# Third-party notices

## Services used

- **GitHub and Google** as optional sign-in providers.
- **Stripe** as the payment processor for the paid plans. Stripe processes
  card data directly; it never reaches OnlyMCP's servers. Stripe is based in
  the US; the transfer relies on EU/CH standard contractual clauses.
- **mail.exigo.ch** as the mail server for verification codes, password
  resets, team invitations, plan notices and the newsletter, encrypted with
  STARTTLS.
- **Hosting** in a Kubernetes cluster on infrastructure located in Europe.

OnlyMCP uses no analytics services, no tracking and no advertising.

## MCP servers you connect yourself

The "MCP connections" feature lets you attach any third-party MCP server to
your account, for example GitHub, Linear, Notion or a service of your own. What
matters about that:

- **You make the choice.** OnlyMCP connects none of these services on its own
  and has no relationship with their operators. A brand named here or in the
  interface is an example, not a partnership and not a recommendation.
- **Each connected service is governed by its own terms and privacy
  policy.** Read them before connecting it. What you read or write through
  such a server happens at that provider, not at OnlyMCP.
- **What OnlyMCP does:** we call the server on your behalf. Your client's
  request goes to OnlyMCP, OnlyMCP calls the connected service, the answer
  comes back the same way. The connected service therefore sees the network
  address of our servers, not yours.
- **Credentials** you store for a connection are kept encrypted
  (AES-256-GCM), decrypted only immediately before the call, and never
  returned to any client. The interface shows the last four characters only.
- **Deleting** a connection deletes the stored credential with it. It changes
  nothing at the connected service; revoke the access there yourself.

## Open source libraries

The following list is generated from the project's actual dependencies and
rewritten on every update.

<!-- GENERIERT:START -->

- **@base-ui/react** (MIT)
- **@better-auth/cimd** (MIT)
- **@better-auth/mcp** (MIT)
- **@clack/prompts** (MIT)
- **@hono/node-server** (MIT)
- **@hono/zod-openapi** (MIT)
- **@hookform/resolvers** (MIT)
- **@icons-pack/react-simple-icons** (MIT)
- **@modelcontextprotocol/sdk** (MIT)
- **@napi-rs/keyring** (MIT)
- **@tanstack/react-query** (MIT)
- **@tanstack/react-table** (MIT)
- **better-auth** (MIT)
- **cacache** (ISC)
- **class-variance-authority** (Apache-2.0)
- **clsx** (MIT)
- **commander** (MIT)
- **drizzle-orm** (Apache-2.0)
- **fflate** (MIT)
- **hono** (MIT)
- **i18next** (MIT)
- **i18next-browser-languagedetector** (MIT)
- **lucide-react** (ISC)
- **motion** (MIT)
- **nodemailer** (MIT-0)
- **open** (MIT)
- **pg** (MIT)
- **pg-boss** (MIT)
- **pino** (MIT)
- **qrcode** (MIT)
- **rate-limiter-flexible** (ISC)
- **react** (MIT)
- **react-dom** (MIT)
- **react-force-graph-2d** (MIT)
- **react-hook-form** (MIT)
- **react-i18next** (MIT)
- **react-router** (MIT)
- **shiki** (MIT)
- **sonner** (MIT)
- **stripe** (MIT)
- **tailwind-merge** (MIT)
- **tw-animate-css** (MIT)
- **undici** (MIT)
- **zod** (MIT)

<!-- GENERIERT:ENDE -->

## Note

Each library listed is subject to its own licence. Listing it here does not
imply any affiliation between its authors and OnlyMCP. The **stripe** entry
refers to the open source client SDK; as a service used, Stripe is also
listed separately above under "Services used".

## Authoritative version

This is a translation provided for convenience. In case of discrepancies, the
German version of this document prevails.
