Legal
Privacy policy
In effect from 17 August 2026.
This explains what we (HeyMCP) collect when you use HeyMCP, why, and what you can do about it. We've written it against what the software actually stores rather than in the abstract.
What we collect
Your account
When you sign in with GitHub we receive and store your GitHub user ID, username, display name, email address and avatar URL. We also store the plan you're on, the URL slug reserved to you, and your email notification preferences.
Your shares
For each share you open: the slug and public URL, the local address you shared, the CLI version, when it opened and closed, counts of requests, events, errors and bytes, and which MCP clients connected (identified from what they tell us about themselves — "Claude", "Cursor" and so on).
The traffic through your shares
This is the part worth reading carefully. While a share is open, the MCP frames crossing it pass through our relay and are stored so you can read them back in the inspector. That includes tool names, arguments, results, error messages, and the request and response bodies themselves — whatever your server and the connected agent send each other. Large payloads are truncated; the rest is kept whole.
We can't tell what's inside those payloads. If you put credentials, customer records or anything else sensitive through a share, we will store it for the retention window below. Treat a share as a development tool and send it development data.
Custom domains
If you connect your own domain we store the hostname, its verification state, and a verification token. Setting one up involves DNS lookups against that hostname.
Security and audit records
We log significant account actions — signing in, rolling a CLI token, adding a domain, changing a plan — with a timestamp and the IP address they came from. CLI tokens are stored only as hashes, alongside the last few characters so you can recognise them.
Payments
Pro subscriptions are handled by Stripe. Stripe holds your card details; we never see or store them. We keep the Stripe customer and subscription identifiers, your plan, and its renewal state.
Why we hold it
- To run the service — carry your traffic, show you your timeline, enforce plan limits, bill you. This is what performing our contract with you requires.
- To keep it safe — spot abuse, investigate incidents, stop the relay being used to attack people. Our legitimate interest, and yours.
- To reach you — service notices, and the failure alerts you can switch off in your profile.
- To meet legal obligations — tax and accounting records, mostly.
We don't sell personal data, and we don't use your traffic to train machine-learning models.
How long we keep it
- Event payloads — 24 hours on the free plan, 7 days on Pro, counted from when the event arrived. A scheduled job deletes them hourly, and the inspector shows the expiry on each session.
- Session records — the slug, counters and timings outlive the payloads, so your history stays legible after the detail has gone.
- Account data — until you delete your account.
- Audit and billing records — kept after account deletion where we need them for security or accounting, then removed.
Who else sees it
We use a small number of providers, each doing one job:
- GitHub — sign-in.
- Stripe — payments and card handling.
- Our hosting and email providers, to run the servers and send you the messages you've asked for.
Otherwise we share personal data only when the law requires it, or to protect someone's rights or safety. If the business is ever sold or merged, account data may transfer with it; we'd tell you first.
Where it's held
Our servers are in the EU. Some of the providers above operate elsewhere, including the United States; where they do, transfers rely on the safeguards those providers publish, such as standard contractual clauses.
Your rights
Depending on where you live, you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere. In practice:
- See it — most of it is already in the app: your sessions, events, domains and profile.
- Export it — the CLI can export a session's events.
- Delete it — deleting your account removes your sessions and their stored events. Closing a share and waiting out the retention window clears its payloads on its own.
Email hello@heymcp.dev for anything you can't do yourself. If you think we've handled your data badly, you can complain to your local data protection authority.
Cookies
We set a session cookie to keep you signed in, and a CSRF cookie to stop forged requests. That's all — there are no advertising or analytics cookies, and nothing to consent to.
Security
Traffic is encrypted in transit. CLI tokens are hashed. Access to production data is limited to people who need it. No service is perfectly secure, and we won't pretend otherwise — if a breach affects you, we'll tell you.
Children
HeyMCP isn't for children under 13, and we don't knowingly collect their data. If you believe a child has given us data, email us and we'll remove it.
Changes
We may update this page. If a change materially affects how we handle your data, we'll email account holders before it takes effect. The date at the top shows the version in force.
Questions about this page? Email hello@heymcp.dev.