendum.
Appwrite Cloud
Processor (Art. 28 GDPR)Appwrite Ltd.
- Purpose
- Application backend: the directory database, account and session handling, file storage, and the transactional emails that carry sign-in codes.
- Data
- Email address, account identifier, sign-in timestamps and session metadata, submissions and claim records, order records.
- Processing location
- European Union â this project runs on Appwrite's Frankfurt region (fra.cloud.appwrite.io).
- Transfer safeguard
- Data is stored in the EU. Appwrite is established in Israel, for which the European Commission has issued an adequacy decision, so no additional safeguard is required for administrative access.
Digistore24
Independent controllerDigistore24 GmbH, St.-Godehard-StraĂe 32, 31139 Hildesheim, Germany
- Purpose
- Payment processing, invoicing, VAT handling, refunds and chargebacks for paid submissions and sponsorships. Digistore24 acts as reseller and merchant of record, which means your purchase contract is with Digistore24 and not with us.
- Data
- Name, billing address, email address, payment details, purchase and refund history. Payment card and bank details are handled by Digistore24 and its payment partners and never reach our servers.
- Processing location
- Germany.
Google (Sign in with Google)
Independent controllerGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Purpose
- Optional single sign-on. Used only if you choose the Google button; nothing is sent to Google if you do not.
- Data
- Google receives the fact that you are signing in to this site. We receive your email address, your display name and a stable account identifier.
- Processing location
- European Union and the United States.
- Transfer safeguard
- EUâUS Data Privacy Framework and Standard Contractual Clauses, as set out in Google's own privacy policy.
GitHub (Sign in with GitHub)
Independent controllerGitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA
- Purpose
- Optional single sign-on, and the route by which a maintainer proves control of a repository when claiming a listing. Used only if you choose the GitHub button.
- Data
- GitHub receives the fact that you are signing in to this site. We receive your email address, your GitHub username and a stable account identifier.
- Processing location
- United States and the European Union.
- Transfer safeguard
- EUâUS Data Privacy Framework and Standard Contractual Clauses, as set out in the privacy statement of GitHub and its parent Microsoft.
Beyond these, data is disclosed only where we are legally obliged to â to a court, a supervisory authority or a law enforcement body acting on a valid legal basis (Art. 6(1)(c) GDPR) â or where it is necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR). We do not sell personal data, and we do not share it for anyone elseâs advertising.
12. Transfers outside the EEA
The application database, its backups and the transactional email service run in the European Union, in Appwriteâs Frankfurt region. Payments run through a German company. The one place data ordinarily leaves the EEA is hosting: Netlify serves the site from a global edge network, so a request from outside Europe is answered by a server outside Europe, and Netlifyâs own operations are in the United States.
For that transfer, and for any support access by a non-EEA provider, Chapter V GDPR is satisfied as follows:
- Netlify â the EUâUS Data Privacy Framework, backed by the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914) in its Data Processing Addendum.
- Appwrite â data stays in the EU. The company is established in Israel, for which the Commission has issued an adequacy decision under Art. 45 GDPR, so administrative access needs no further safeguard.
- Google and GitHub â only if you choose their sign-in button. Both rely on the EUâUS Data Privacy Framework and the Standard Contractual Clauses.
You can ask us for a copy of the safeguards relied on for any of these, at the address in section 1.
13. How long we keep things
The rule is that data is deleted once the purpose it was collected for has ended, unless a statutory retention period says otherwise.
- Server and edge logs
- Held briefly by Netlify under its own policy; we keep none.
- Account, email address, sessions
- Until you delete the account. Expired sessions are removed on their own.
- Sign-in codes
- Minutes. Single use, then void.
- Submissions
- While the resulting listing is live; up to twelve months after a rejection.
- Claim records
- Unverified claims expire and are cleared. Verified claims last as long as the ownership they establish.
- Orders, invoices and payment notifications
- Ten years from the end of the calendar year concerned, as required by § 147 AO and § 257 HGB. Not deletable on request.
- Aggregate counters
- Indefinitely â they contain no personal data.
- Correspondence with us
- Up to three years from the end of the year of the last exchange, matching the ordinary limitation period in § 195 BGB, so that a claim arising from it can still be answered.
14. Your rights
Under the GDPR you have the following rights against us. Exercising any of them is free, and we answer within one month of receiving the request (Art. 12(3) GDPR), or tell you why we need longer.
- Access (Art. 15) â confirmation of whether we process data about you, a copy of it, and the details of that processing.
- Rectification (Art. 16) â correction of inaccurate data and completion of incomplete data.
- Erasure (Art. 17) â deletion, where one of the grounds applies and no retention obligation stands in the way.
- Restriction (Art. 18) â processing frozen rather than deleted, for instance while a dispute about accuracy is resolved.
- Data portability (Art. 20) â the data you gave us, in a structured, commonly used, machine-readable format, where processing rests on consent or contract and is automated.
- Objection (Art. 21) â see section 15, which sets this out separately because the GDPR requires it to be.
- Withdrawal of consent (Art. 7(3)) â at any time, as easily as it was given, without affecting the lawfulness of processing carried out beforehand.
- Complaint to a supervisory authority (Art. 77) â you may complain to the authority in the EU member state where you live, where you work, or where the alleged infringement took place. In Germany, the federal and state authorities are listed by the Federal Commissioner for Data Protection and Freedom of Information. You do not have to raise it with us first, though we would rather you did â most complaints are a misunderstanding we can clear up in a day.
Write to privacy@mcpthesaurus.com. If a request concerns an account, send it from the address on that account, or expect us to ask for something that establishes it is yours â Art. 12(6) GDPR allows that, and handing someone elseâs data to whoever asks would be the worse failure.
15. Right to object
Presented separately and in this form because Art. 21(4) GDPR requires the right to object to be brought to your attention clearly and separately from any other information â not buried in a list.
16. Automated decisions and profiling
We make no decisions about you that produce legal effects concerning you or similarly significantly affect you, and which are based solely on automated processing. Art. 22 GDPR is therefore not engaged. We build no behavioural profiles of visitors.
One thing on this site is automated and deserves naming anyway. Each listing carries a score computed by a published rubric from public signals â documentation, maintenance, licence clarity and so on. It rates a piece of software, not a person, and it decides nothing about anybody: it ranks entries in a list. Publication decisions, claim decisions and moderation decisions are all made by a person.
17. Security
Art. 32 GDPR requires measures appropriate to the risk. In practice, for this site:
- Every connection is TLS-encrypted; plain HTTP is redirected.
- There are no passwords to steal â sign-in is by emailed one-time code or by an external provider.
- The session secret lives in an
httpOnly,Secure,SameSite=Laxcookie, unreadable by scripts. - Payment notifications are verified against a cryptographic signature before anything is granted; the buyer-facing confirmation page grants nothing at all, because it is a URL anyone could visit.
- Administrative credentials are held server-side only, and the public parts of the site read the database through a separate, unprivileged path.
- Data is stored and backed up in the EU by providers holding recognised security certifications.
No system is perfectly secure. If you find a vulnerability here, please tell us at hello@mcpthesaurus.com before telling anyone else; we will not pursue anyone who reports in good faith and does not access or alter other peopleâs data.
18. Children
This is a technical reference for software developers and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to privacy@mcpthesaurus.com and we will delete it.
19. Changes to this policy
We update this policy when what we do changes â a new provider, a new feature, a change in the law. The date at the top always reflects the current version, and material changes are noted in the changelog. Where a change requires consent, we ask for it before the change takes effect rather than announcing it afterwards. Continuing to use the site after a non-material change means the updated version applies.