# Privacy policy

This policy describes which data OnlyMCP processes, for what purpose, and what
rights you have. It follows the Swiss Data Protection Act (revFADP) and, where
applicable, the EU General Data Protection Regulation (GDPR).

## Controller

Francesco Palazzo, contact details in the [legal notice](https://only-mcp.com/legal/imprint).

## What OnlyMCP is

OnlyMCP is a cloud workspace for AI coding agents. You connect your own MCP
client (for example Claude Code, Codex or Gemini CLI) to OnlyMCP through a
single endpoint and get your skills, agent definitions and structured memory
synced across devices. What your AI client does with that content is outside
OnlyMCP. See the [AI notice](https://only-mcp.com/legal/ai-notice).

## Data processed

**Account data:** email address, name, password as a hash (the password itself
is never stored), and which versions of the terms of service and of this privacy
policy you accepted, and when.

**Sign-in data:** sessions with IP address and user agent. When signing in via
GitHub or Google, additionally the identity confirmed by that provider.

**Device and API tokens:** for access through your MCP client, only a SHA-256
hash of the token is stored, never the token itself.

**Your content:** the skill files, agent definitions and memory files
(Markdown with frontmatter and wiki-links) you create in OnlyMCP. They reside
exclusively in the database (Postgres), never on a filesystem.

**Event log:** which of your content your clients read or changed, with its
name, the device and the time, so that you can follow it in the activity view.

**Audit log:** administrative and security-relevant actions on your account,
with the IP address they came from.

**OAuth authorizations:** when you connect a chat client such as Claude.ai or
ChatGPT through OAuth, the client's registration, your consent and the tokens
issued to it.

**Billing data:** when a paid plan is used, the data required for that. See
the third parties section below.

**MCP connections:** when you attach third-party MCP servers, we store the
name, address, transport and the list of capabilities found there. A
credential you store for it, and the OAuth tokens you obtain when you
authorize it, are kept encrypted (AES-256-GCM), decrypted only immediately
before a call and never returned to any client; of a stored credential only
the last four characters are visible. The content flowing through such a
connection is not stored - it is passed through.

**Newsletter:** only if you subscribe, see the newsletter section below.

**Contact form:** only if you use it, see the contact form section below.

## Purposes and legal bases

- **Performance of contract:** operating the platform, syncing your content,
  billing, and the record of which versions of these documents you accepted.
- **Legitimate interest:** security, abuse prevention, troubleshooting,
  technical logs, answering messages sent through the contact form.
- **Consent:** the newsletter, if you subscribe to it.
- **Legal obligation:** retention of billing-relevant data.

## Newsletter

OnlyMCP sends its newsletter only to addresses that asked for it and confirmed
that request (double opt-in). After you subscribe, whether on the website,
during registration or in your account settings, you receive an email with a
confirmation link, and no newsletter is sent to that address until you click
it.

**What is stored:** your email address, the language you chose, where you
subscribed, the wording of the consent you gave and the IP address you gave it
from, the times of subscribing, confirming and unsubscribing, and for each
mailing whether it was delivered. Three failed deliveries in a row end the
subscription.

**Purpose and legal basis:** sending the newsletter, on the basis of your
consent; keeping the record of that consent, on the basis of the legitimate
interest in being able to prove it, also after you withdraw it.

**Unsubscribing:** every newsletter contains a link that unsubscribes you with
one click, and email programs that support it offer the same through the
`List-Unsubscribe` header. You may also withdraw your consent at any time by
writing to the address in the legal notice.

**Retention:** the entry is kept while you are subscribed. A subscription that
is never confirmed stays pending and receives nothing further. After you
unsubscribe, the entry stays as the record of the consent you gave and
withdrew. Your email address and IP address remain in it for
3 years after you unsubscribe; then the address is replaced
by a one-way hash and the IP address is removed: the record remains, your
address does not. Subscribing again later starts a new double opt-in.

**Giveaways:** the newsletter may announce a giveaway of a plan trial. Winners
are drawn at random among confirmed subscribers who have an account and no
paid plan or running trial; a winner's account receives the trial and the
winner is told by email. Nothing is passed on to anyone for the draw; the
email to the winner is sent like every other email (see Third parties).

## Contact form

Through the contact form on the website you can write to the operator, whether
you have an account or not. The operator reads your message in OnlyMCP's
administration area and answers you personally by email; no automatic
confirmation is sent to the address you give.

**What is stored:** the email address you give, the topic you chose, your
message, the language of the page and the time, and your account if you are
signed in when you send it. To limit abuse, your IP address is also kept as a
counter for about an hour, and a one-way hash of your email address for about
a day.

**Purpose and legal basis:** answering your message, on the basis of the
legitimate interest in being able to answer enquiries, and, where it concerns
your account or your plan, the performance of contract.

**Where it is kept:** only in OnlyMCP's database, where the operator reads the
message in the administration area. The message itself is not sent by email
and is not passed on to anyone.

**Retention:** a message is deleted after 12 months, or earlier if
you ask (a message to the address in the legal notice is sufficient). If you
delete your account, the messages you sent while signed in are deleted with
it, and so are those received under its email address.

## Third parties

OnlyMCP uses the following services. Operation is not possible without them.

- **GitHub and Google** only if you choose to sign in with those providers.
- **Stripe** for payment processing of the paid plans. Your card data never
  reaches OnlyMCP's servers, it is processed directly by Stripe. Stripe is a
  US-based provider; the transfer relies on EU/CH standard contractual
  clauses.
- **Email delivery** via mail.exigo.ch (encrypted with STARTTLS) for
  verification codes, password resets, team invitations and notices about your
  plan, and for the newsletter if you subscribe to it.
- **Hosting** in a Kubernetes cluster on infrastructure located in Europe.

**MCP servers you connect yourself** are not services OnlyMCP uses, but
services you choose. OnlyMCP calls them on your behalf and has no
relationship with their operators; their own terms and privacy policies
apply. Details are in the third-party notices.

OnlyMCP uses no analytics services, no tracking and no advertising.

## What your AI client does with your content

OnlyMCP itself runs no AI model and holds no AI access tokens. When you fetch
your content through your own MCP client, it is sent to whichever AI provider
that client uses. OnlyMCP has neither visibility into nor control over that
data flow, and is not responsible for it. See the [AI notice](https://only-mcp.com/legal/ai-notice).

## Retention

Your content is kept until your account is deleted. The audit log is kept for
12 months, the event log for 90 days. Billing data is kept for as long as
statutory retention periods require. Newsletter data is kept as described in
the newsletter section, messages from the contact form as described in the
contact form section.

## Your rights

You have the right of access, rectification, erasure and restriction of
processing, the right to data portability, and the right to object to
processing based on legitimate interest. You may withdraw consent at any time.
A message to the address in the legal notice is sufficient. OnlyMCP does not
make automated individual decisions with legal effect or a comparably
significant impact on you.

## Right to complain

In Switzerland you may contact the Federal Data Protection and Information
Commissioner (FDPIC). In the EU, the data protection authority of your country
of residence.

## Data security

Transmission is encrypted (TLS) only. Passwords and device/API tokens are
stored as hashes only. Access to production data is restricted to the operator
of the platform.

## Changes

If this policy changes materially, renewed consent is requested. Purely
editorial corrections do not trigger this. The applicable version is shown at
the top of this document.

## Authoritative version

This is a translation provided for convenience. In case of discrepancies, the
German version of this document prevails.
