MCPatch is run by Abhijay Gupta, an individual in India ("we", "us"). This page lists what the site collects, why, where it goes and how long it stays. Questions go to superwired.hq@gmail.com.
The short version
- We don't sell your data, and we don't use it for ads.
- There are no accounts and no cookies of our own.
- Every check is saved as a report page that anyone with its link can open.
- A token you add to a check is used for that one check and never saved.
- No AI model sees your data. Fix prompts are built in your browser from a template.
1. Connector checks
When you paste a connector URL, our server connects to it over the public internet, the way Claude would. It:
- looks up the hostname in DNS and opens an HTTPS connection to read the certificate
- sends MCP requests:
initialize(once for each published protocol version),notifications/initializedandtools/list - fetches the OAuth discovery documents your server points to
- if your authorization server offers dynamic client registration, registers a test client named "MCPatch check" with claude.ai's callback URL
- opens your sign-in page once, and sends your token endpoint one deliberately fake code to see how it refuses it
These requests carry the user agent MCPatch/0.1. Our server refuses to connect to private or internal network addresses.
What we save: the URL, the time, the result of each step, and short evidence such as status codes, some response headers, short pieces of response bodies and certificate details. If your server lists its tools, we also save a snapshot of them (tool names, parameter names and types, which parameters are required, and the first 160 characters of each description) and short quotes of any text in tool descriptions that our hidden instructions scan flags. We keep this to show your report and to tell you what changed in your tools on your next check.
Tokens and headers: if you add a token or a custom header, it is sent to your server during that check only. We don't save it and it doesn't appear in the report. A short-lived test token is the safest choice. The URL itself is saved, so don't put secrets in it.
2. Report links
Each report gets a random link, like /r/… for connector checks and /v/… for install checks. Anyone who has the link can open the report. We don't list reports anywhere on the site or in our sitemap, but treat the link as shareable and only share it with people you trust.
3. Your IP address and the free limit
Connector checks are free up to 3 a day per visitor. To count them, we combine your IP address with a secret value, hash it with SHA-256, and save the result with each connector check. We don't save your plain IP address in our database. The hash is used for two things only: counting your checks, and finding your previous check of the same connector so we can show tool changes.
To stop bursts of requests, our server also keeps your plain IP address in memory for up to 10 minutes. It is not written to the database. Install checks are not saved with your IP hash and don't count toward the free limit.
4. Install checks
When you paste a link on the install check page, our server downloads what it points to:
- GitHub links: the repository archive from
codeload.github.com - npm packages and
npxcommands: package details and the package file fromregistry.npmjs.org - any other https link: that file, from that address
The files are scanned in memory and not kept. We save the report: the link you pasted, the package or repository name, and the findings, which can include file paths, line numbers and short quotes from the files. Only paste links to public code you are comfortable having quoted in a shareable report.
5. Paid plan requests
Payments are not open yet. If you say "Yes, I want it" to a plan, we save your name, email, the plan, the connector URL if you gave one, and the time. Our server emails these details to the owner through Resend. We use them to reply to you about the plan and to tell you when payments open. You are not charged.
Once a paid plan is active, we check your connector every day, save each result as a report, and email you through Resend when the result changes.
When payments open, they will go through a hosted checkout page run by a payment provider. Your card details go to that provider, never to our server. We will name the provider on this page before we take any payment.
6. What stays in your browser
We set no cookies of our own. The site uses your browser's storage for a few small things:
- Local storage: the times of your recent connector checks (to show the free limit), the last report id for each connector you checked (to compare tools), and which AI tool you picked for the fix prompt.
- Session storage: the report you just ran, so it opens instantly. It clears when you close the tab.
You can clear these at any time in your browser settings. The fix prompt and the support report are built in your browser.
7. Services we use
- Vercel hosts the site and runs our server. Like any host, it processes your IP address and request details to serve pages.
- Vercel Web Analytics counts page views without cookies.
- Neon hosts the Postgres database that stores reports and plan requests.
- Resend sends our emails.
- Google Fonts serves the site's fonts, so your browser sends Google your IP address when it loads them.
- GitHub and npm are contacted by our server, not your browser, when you run an install check.
These providers run servers outside India, including in the United States, so your data may be processed there.
8. Sharing and selling
We don't sell or rent your data. We share it only with the services above so MCPatch can run, or when the law requires it.
9. How long we keep it
Reports and plan requests are kept until you ask us to delete them. We may delete old reports at any time. The in-memory IP list clears within 10 minutes.
10. Your choices
Email superwired.hq@gmail.com to see, correct or delete what we hold about you. To delete a report, send us its link. We will act on your request within 30 days.
11. Children
MCPatch is not for anyone under 13. If we learn we hold data from someone under 13, we will delete it.
12. Security
The site runs over HTTPS and the database is not public. No system is perfectly secure, so please don't send us anything you can't afford to have exposed.
13. Changes
If this policy changes, we will update this page and the date at the top. If a change matters for a paid plan, we will also email you.
14. Contact
Abhijay Gupta, India. Email superwired.hq@gmail.com.