Privacy Policy

Effective September 6, 2026

MCP Selection Lab is a metadata-only MCP tool-selection readiness service. This policy describes the hosted service at https://mcp-selection-lab-production.up.railway.app.

What the service processes

What the hosted service does not do

Reports and retention

Successful standard scans create public-by-link reports using unguessable report IDs. A report may contain the submitted public MCP URL, discovered public tool metadata, routing metrics, and candidate description-only routing fixes. Standard reports may be retained until operational cleanup; the service currently does not promise an automatic deletion period.

The /api/holdout endpoint is different: Selection Lab does not write caller-supplied holdout prompts or its receipt into the standard public-report database. The request and response are still processed by the application and hosting infrastructure to serve the request, so callers should not submit secrets or personal data.

Evaluation requests

The optional paid evaluation request form collects the submitter's name, email address, MCP/project name, MCP endpoint or repository URL, public-profile preference, and optional short description. Evaluation request records are stored in production Postgres for manual qualification and follow-up, with an internal status such as NEW or COMPLETED. They are not published as a public lead list. Payment is requested only after qualification is accepted; submitting a request does not guarantee evaluation or publication.

Third-party processing

The hosted service runs on Railway infrastructure. When you request a scan or holdout evaluation, the target public MCP server receives the discovery requests required for initialize and tools/list. The deterministic hosted evaluations do not send target metadata or caller-supplied holdout prompts to a model provider.

Use of information

Processed information is used to operate evaluations, generate and retrieve reports or receipts, measure service reliability and usage, prevent abuse, and improve routing-readiness analysis. We do not sell scan or holdout data to advertisers.

Your choices

Submit only public MCP metadata and non-sensitive test prompts. Standard scan reports are public-by-link; caller-supplied holdout receipts are returned to the caller without being inserted into the standard public-report database.

For questions about an evaluation request or privacy concern, contact contact@agenttrustlab.com. We do not sell evaluation request data or customer data.

Changes

We may update this policy when the service changes. The effective date above identifies the current version.