Last updated: August 26, 2026
This Policy explains what personal information AgentMCP collects through the AgentMCP dashboard and the MCP endpoints and sign-in pages it publishes, why we collect it, and how you can exercise your rights over it. It covers both AgentMCP builders (people with an AgentMCP account) and end users (people who sign in to a package a builder has published).
Account information. To create and use an AgentMCP account, we collect your email address. It's the only credential needed — we authenticate you with a one-time code, so we never see or store a password.
Workspace & content. Anything you build — tool definitions, instructions, package configurations, connection settings (including allow-listed domains/emails, and OAuth client IDs where you configure a social sign-in connection — client secrets are stored encrypted, never in plain text) — and any files or logos you upload for branding, which we store in our cloud storage.
End-user information. If you're signing in to a package someone else published (for example, to let an AI agent use it), we collect the email address you provide to authenticate you, and check it against that package's access rules. We use it solely to authenticate you and enforce those rules — never for marketing.
Automatically collected information. Like most web services, our hosting infrastructure logs standard request metadata (IP address, timestamps, request paths) for security and abuse prevention. We don't run analytics or advertising trackers on AgentMCP.
AgentMCP uses exactly one cookie: a first-party, essential session cookie that keeps you signed in to the dashboard. It's set to HttpOnly and Secure, can't be read by JavaScript or third parties, and expires automatically. We don't use tracking, advertising, or third-party cookies anywhere on the site.
We do not use your content or your end users' information to train any models, and we don't sell personal information.
We share information only with the service providers ("subprocessors") that help us run AgentMCP, and only for that purpose:
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, compute, database, and file storage for the entire Service |
| Resend | Delivering transactional email (sign-in codes, invites) |
| Polar | Processing payments for paid plans, as our merchant of record |
We may also disclose information if required to by law, or to protect the rights, safety, or property of AgentMCP, our users, or the public.
We keep your information for as long as your account or workspace is active. If you delete your workspace, we delete or anonymize the associated content within a reasonable grace period, currently 30 days, except where we need to keep it longer for legal or fraud-prevention reasons.
You can ask us to access, correct, export, or delete your personal information at any time by emailing team@agentmcp.app. If data protection law that applies to you — such as the GDPR or CCPA — grants you additional rights, we'll honor those too, within the scope of that law.
We use industry-standard technical measures to protect your information: all traffic is encrypted in transit (HTTPS), OAuth client secrets are encrypted at rest, and one-time sign-in codes are never stored in plain text — only a salted hash of each code is kept, just long enough to verify it. No method of transmission or storage is 100% secure, but we work to keep these protections current.
AgentMCP is not directed at children, and we don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.
AgentMCP runs on Cloudflare's global network, which may process data in multiple countries in order to serve requests quickly and reliably close to where you are. Wherever your data is processed, we require our subprocessors to protect it consistently with this Policy.
We may update this Policy from time to time. We'll update the "Last updated" date above, and for material changes we'll make a reasonable effort to notify you by email or an in-app notice.
Questions about this Policy, or a request about your data? Email us at team@agentmcp.app.