mcpcert.org

Privacy Policy

Last updated: May 2025

This Privacy Policy describes how mcpcert.org (the “Service”) collects, uses, and shares information when you use our platform.

1. Information We Collect

We collect the information you provide when creating an account (via Google or GitHub OAuth), including your email address and display name. We also collect the application details you submit during registration (application name, redirect URIs, client metadata).

2. How We Use Your Information

Your information is used to operate the Service, generate and host Client Identity Metadata Documents, and run conformance tests. We do not sell your personal information to third parties.

3. Hosted Documents

Client ID Metadata Documents (CIMDs) hosted at mcpcert.org are publicly accessible at the URLs generated during registration. This is necessary for the MCP client ID verification protocol to function.

4. Authentication Providers

We use Firebase Authentication with Google and GitHub as identity providers. Authentication is handled by these providers' respective OAuth flows. We do not store your OAuth credentials.

5. Data Retention

Registration data and hosted documents are retained for as long as your account is active. You may request deletion of your account and associated data by contacting us.

6. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email.