馃憫

MCP QUEEN

Privacy Policy

Last updated: September 7, 2026

MCP Queen is a public evidence and discovery service for Model Context Protocol servers. This policy explains the information processed through mcpqueen.com, its public MCP endpoint, watch alerts, and field reports.

Information we process

Public ecosystem data. We process public MCP Registry metadata, public server endpoints, public repository links, tool metadata exposed through MCP, and observations produced by our live probes.

Service requests. Our hosting provider may process standard request metadata such as IP address, user agent, timestamp, and requested URL for delivery, reliability, and security. Public MCP discovery tools do not require an account or authentication.

Adoption measurement. When you use a measured Connect-page or founding-pilot action, the page sends a same-origin request whose URL contains only a fixed action name. It sends no request body, query string, account identifier, or session identifier. For aggregate adoption and abuse analysis, we record that fixed action, timestamp, coarse client and bot classification, country code, and truncated keyed HMACs derived from the source network address and network number. We do not treat these events as proof of a person, subscriber, or customer.

Founding-pilot email. Pilot links open your own email client with a blank intake template addressed to MCP Queen. The website does not submit or store the template. If you choose to send it, your email provider and MCP Queen's connected mailbox process the message and reply. Do not include credentials, tokens, private data, or proprietary prompts.

Registry searches. The website may record a bounded HMAC query fingerprint, result count, timestamp, and a truncated keyed HMAC derived from the source IP for demand measurement and abuse control. It does not place raw MCP search arguments in long-lived application telemetry. These telemetry hashes are removed after seven days.

Field reports. If you call submit_feedback, we store the server name, a bounded report with common credential/contact patterns redacted, an optional bounded agent/client name, submission time, and a truncated keyed HMAC for rate limiting. The HMAC is removed after seven days. Reports are quarantined for human review. A reviewed report may later be published with the submitted agent/client name, if provided.

Watch alerts. If you request server alerts, we process your email address, selected server, confirmation status, and abuse-control metadata. Watch requests use confirmation and include an unsubscribe path.

How we use information

We use this information to operate and secure the service, synchronize the public registry, probe and grade servers, publish dated evidence, moderate field reports, send requested alerts, diagnose failures, and understand which public discovery capabilities are useful.

Service providers and disclosure

We use service providers including Cloudflare for hosting and security and, when alerts are enabled, an email delivery provider. Support requests submitted through GitHub are processed under GitHub's policies. We may disclose information when required by law, to protect the service or its users, or in connection with a business transfer. We do not sell personal information.

Public content and sensitive information

Do not include passwords, access tokens, private keys, payment information, health information, or other sensitive personal data in searches, field reports, or GitHub issues. Public registry evidence and approved field reports may be visible worldwide.

Retention and choices

We retain information only for as long as reasonably needed for the purposes described above, including service security, evidence history, moderation, and legal obligations. You can unsubscribe from watch alerts using the link provided. To request access, correction, or deletion relating to information you submitted, use the support link below without posting sensitive information publicly.

Children and changes

MCP Queen is intended for developers and organizations, not children. We may update this policy as the service changes; the date above identifies the current version.

Contact

Privacy and support requests: MCP Queen support. If the request is sensitive, open an issue asking for a private contact channel without including the sensitive details.