Privacy
Version 1.1 · effective .
What is collected today: nothing
This build is a preview. There is no claim flow accepting submissions, and no route on this site stores anything about a visitor. Everything below describes what will apply when claiming a server becomes possible, published in advance rather than after collection begins.
The distinction this whole page turns on
A reachability observation of a public endpoint is not personal data. We record a URL that is already publicly listed, whether a protocol handshake completed, how long it took, and a fingerprint of the tool schema the server itself advertises. That describes a service, not a person, and it is the entire content of the archive.
A claimant's contact details are personal data. The moment someone tells us who they are in order to claim a server, we are holding information about a person, and it is treated differently from everything in the paragraph above. The two are never merged into one store and never published together.
What the claim flow will collect
- An email address to correspond about the claim.
- The endpoint being claimed, and the domain or account the claim is made against.
- Public key material only — the key you have already published in DNS or at a well-known URL, plus a signature over a challenge we issue. This is public by design; publishing it is how the proof works.
- Which method proved the claim, against which key, and at what time.
A verified claim is stored apart from your contact details. The record a badge reads carries what was proven, how, against which published key and when — and no contact detail of any kind. That is enforced by the shape of the stored record rather than by a promise to keep them apart.
We never accept a private key, and we will never ask for one. A proof that required you to hand over a secret would be a worse proof and a liability for both of us. If anything ever asks you for a private key in our name, it is not us.
Why we hold it
Contact details are held to operate the claim — to correspond with you about it, and to let you manage or withdraw it later. Proof material is held to make a verified claim re-checkable: a claim nobody can re-verify later is an assertion, and this site does not trade in those. That is the whole of the purpose, and we do not repurpose either for anything else.
We do not sell personal data, and we do not use claim contact details for marketing.
How long it is kept
- Contact details: for as long as the claim stands. Withdraw the claim and they are deleted.
- Proof material and the verification result: retained for as long as the claim is displayed, because a displayed claim that cannot be re-checked is worth less than no claim.
- Reachability observations: retained permanently. They are the archive, and their value is precisely that they are longitudinal.
What you can ask for, and one thing we cannot do
Ask at contact@mcpverify.ai for a copy of what we hold about you, a correction to it, or its deletion. For contact details and claim records, we can do all three.
What we cannot do is remove an observation from a published snapshot. Published snapshots are anchored and append-only — the reasoning is set out on delisting. We are stating that here rather than promising a deletion we would then have to explain our way out of. It is also a narrower limit than it sounds: those snapshots contain endpoint observations, which is the category that is not personal data in the first place.
Who is responsible for your data
The data controller for personal data collected through the claim flow is MCPVERIFY LABS, contactable at the address below.
Data controller: MCPVERIFY LABS · contact@mcpverify.ai
Third parties
This site is served by a hosting provider, which necessarily processes the requests that reach it. There is no analytics, no advertising, and no third-party tracking script on any page here — you can check that by viewing the source of this one.