Skip to content

Privacy

Privacy

Short version: no cookies, no tracking pixels, no third-party requests from your browser. If you subscribe, we keep your email address to send you reports — nothing else.

Last updated 2026-10-08

Reading the site

  • No cookies. This site sets none.
  • No third-party requests. Fonts and every other asset are served from our own domain; your browser doesn’t contact Google, a CDN, or an ad network when you read a page.
  • Analytics: none at the moment. If we add page-view counting, it will be cookieless and collect no personal data, and this page will name the provider before it is switched on.
  • Server logs. Like any website, our host (Vercel) processes your IP address and browser details to deliver pages and protect against abuse.

Newsletter

  • What we keep: your email address, when you signed up, which form you used, and the status of your subscription with when it changed (when the confirmation email was sent, when you confirmed, when you unsubscribed).
  • What it’s for: one email when we publish a report or a correction. Nothing else, and it is never sold or shared for marketing.
  • Confirmation first: after you sign up we send one email asking you to confirm; we won’t send anything else until you do. Confirmation links expire after 48 hours, and we send at most one confirmation email per address per day.
  • Who sends it: emails are delivered by Resend, an email delivery service, which receives your address and the message in order to deliver it. Your browser never contacts Resend — the signup, confirm and unsubscribe pages are all on our own domain.
  • No tracking: our emails contain no tracking pixels, and links are not rewritten — each one goes straight to the page it names.
  • Leaving: every email has a one-click unsubscribe link, and you can also reply to any email. Unsubscribing stops all newsletter emails; to have your address deleted entirely, contact us.
  • Where it’s stored: a MongoDB Atlas database used only by this site.

Data about MCP servers

Our reports use public records from the MCP registry, npm, PyPI and GitHub. Reports are aggregate; where a future page names a server, it quotes only public upstream facts, each with its source and date, and its publisher can respond.