Privacy Policy

Last updated: August 20, 2026

This Privacy Policy explains how Hauke Jung ("we," "us," or "our") collects, uses, and protects personal information in connection with mcpi — this website (https://mcpi.app), the public MCP server directory it hosts, and the mcpi desktop application.

We handle data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws in Germany and the European Union.


1. The desktop app first

The mcpi desktop application runs entirely on your machine and sends us nothing. It has no telemetry, no account, and no activation server; the licence key is verified offline. Its only network traffic is between you and the MCP servers you choose to connect to. Server configurations and call history are stored in a local database on your disk, and secrets go to your operating system's keychain. Everything below therefore concerns the website and directory only.


2. Information We Collect

a. Information you provide directly

  • Account registration details (email address, authentication data)
  • Purchase information when you buy a licence (processed by Polar as merchant of record; we receive your email address and order reference to issue and support your licence key)
  • Emails you submit to the directory's alerts waitlist
  • Messages you send us (support requests, listing corrections)

b. Information collected automatically

  • Log data such as IP address, access times, and requested pages, kept briefly for security and abuse prevention
  • Bot-protection signals from our self-hosted captcha service, used when you create an account. It processes your IP address and basic interaction data (for example, time spent on the page and a proof-of-work check) to detect and block automated abuse. This data is processed on our own servers and is not shared with any third party. The legal basis is our legitimate interest in preventing fraud and securing the service (Article 6(1)(f) GDPR).

We use no analytics or tracking services on this site. Cookies are limited to what sign-in technically requires (session cookies).

c. The server directory

The directory records technical facts about publicly reachable third-party MCP endpoints (reachability, authentication method, advertised capabilities). This is technical metadata about services, not personal data about visitors. If you claim a listing, the DNS TXT record you create to prove control is public information by nature of DNS.

d. Information from third parties

  • FerrisKey (self-hosted) for authentication and secure login
  • Polar for checkout, billing, and invoicing as merchant of record

Each provider processes data in compliance with EU regulations.


3. How We Use Your Information

  • Provide the service: authentication, licence issuing, licence support
  • Notify you, if you joined the alerts waitlist, when the feature you signed up for exists — nothing else is sent to that address
  • Prevent fraud and maintain security
  • Comply with legal obligations under EU and German law

We do not send marketing email without your explicit consent.


4. How We Share Your Information

We do not sell personal information. We share it only:

  • With service providers named above, under data protection agreements
  • When required by law or governmental authorities
  • With your consent, when you explicitly authorize it

5. Data Security

  • HTTPS encryption for all data transmissions
  • Access controls and regular security updates
  • Hosting within the European Union
  • Licence keys are verified offline; there is no activation infrastructure to breach

No system is 100% secure; while we work to protect your information, we cannot guarantee absolute security.


6. Data Retention

We retain personal data only as long as necessary to provide the service, fulfill contractual and legal obligations, and resolve disputes. Waitlist emails are deleted when the list is retired or on your request, whichever comes first. Purchase records are retained as long as required by German commercial and tax law.


7. Your Rights

As a person in the European Union, you have the following rights under the GDPR:

  • Access to a copy of the personal data we hold about you
  • Correction of inaccurate or incomplete information
  • Deletion ("right to be forgotten")
  • Restriction of processing
  • Data portability in a structured, machine-readable format
  • Objection to processing based on legitimate interests
  • Withdrawal of consent at any time, without affecting prior lawful processing

To exercise any of these rights, contact mail@haukejung.de. You also have the right to lodge a complaint with your local Data Protection Authority, such as the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI).


8. International Data Transfers

Data is stored and processed within the European Union. If a transfer outside the EU is ever necessary, we ensure appropriate safeguards such as Standard Contractual Clauses are in place.


9. Children's Privacy

The service is not intended for children under 16 years of age, and we do not knowingly collect personal information from minors.


10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced with a prominent notice on this website.


11. Contact

Data Controller:
Hauke Jung
Hauptstr. 41
79199 Kirchzarten, Germany
Email: mail@haukejung.de