HeyMCP

Legal

Privacy policy

In effect from 17 August 2026.

This explains what we (HeyMCP) collect when you use HeyMCP, why, and what you can do about it. We've written it against what the software actually stores rather than in the abstract.

What we collect

Your account

When you sign in with GitHub we receive and store your GitHub user ID, username, display name, email address and avatar URL. We also store the plan you're on, the URL slug reserved to you, and your email notification preferences.

Your shares

For each share you open: the slug and public URL, the local address you shared, the CLI version, when it opened and closed, counts of requests, events, errors and bytes, and which MCP clients connected (identified from what they tell us about themselves — "Claude", "Cursor" and so on).

The traffic through your shares

This is the part worth reading carefully. While a share is open, the MCP frames crossing it pass through our relay and are stored so you can read them back in the inspector. That includes tool names, arguments, results, error messages, and the request and response bodies themselves — whatever your server and the connected agent send each other. Large payloads are truncated; the rest is kept whole.

We can't tell what's inside those payloads. If you put credentials, customer records or anything else sensitive through a share, we will store it for the retention window below. Treat a share as a development tool and send it development data.

Custom domains

If you connect your own domain we store the hostname, its verification state, and a verification token. Setting one up involves DNS lookups against that hostname.

Security and audit records

We log significant account actions — signing in, rolling a CLI token, adding a domain, changing a plan — with a timestamp and the IP address they came from. CLI tokens are stored only as hashes, alongside the last few characters so you can recognise them.

Payments

Pro subscriptions are handled by Stripe. Stripe holds your card details; we never see or store them. We keep the Stripe customer and subscription identifiers, your plan, and its renewal state.

Why we hold it

We don't sell personal data, and we don't use your traffic to train machine-learning models.

How long we keep it

Who else sees it

We use a small number of providers, each doing one job:

Otherwise we share personal data only when the law requires it, or to protect someone's rights or safety. If the business is ever sold or merged, account data may transfer with it; we'd tell you first.

Where it's held

Our servers are in the EU. Some of the providers above operate elsewhere, including the United States; where they do, transfers rely on the safeguards those providers publish, such as standard contractual clauses.

Your rights

Depending on where you live, you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere. In practice:

Email hello@heymcp.dev for anything you can't do yourself. If you think we've handled your data badly, you can complain to your local data protection authority.

Cookies

We set a session cookie to keep you signed in, and a CSRF cookie to stop forged requests. That's all — there are no advertising or analytics cookies, and nothing to consent to.

Security

Traffic is encrypted in transit. CLI tokens are hashed. Access to production data is limited to people who need it. No service is perfectly secure, and we won't pretend otherwise — if a breach affects you, we'll tell you.

Children

HeyMCP isn't for children under 13, and we don't knowingly collect their data. If you believe a child has given us data, email us and we'll remove it.

Changes

We may update this page. If a change materially affects how we handle your data, we'll email account holders before it takes effect. The date at the top shows the version in force.

Questions about this page? Email hello@heymcp.dev.