Privacy
Effective 25 September 2026. Operator: Sun Business Group. Product: WebMCP Eval at www.webmcp-eval.com and https://mcp.webmcp-eval.com/mcp.
This page is the privacy policy for directory and connector review. Terms govern payment and acceptable use.
What we collect
- Wallet. Prepaid balance, last successful debit or reload time, Stripe checkout and payment identifiers needed to fulfill or refund a pack. Keys look like
usr_live_. OAuth access tokens map to that wallet. We do not store card numbers. - An evaluation request. The HTTPS URL you submit to
evaluate_webmcp, plus the page content fetched so we can describe WebMCP surfaces and recommend tools. Failed fetches are not billed as full evaluations. - Account delivery. If an operator sends a one-shot view-key link, we use the email you provided for that delivery. The key is not put in the email body.
- Connector session. Host name of the client that completed OAuth (Claude, ChatGPT, Grok, Cursor, or another MCP host) so the consent page can name that host.
What we do not keep
We do not keep a first-party history of the URLs you evaluate, page titles, page sketches, or intent labels. The evaluation JSON in your agent chat is your copy. The default ledger is wallet-only.
An audit log of evaluated URLs is not on by default. If a buyer later needs one for their own client billing, that will be an explicit opt-in setting.
We do not run first-party analytics, advertising pixels, or session replay on this site.
How an evaluation is processed
To complete evaluate_webmcp we send the submitted URL and fetched page material to:
- Firecrawl — scrape / sketch when the page must be read as a document.
- A hosted inference API in the United States — classify the page and draft recommended tools. We do not train foundation models on your evaluations.
- Our browser worker (when used) — inspect in-page WebMCP tools. It does not execute those tools.
Payment is processed by Stripe. Checkout cookies on Stripe’s pages are Stripe’s.
We use infrastructure hosts to run the MCP and this site. They see connection metadata the way any HTTPS host does. We do not sell personal data.
Retention
- Wallet and Stripe fulfillment records: while the wallet exists and as long as we must keep them for tax, dispute, or abuse review.
- Page content used during an evaluation: processed to produce the result, then discarded from our first-party store. Subprocessors keep their own logs under their policies for a short operational window.
- OAuth tokens: until you disconnect the host or we revoke abuse.
What this product does not do
- It does not execute tools registered on the page you evaluate.
- It does not ask for passwords, cookies, or private URLs. Do not put secrets in the evaluated URL.
- Connect,
tools/list, andget_creditsare not billed. A successfulevaluate_webmcpdebits $2 from the prepaid wallet. Reload checkout is a separate Stripe payment you approve in a browser.
Your requests
Email [email protected] to close a wallet, rotate a key, or ask what we hold for an account_id from get_credits. We can confirm balance and last debit or reload. We cannot replay URL history we do not store.