Free MCP beta
Privacy
The beta needs no account, email address or payment card. We collect only what is necessary to issue an API key, enforce the free quota and keep the service reliable.
Last updated: 18 August 2026
What we store
When you create a key, the service stores a one-way SHA-256 hash of the key, a short non-secret prefix, its plan and quota, creation and last-used timestamps, total call count, and revocation time if you revoke it. The raw API key is shown once and is not stored by us.
Daily usage records contain the key hash, UTC date and call count. To limit automated key creation, a salted one-way hash of the requesting network address and its daily issue count is kept for up to 48 hours. Standard web-server logs may temporarily contain request metadata such as an IP address, route, status and user agent.
How we use it
We use these records only to authenticate MCP requests, show usage, enforce quotas, prevent abuse, diagnose failures and operate the beta. We do not sell this data or use MCP requests for advertising.
Retention and control
Key and usage records are retained while the beta operates so quotas and abuse can be audited. Revoking a key disables it immediately. Do not put a key in source control; create a replacement and revoke the exposed key if that happens.
External projects
Component pages can link to third-party source repositories, packages and author sites. Those services have their own privacy practices. The offline npm package runs locally and does not need this hosted API.
Contact
Privacy questions can be sent through the contact route on mrkeyoor.com.