Skip to content
Back

Privacy policy

Version 1.3.1 · 2026-10-05

This policy describes which data OnlyMCP processes, for what purpose, and what rights you have. It follows the Swiss Data Protection Act (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

Controller

Francesco Palazzo, contact details in the legal notice.

What OnlyMCP is

OnlyMCP is a cloud workspace for AI coding agents. You connect your own MCP client (for example Claude Code, Codex or Gemini CLI) to OnlyMCP through a single endpoint and get your skills, agent definitions and structured memory synced across devices. What your AI client does with that content is outside OnlyMCP. See the AI notice.

Data processed

Account data: email address, name, password as a hash (the password itself is never stored), and which versions of the terms of service and of this privacy policy you accepted, and when.

Sign-in data: sessions with IP address and user agent. When signing in via GitHub or Google, additionally the identity confirmed by that provider.

Device and API tokens: for access through your MCP client, only a SHA-256 hash of the token is stored, never the token itself.

Your content: the skill files, agent definitions and memory files (Markdown with frontmatter and wiki-links) you create in OnlyMCP. They reside exclusively in the database (Postgres), never on a filesystem.

Event log: which of your content your clients read or changed, with its name, the device and the time, so that you can follow it in the activity view.

Audit log: administrative and security-relevant actions on your account, with the IP address they came from.

OAuth authorizations: when you connect a chat client such as Claude.ai or ChatGPT through OAuth, the client's registration, your consent and the tokens issued to it.

Billing data: when a paid plan is used, the data required for that. See the third parties section below.

MCP connections: when you attach third-party MCP servers, we store the name, address, transport and the list of capabilities found there. A credential you store for it, and the OAuth tokens you obtain when you authorize it, are kept encrypted (AES-256-GCM), decrypted only immediately before a call and never returned to any client; of a stored credential only the last four characters are visible. The content flowing through such a connection is not stored - it is passed through.

Newsletter: only if you subscribe, see the newsletter section below.

Contact form: only if you use it, see the contact form section below.

  • Performance of contract: operating the platform, syncing your content,

billing, and the record of which versions of these documents you accepted.

  • Legitimate interest: security, abuse prevention, troubleshooting,

technical logs, answering messages sent through the contact form.

  • Consent: the newsletter, if you subscribe to it.
  • Legal obligation: retention of billing-relevant data.

Newsletter

OnlyMCP sends its newsletter only to addresses that asked for it and confirmed that request (double opt-in). After you subscribe, whether on the website, during registration or in your account settings, you receive an email with a confirmation link, and no newsletter is sent to that address until you click it.

What is stored: your email address, the language you chose, where you subscribed, the wording of the consent you gave and the IP address you gave it from, the times of subscribing, confirming and unsubscribing, and for each mailing whether it was delivered. Three failed deliveries in a row end the subscription.

Purpose and legal basis: sending the newsletter, on the basis of your consent; keeping the record of that consent, on the basis of the legitimate interest in being able to prove it, also after you withdraw it.

Unsubscribing: every newsletter contains a link that unsubscribes you with one click, and email programs that support it offer the same through the List-Unsubscribe header. You may also withdraw your consent at any time by writing to the address in the legal notice.

Retention: the entry is kept while you are subscribed. A subscription that is never confirmed stays pending and receives nothing further. After you unsubscribe, the entry stays as the record of the consent you gave and withdrew. Your email address and IP address remain in it for 3 years after you unsubscribe; then the address is replaced by a one-way hash and the IP address is removed: the record remains, your address does not. Subscribing again later starts a new double opt-in.

Giveaways: the newsletter may announce a giveaway of a plan trial. Winners are drawn at random among confirmed subscribers who have an account and no paid plan or running trial; a winner's account receives the trial and the winner is told by email. Nothing is passed on to anyone for the draw; the email to the winner is sent like every other email (see Third parties).

Contact form

Through the contact form on the website you can write to the operator, whether you have an account or not. The operator reads your message in OnlyMCP's administration area and answers you personally by email; no automatic confirmation is sent to the address you give.

What is stored: the email address you give, the topic you chose, your message, the language of the page and the time, and your account if you are signed in when you send it. To limit abuse, your IP address is also kept as a counter for about an hour, and a one-way hash of your email address for about a day.

Purpose and legal basis: answering your message, on the basis of the legitimate interest in being able to answer enquiries, and, where it concerns your account or your plan, the performance of contract.

Where it is kept: only in OnlyMCP's database, where the operator reads the message in the administration area. The message itself is not sent by email and is not passed on to anyone.

Retention: a message is deleted after 12 months, or earlier if you ask (a message to the address in the legal notice is sufficient). If you delete your account, the messages you sent while signed in are deleted with it, and so are those received under its email address.

Third parties

OnlyMCP uses the following services. Operation is not possible without them.

  • GitHub and Google only if you choose to sign in with those providers.
  • Stripe for payment processing of the paid plans. Your card data never

reaches OnlyMCP's servers, it is processed directly by Stripe. Stripe is a US-based provider; the transfer relies on EU/CH standard contractual clauses.

  • Email delivery via mail.exigo.ch (encrypted with STARTTLS) for

verification codes, password resets, team invitations and notices about your plan, and for the newsletter if you subscribe to it.

  • Hosting in a Kubernetes cluster on infrastructure located in Europe.

MCP servers you connect yourself are not services OnlyMCP uses, but services you choose. OnlyMCP calls them on your behalf and has no relationship with their operators; their own terms and privacy policies apply. Details are in the third-party notices.

OnlyMCP uses no analytics services, no tracking and no advertising.

What your AI client does with your content

OnlyMCP itself runs no AI model and holds no AI access tokens. When you fetch your content through your own MCP client, it is sent to whichever AI provider that client uses. OnlyMCP has neither visibility into nor control over that data flow, and is not responsible for it. See the AI notice.

Retention

Your content is kept until your account is deleted. The audit log is kept for 12 months, the event log for 90 days. Billing data is kept for as long as statutory retention periods require. Newsletter data is kept as described in the newsletter section, messages from the contact form as described in the contact form section.

Your rights

You have the right of access, rectification, erasure and restriction of processing, the right to data portability, and the right to object to processing based on legitimate interest. You may withdraw consent at any time. A message to the address in the legal notice is sufficient. OnlyMCP does not make automated individual decisions with legal effect or a comparably significant impact on you.

Right to complain

In Switzerland you may contact the Federal Data Protection and Information Commissioner (FDPIC). In the EU, the data protection authority of your country of residence.

Data security

Transmission is encrypted (TLS) only. Passwords and device/API tokens are stored as hashes only. Access to production data is restricted to the operator of the platform.

Changes

If this policy changes materially, renewed consent is requested. Purely editorial corrections do not trigger this. The applicable version is shown at the top of this document.

Authoritative version

This is a translation provided for convenience. In case of discrepancies, the German version of this document prevails.