Privacy policy
Last updated 2026-09-28
protogrid is a public registry of MCP servers: the portal at protogrid.dev, the REST API and MCP server at api.protogrid.dev and the documentation at docs.protogrid.dev. This policy says what personal data those services handle, why, who else sees it and for how long. We collect as little as the service needs, sell nothing and run no advertising or analytics trackers.
Who is responsible
The controller of your data is Pedro Ibáñez Requena, tax id (NIF) 21679583J, Calle Jerez 254, Serra, Valencia, Spain. Contact: [email protected]. Write to that address for anything in this policy.
Using protogrid without an account
Searching, reading server pages, calling the API or our MCP server and checking a server URL need no account. For that we handle:
- The request log of our edge: time, your IP address as Cloudflare reports it, the host and address requested (search queries are part of the address), status, size, timing, cache result and your browser's or client's user agent, kept 30 days to keep the service secure and working. After each day the lines are copied without the IP address (replaced by a code that cannot be traced back to it or linked across days) and kept up to 400 days to count the service's use.
- Searches: the query text, the filters, the number of results, the client's user agent and a hash of your IP address with a salt that changes every day and is never stored, so searches cannot be linked across days or back to an address. Kept 90 days, to improve search.
- Rate limits: your IP address held in memory for about a minute to count requests. On-demand checks count per hour against a keyed hash of your address (IPv6 by its /64), kept 2 days.
- On-demand checks: the URL you asked us to check and the result of our probe, kept 30 days under a random link. We do not record who asked for a check.
The legal basis is our legitimate interest in running a secure, working and useful public service (GDPR art. 6(1)(f)).
Accounts (sign in with GitHub)
A free account gives an API key and, for server owners, claims, monitoring and alerts. When you sign in with GitHub we receive and keep:
- Your GitHub user id, login, public name, avatar address and primary verified email address. The GitHub access token is used once during sign-in and never stored.
- A session cookie (
pg_session, 30 days, renewed while you use it) and, during sign-in only, a state cookie (pg_oauth_state, 10 minutes). These are strictly necessary cookies; there are no others. - Your API keys, stored only as a hash, with the date each was last used, and the number of requests per key, operation and day, kept up to 10 years for usage reports and a future paid plan.
- If you ask to see restricted listings (adult content, gambling): the categories granted, when, by whom and a short note of the review, kept while your account exists; your request email stays in our mailbox ([email protected]) as long as needed to handle it.
- If you own MCP servers: the namespaces and domains you prove, the DNS check results, your claims and monitoring choices, your webhook endpoints (their signing secrets encrypted) with 90 days of delivery attempts, and the alert emails sent to you, kept up to 10 years.
Your profile, proofs, claims and webhook endpoints are kept while your account exists and deleted when it is closed. The legal basis is the contract to provide the account you ask for (GDPR art. 6(1)(b)). Server pages show that an owner is verified, by which method and since when, never which account.
Your controls
- Use protogrid without an account: searching, reading, the API, our MCP server and the check never need one.
- Sign out at any time, which ends the session; revoke an API key on your account page, which stops it at once.
- Switch alert emails off in My servers, or use the one-click unsubscribe link in any alert email.
- Release a claim, stop monitoring a server, remove a domain proof or delete a webhook endpoint in My servers.
- Ask for a copy of your data, a correction, or the deletion of your account and the data tied to it, by writing to [email protected].
Emails
Server owners who monitor servers receive alert emails at their GitHub email address. Every email has a one-click unsubscribe link, and alerts can be switched off in My servers. We send no marketing email.
Who else processes data
- OVH (OVH Hosting, Inc.) hosts our servers and database in Canada, a country the European Commission recognizes as providing adequate protection.
- Cloudflare, Inc. carries every request to our sites as a proxy and network provider; it processes your IP address and the request under the EU-US Data Privacy Framework and standard contractual clauses.
- Resend sends alert emails from its EU region.
- GitHub processes your sign-in under its own privacy statement; we only receive the profile data listed above.
We do not sell or share personal data with anyone else, except where the law requires it.
Our MCP server and AI assistants
When an AI assistant such as ChatGPT or Claude calls our MCP server, we receive the tool arguments it sends (a search query, a server name, a URL to check) together with the request data described above. We never ask for conversation history, location or credentials, and we never pass anything to the MCP servers listed in the registry: our probes are ours alone and carry no user data.
Backups and security
The database is copied every night and each copy kept 7 days; the operator also keeps copies on their own computer in Spain for disaster recovery. Access is limited to the operator, connections are encrypted, and API keys and session tokens are stored only as hashes.
Your rights
You can ask for access to, correction or deletion of your data, restriction of or objection to its processing, and a portable copy, by writing to [email protected]. To close your account and delete the data tied to it, write to the same address from the email of your GitHub account. You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).
Children
protogrid is a developer service and is not directed at children under 14.
Changes
We will update this page when our practices change and note the date below. Last updated 2026-09-28.