Privacy Policy & Data Protection Statement
Effective Date: August 21, 2026 · Version 2.4
At MCP-Bridge (https://mcpbridge.org), we take developer privacy and data protection with absolute seriousness. This Privacy Policy outlines the specific mechanisms through which we handle technical data, our zero-retention client-side architecture, third-party advertising disclosures including Google AdSense, analytical tracking frameworks, and your individual statutory rights under global data privacy regimes including GDPR, UK-GDPR, and CCPA/CPRA.
1. Client-Side Processing & Zero-Retention Data Policy
The fundamental architecture of MCP-Bridge is engineered around local execution:
- OpenAPI & JSON Specifications: All parsing, schema analysis, and Model Context Protocol (MCP) server configuration generation takes place entirely within your client web browser via JavaScript/WebAssembly.
- Zero Server Transmission: API tokens, schemas, endpoint URLs, and custom environment variables you enter into our converter, sandbox, or config generators are never transmitted to, inspected by, or stored upon our backend web servers.
- Local Storage: Temporary session parameters or user interface preferences (such as code snippet selections or cookie consent choices) are stored strictly within your browser's local storage (
localStorage) and can be cleared by you at any time.
2. Third-Party Advertising & Google AdSense Compliance
We partner with third-party advertising networks, primarily Google AdSense and Carbon Ads, to subsidize the operational and edge bandwidth costs of hosting free open-source tools for the global developer ecosystem.
Please review the following mandatory disclosures regarding Google's advertising practices:
- Third-Party Vendor Cookies:Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites on the Internet.
- Google DART & Advertising Cookies:Google's use of advertising cookies enables it and its partners to serve targeted, personalized advertisements to users based on their navigation history across MCP-Bridge and other destinations across the web.
- Personalized Advertising Opt-Out: Users may opt out of personalized advertising at any time by visiting Google's Google Ads Settings. Alternatively, you may opt out of third-party vendor use of cookies for personalized advertising by visiting www.aboutads.info or the European Interactive Digital Advertising Alliance (EDAA) opt-out portal at www.youronlinechoices.eu.
- Restricted Ad Delivery: On MCP-Bridge, advertising scripts are restricted exclusively to approved editorial and educational guides. Interactive configuration tools, checkout flows, and raw JSON endpoints are protected from intrusive or disruptive ad placements.
3. Google Consent Mode v2 & Cookie Consent Framework
To ensure compliance with the European Union ePrivacy Directive and General Data Protection Regulation (GDPR), MCP-Bridge implements Google Consent Mode v2 across all pages:
- Default Denied State: Upon initial page load, all ad storage (
ad_storage), analytics storage (analytics_storage), user data tracking (ad_user_data), and personalization signals (ad_personalization) are explicitly denied until you take affirmative action via our cookie consent banner. - Explicit Opt-In:Non-essential tracking cookies and marketing identifiers are only initialized after you select “Accept” in the consent interface.
- Revocation of Consent: You can reset your consent decision at any time by clearing your browser cookies for the
mcpbridge.orgdomain.
4. Analytics & Performance Telemetry
We utilize privacy-respecting telemetry providers to monitor network latency, identify broken API specs, and maintain high-uptime edge availability:
- Google Analytics 4 (GA4): Collects anonymized, aggregated traffic data (e.g. general geographic region, browser engine, operating system, and feature utilization events). IP anonymization is enforced by default.
- Cloudflare Web Analytics: Gathers non-invasive, cookie-less performance metrics regarding page render speeds, DNS lookup duration, and CDN edge cache hit ratios.
5. Commercial Transactions & Merchant of Record Disclosures
When purchasing premium asset packs, directory listing sponsorships, or enterprise configuration bundles, transactions are processed directly by our Merchant of Record, Paddle.com Market Ltd.
Paddle is responsible for all payment capture, international VAT/sales tax calculation, and financial data encryption. MCP-Bridge does not process, receive, or store your credit card numbers, bank account credentials, or billing billing addresses. We only receive confirmation of the order ID, purchased product SKU, and associated email address for digital license fulfillment.
6. User Rights Under GDPR, UK-GDPR & CCPA/CPRA
Depending on your location, you possess statutory rights regarding personal data:
- Right to Access & Portability: You may request a summary of any transactional data associated with your email address.
- Right to Erasure (“Right to be Forgotten”): You may request deletion of your order records or newsletter contact details.
- Right to Restrict or Object to Processing: You have the right to prohibit non-essential profiling or advertising cookies.
- Non-Discrimination: We will never deny services, charge different prices, or degrade tool functionality if you exercise your privacy rights.
7. Data Protection Officer & Contact Information
If you have any questions, inquiries, or formal data protection requests regarding this Privacy Policy, please contact our privacy and legal compliance team:
MCP-Bridge Compliance Office
Email: privacy@mcpbridge.org
General Support: hello@mcpbridge.org
Website: https://mcpbridge.org