MCPatrol — Privacy Policy
Effective 23 July 2026 · applies to the MCPatrol Android app (package com.moc.mobile)
MCPatrol monitors MCP (Model Context Protocol) servers you choose to add. This page describes exactly
what data the app handles, where it lives, and how to delete it.
Two modes, two data locations
- Local mode (no account): everything you add — server URLs, probe results, incidents —
is stored only in the app's private database on your device. Nothing is sent to us.
- Cloud mode (with an account): the servers you register are monitored around the clock
by our backend, and the data below is stored on our servers (Microsoft Azure, East US region).
What we store in cloud mode
- Account: your email address and a salted hash of your password
(PBKDF2-HMAC-SHA256 via ASP.NET Identity's password hasher — we never store the password itself),
plus the API key the app uses to talk to the backend.
- Monitoring configuration: the names and URLs of the MCP servers you register, and
optional metadata you add (such as a repository URL for registry submissions).
- Probe outcomes: health state, response latency, and timestamps from each check,
plus incidents derived from them.
- Server inventory: the tools, resources, and prompts your MCP servers report, and a
history of changes to that inventory.
- Bridge data (optional): if you run the PC bridge agent, the machine name and the
stdio servers it relays, and per-request traffic metadata (method names, payload sizes, durations).
Request/response payload capture is off by default; if you enable it explicitly, captured payloads are
redacted before storage and you can turn it off at any time.
- Push tokens: if you enable notifications, the Firebase Cloud Messaging token for your
device, used only to deliver your alerts.
What we don't do
- No advertising SDKs, no analytics or tracking SDKs, no location, no contacts, no advertising identifiers.
- We don't sell data or share it with third parties. The only processors involved are our infrastructure
providers: Microsoft Azure (hosting and database) and Google Firebase Cloud Messaging (push delivery).
- Data from your servers is used only to show you your own monitoring — never for anything else.
Security
All traffic between the app, the bridge, and the backend uses TLS. Backend access requires your
per-account API key. Passwords are stored only as salted PBKDF2 hashes.
Delete your account and data
You can delete your account and all associated data directly in the app, without contacting anyone:
- Open MCPatrol and go to the Manage tab.
- In the account card, tap Delete account.
- Confirm with Delete everything.
Deletion is immediate and complete: your account, servers, probe history, incidents, inventory records,
traffic records, captured payloads, bridge registrations, and push tokens are all removed from our
database. Nothing is retained after deletion — there is no backup-restore of deleted accounts. Your API key
and login stop working the moment deletion completes.
If you can no longer access the app, email us from your account email address and we will run the same
deletion for you.
Data retention
Cloud data is retained while your account exists and is deleted when you delete your account.
Local-mode data lives only on your device and is removed when you clear the app's data or uninstall it.
Your rights (GDPR / CCPA and similar laws)
Depending on where you live, you have legal rights over your personal data. We honor them for
everyone, wherever you are:
- Access & portability: email us and we'll send everything associated with
your account email in a machine-readable form.
- Correction: the only personal data we hold is your email; email us to change it.
- Deletion: self-serve, in the app, immediate (see above) — or by email if you've
lost access.
- No sale, no sharing for advertising: we don't sell personal data or share it for
cross-context behavioral advertising, so there is nothing to opt out of.
- Complaint: you can lodge one with your local data-protection authority; we'd
appreciate the chance to fix the problem first.
Legal bases for processing (GDPR art. 6): performance of the service you signed up for
(account, monitoring data, push tokens) and legitimate interest in keeping the service secure
(server-side logs). Data controller: the developer of MCPatrol, reachable at the address below.
No automated decision-making, no profiling.
Changes and contact
If this policy changes, the effective date above will be updated. Questions and deletion requests:
privacy@detentpoint.com.