Privacy
MCP Trust Index is operated by Klars AI. This page describes what personal data we hold, why, and how to have it removed. It is written to be read, not to be survived.
Last updated 30 August 2026.
What we collect
If you only browse
No account, no tracking cookies, no analytics scripts and no advertising pixels. Our server keeps standard request logs — IP address, timestamp, the page requested and the user agent — which are used solely to operate the service and to identify abuse. These are retained for up to 30 days and then deleted.
If you subscribe to the weekly report
We store:
- Your email address — to send you the report.
- The IP address you signed up from — to rate-limit abuse of a public form. Held for the life of the subscription.
- Signup and confirmation timestamps — to evidence consent.
That is the whole record. We do not track opens, clicks, or anything you do after the email arrives.
Cookies
The public site sets no cookies at all. The separate operations console sets a single strictly-necessary session cookie for authorised staff; it carries no tracking identifier and is not used on this site.
Data about MCP servers
The index itself is built from public sources: the official MCP registry, the GitHub REST API and the OSV vulnerability database. Where that data includes a maintainer's name or handle, it is already public on those platforms and is shown here in the same form. If you publish a server and want a record corrected or removed, email contact@klars.ai.
Legal basis and retention
Under the UK GDPR and EU GDPR we rely on consent for the mailing list (withdrawable at any time) and on legitimate interests for security logging and abuse prevention. Subscription data is kept until you unsubscribe, after which the record is deleted.
Who else sees your data
The service runs on Amazon Web Services (EU/US regions) and outbound email is sent through a transactional email provider. Both act as processors under contract and may not use your data for their own purposes. We do not sell, rent or share personal data with anyone else.
Your rights
You can ask us to access, correct, export or delete your data, object to processing, or withdraw consent. Every email we send carries a one-click unsubscribe link. For anything else, email contact@klars.ai — we aim to reply within a few days, and within one month at the outside. If you are in the UK or EU and are unhappy with our response, you may complain to your national data protection authority.
Security
Traffic is encrypted in transit with TLS. Data at rest is on encrypted storage. Administrative access requires two-factor authentication, and every access to personal data is recorded in an append-only audit log with the actor, address and timestamp.
Changes
If this policy changes materially, the date above changes with it, and subscribers are told by email before the change takes effect.