Back to home

GDPR information

Last updated September 23, 2026

1. Summary

This page explains how MCPBay approaches the EU General Data Protection Regulation (GDPR) and the UK GDPR: who is responsible for your data, where it is stored, who processes it on our behalf and how to exercise your rights. It complements the Privacy Policy, which remains the governing document.

This is a self-assessment. There is no official “GDPR certificate”, and this page is not one.

2. Who is responsible

The data controller is Stonebyte LLC, a Wyoming limited liability company, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Contact: support@mcpbay.pro.

For MCP servers in the catalog, each server’s author decides what their server does with the data you send to it. We check hosted servers as described on the Security page, but we do not see or control what a third-party server does with your requests.

3. What we keep and why

  • Account data — login, email, password hash, optional 2FA settings — to provide your account (contract).
  • API keys you choose to store, encrypted, to let the servers you use call third-party services for you (contract).
  • Per-user tool-call statistics — tool name, success, duration, paid or not; never arguments or content — to show your usage and bill paid calls (contract).
  • Security logs of sign-ins and sensitive account actions, including IP address and browser, to protect accounts (legitimate interest).
  • Website analytics, subject to consent in the EEA, UK and Switzerland (consent / legitimate interest).

The legal bases are set out in section 5 of the Privacy Policy.

4. Where your data is stored

Our servers are located in the United States. Transfers of personal data from the EEA, the UK and Switzerland are made as described in section 7 of the Privacy Policy.

5. Your rights

You have the right to access, correct, delete and export your personal data, to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your data protection authority.

  • Correct your login and email in your account settings.
  • Delete your account yourself in account settings (your password is required).
  • Everything else — access, export, restriction, objection — email support@mcpbay.pro from the address on your account. We answer within one month.

6. What happens when you delete your account

Your account and the data tied to it are deleted immediately: profile, stored API keys, saved servers, usage statistics, wallet and billing records, sign-in tokens, trusted devices, recovery codes and notifications.

Kept after deletion: security logs (IP address and browser of past actions, and a record of the deletion that includes your login and email), the access log of stored keys, aggregate tool-call statistics, and servers you submitted to the catalog, which stay listed but are no longer linked to your account. Delete your servers before deleting the account if you want them removed, or ask us.

7. Cookies

  • mcpbay_session — keeps you signed in (7 days).
  • mcpbay_trusted — “remember this device” for 2FA (15 days), only if you choose it.
  • Analytics cookies — only if analytics is allowed; in the EEA, UK and Switzerland only after consent.

8. Security

Technical and organisational measures are described on the Security page.

9. Contact

Questions and requests about your data: support@mcpbay.pro.