# Privacy

What The MCP Census collects, what it does not, and how long we keep it.

## Who we are
The MCP Census is operated by **Jaco Veldsman** (Australia). Contact: **info@mcpcensus.com**.

## What this product is
A public website and API that check **public** facts about Model Context Protocol servers (registry listings, repository and package metadata, hosted endpoints, and similar open sources). The census itself is not personal data.

## Data we may process

### Public census data
Server names, namespaces, repository URLs, package names, health signals, and related facts from public sources. This is product data, not user profiles.

### Account and auth
- Email address when you sign in or create an account (magic link or OAuth with a verified email)
- OAuth provider identifiers linked to that email (e.g. GitHub, Google) when you connect them
- Session cookies to keep you signed in on mcpcensus.com
- API keys you create (stored as secrets; shown once at mint time)

### Usage and limits
- Rate-limit counters (by IP for anonymous use, by API key for authenticated use) in Cloudflare KV
- Optional product events (e.g. which public pages you open) used to understand product usage — not sold as advertising profiles
- **Client identity aggregates** (API/MCP/pages): a coarse label from `User-Agent` and optional `X-Census-Client` / `X-Client-Name` headers, plus hit counts and last tier (anonymous/free/pro). No IP, no API key value. Agents are asked via `llms.txt` to self-identify; browsers collapse to a generic “browser” family
- **Visitor event log** (`visitor_event`): when/who/what for API, MCP, and site page beacons — path, channel, truncated search/query detail, client label, country (Cloudflare edge), status, opaque session id for site clicks. **No raw IP.** Retained about 90 days then pruned. Complements the query-only research ledger and the aggregate client table

### Research and discovery
- **Search signal ledger:** normalized search query text only (no IP, no session) so we can research repeated brand misses over time
- **Research watch emails** you opt into when a brand has no official hit yet
- Optional alert preferences (e.g. new servers) on your account

### Submissions
If you submit a missing server: the payload you send, and the email you provide for reward / follow-up when applicable.

### Billing
Paid Pro access is arranged by email (no self-serve card checkout on this site today). When you pay, we process the billing details required by that arrangement.

### Infrastructure
Hosting, DNS, email delivery, and error reporting run on subprocessors (today primarily **Cloudflare** for site, Workers, D1, KV, and email). They process data only to provide those services.

## What we do not do
- No sale of personal data
- No third-party advertising pixels as a business model
- No fabricated user testimonials or fake social proof in the product

## Cookies
Essential cookies for session auth. No non-essential marketing cookie wall.

## Retention
- Account and API key records: while the account is active, and a short period after deletion requests for security/abuse logs
- Rate-limit counters: rolling daily windows
- Search signal rows: retained as a research ledger (query text only)
- Visitor events: ~90 days
- Error reports: per our error-reporting provider’s retention

## Your choices
- Request access or deletion of account data: **info@mcpcensus.com**
- Opt out of research-watch or new-server emails via account alerts or by emailing us
- Stop using the product and delete keys in account settings

## Children
Not directed at children under 16.

## Changes
We will update this page and the `updated` date when practices change materially.
