MCPatrol — Privacy Policy

Effective 28 July 2026 · applies to the MCPatrol Android app (package com.detentpoint.mcpatrol) and the web console at app.mcpatrol.com

MCPatrol monitors MCP (Model Context Protocol) servers you choose to add. This page describes exactly what data the app handles, where it lives, and how to delete it.

Two modes, two data locations

What we store in cloud mode

The web console, and the one cookie it sets

app.mcpatrol.com is a browser view of the same account and the same data described above. It reads and writes nothing else: signing in there shows you the estate your app already shows you. Using it is optional — the app works exactly the same whether you ever open it or not.

Both are strictly necessary to keep you signed in, so no consent banner is shown for them. There are no advertising, analytics or tracking cookies on the console, and none on this website either.

What we don't do

Security

All traffic between the app, the bridge, the web console and the backend uses TLS. Backend access requires your per-account API key — held in the Android Keystore on your phone, and in an HttpOnly cookie your browser will not hand to a script. Passwords are stored only as salted PBKDF2 hashes.

Delete your account and data

You can delete your account and all associated data directly in the app, without contacting anyone:

  1. Open MCPatrol and go to the Manage tab.
  2. In the account card, tap Delete account.
  3. Confirm with Delete everything.

Deletion is immediate and complete: your account, servers, probe history, incidents, inventory records, traffic records, captured payloads, bridge registrations, and push tokens are all removed from our database. Nothing is retained after deletion — there is no backup-restore of deleted accounts. Your API key and login stop working the moment deletion completes.

If you can no longer access the app, email us from your account email address and we will run the same deletion for you.

Delete some of your data, without deleting your account

You do not have to choose between keeping the account and removing something in it. Each of these is self-serve, takes effect immediately on our servers, and needs no request to us:

The same actions are available in the web console at app.mcpatrol.com. If you would rather we did any of it for you, email [email protected] from your account address.

To remove everything at once instead, see Delete your account and data.

Data retention

Cloud data is retained while your account exists and is deleted when you delete your account. Local-mode data lives only on your device and is removed when you clear the app's data or uninstall it.

Your rights (GDPR / CCPA and similar laws)

Depending on where you live, you have legal rights over your personal data. We honor them for everyone, wherever you are:

Legal bases for processing (GDPR art. 6): performance of the service you signed up for (account, monitoring data, push tokens) and legitimate interest in keeping the service secure (server-side logs). Data controller: Detent Point, LLC (United States), reachable at the address below. No automated decision-making, no profiling.

Changes and contact

If this policy changes, the effective date above will be updated. Questions and deletion requests: [email protected].