Privacy
The public registry is readable without an account, and we built it to stay quiet: no advertising trackers, no third-party analytics scripts, no fonts loaded from CDNs, and no cookies on public pages.
What the public site collects
- Server logs. Standard web-server request logs (IP address, user agent, requested path) for security and abuse prevention, with a bounded retention period.
- Interaction events. The events listed below currently go to your own browser console only — nothing is transmitted off your device. If we start sending them to our own (self-hosted) collector, this page will list that change first.
Every analytics event, enumerated
| Event | When | Payload |
|---|---|---|
| ui.page_view | Navigating to any page | the path visited (no query string), per-page-load correlation id |
| ui.scanner_toggled | Toggling a scanner chip in “Your view” on a server page | scanner name, on/off, resulting selection, server id, per-page-load correlation id |
| ui.registry_filter_changed | Changing a registry filter (keyword, author, badge, min score) | the resulting filter query string, per-page-load correlation id |
The correlation id is a random value generated per page load, never stored, and never linked to an identity. No event contains page content, form input, or anything typed into a filter beyond the filter state itself.
What we never do
- No third-party trackers, ad pixels, or fingerprinting.
- No selling or sharing of usage data.
- No engagement-derived trust signals: install counts and favourites are display-only and never feed a badge or ranking.
Registry data about MCP servers (names, repositories, scan results) is public information about published software, maintained under our records-of-processing documentation. Account features, when they ship, will get their own section here before launch.