Privacy Policy
Last updated: May 2026 · GDPR compliant · Version française
OneMCP is a technical tool for developers. We collect the strict minimum. No personal data is sold or shared for commercial purposes.
1. Data we collect
Local mode (stdio, npx): No data is collected. The MCP server runs entirely on your machine.
Hosted mode (api.onemcp.fr):
- API key: anonymous technical identifier used to authenticate your requests
- Request logs: tool called, timestamp, duration, HTTP status — no parameter contents
- Usage counters: number of calls per key, for billing and rate limiting
- Email address: only if you create a paid account via Stripe
2. Aggregated third-party data
OneMCP returns public data sourced from official registries (INSEE, INPI, BODACC…). This data sometimes includes information about individuals (company officers).
In compliance with GDPR:
- Officers' dates of birth are truncated to
YYYY-MM(month/year only) - The provenance of each data point is included in responses
- This data is public data from official registries (legal basis: legitimate interest / legal obligation)
3. Cookies and tracking
The onemcp.fr website uses Google Tag Manager and Google Analytics 4, only after consent. Measured events are used to track product usage, CTAs, and conversions. No third-party advertising cookie is activated without consent.
Cloudflare Pages may collect aggregated access metrics (no cookies) for service availability.
4. Data retention
- API logs: rolling 30 days
- Usage counters: duration of subscription + 1 year
- Stripe email: per Stripe's policy (legal billing data)
5. Your rights (GDPR)
You have the right to access, rectify, delete, and port your personal data. To exercise these rights: contact@onemcp.fr
Response time: 30 days maximum.
6. Security
API keys are stored hashed in Cloudflare KV. Communications are encrypted with TLS 1.3. No sensitive data is logged.
7. DPO contact
For any question regarding data protection: contact@onemcp.fr