Privacy Policy
How MCP Studio handles your account, API specifications, and generated servers.
Last updated: September 27, 2026
1. Overview
This Privacy Policy explains how MCP Studio collects, uses, stores, and protects information when you use this application to import OpenAPI specifications and generate Model Context Protocol servers. By using the service, you agree to the practices described here.
2. Information We Collect
We collect only the information needed to operate the service:
- Account information: the email address and password you provide when signing in. Passwords are never stored in plain text.
- API specifications: the OpenAPI or Swagger JSON files you upload, together with derived data such as endpoints, parameters, request bodies, and response schemas.
- Generated server metadata: records of the servers you create, including target base URLs.
- Technical data: basic request and error logs such as IP address, browser type, and timestamps, used for security and diagnostics.
3. How We Use Information
- Authenticate you and maintain your session.
- Parse, validate, and index uploaded specifications.
- Generate and deliver MCP server bundles.
- Operate, secure, and troubleshoot the service.
- Respond to support requests and legal obligations.
We do not sell your personal information or use uploaded specifications to train third-party models.
4. Data Storage & Retention
Specifications and their derived data are stored in the application database and remain until you delete them. Account sessions expire when you sign out, and temporary server files are retained only as long as needed to serve your downloads.
5. Cookies & Sessions
MCP Studio uses a single session cookie to keep you signed in. It is marked HttpOnly and SameSite=Lax, and it does not contain your password. Clearing cookies or signing out ends the session.
6. Sharing & Disclosure
We do not share your data with third parties except where necessary to run the service (for example, hosting or database infrastructure), or where required by law. Links to external resources such as the MCP documentation are governed by those sites' own privacy policies.
7. Security
Passwords are hashed and verified with PHP's password_hash() and password_verify(). Access to the dashboard requires authentication. While we apply reasonable safeguards, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
You may access, correct, or delete the specifications and account data associated with your use of the service. To make a request, contact the operator of this instance using the details below.
9. Children's Privacy
MCP Studio is intended for developers and is not directed at children. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this policy or your data can be directed to the administrator of this MCP Studio instance.