mcphub.travel

Privacy Policy

Last updated: 29 August 2026

Draft — pending legal review. This describes what MCPHub.travel does today; the wording has not been reviewed by a lawyer yet, and the retention period and governing law are still to be confirmed. We will update the date above when it changes.

MCPHub.travel (“MCPHub.travel”, “we”, “us”) operates a directory and routing hub for travel-related MCP (Model Context Protocol) servers. This policy explains what we collect, why, and what choices you have.

1. What we collect

Account information. When you create an account we collect your name, email address, an optional username, and a password (stored as a salted hash, never in plain text).

Requests you send through the hub. When you or your AI assistant makes a request (for example, “find flights from Tel Aviv to Lisbon”), we route that request to the relevant travel MCP server(s) listed in our catalog, and we log which servers were called, whether they answered, and how long they took — so the “last checked” and status information shown in our catalog stays accurate. We do not need to store the substance of your travel search to route it, and we minimize retention of query content to what’s needed for abuse prevention and debugging.

Credentials for gated servers. Some servers (marked “Needs your credentials” in the catalog) require your own account with that provider. Where you supply credentials or an OAuth grant for one of these servers, we pass them through to that provider to make the call on your behalf; we do not use them for any other purpose, and you can revoke that grant at any time from your account settings.

Technical data. Standard web/server logs (IP address, browser type, timestamps) for security and troubleshooting.

2. What we don’t collect

We don’t require payment details to browse or connect servers through the free tier. If a server you connect to requires payment for a booking, that payment happens on the provider’s own site, not ours, and is covered by their privacy policy.

3. How we use it

We do not sell your personal information, and we do not use your travel queries to build advertising profiles.

4. Sharing with third-party servers

Because MCPHub.travel’s entire purpose is connecting you to third-party travel MCP servers (Kiwi, Viator, Peek, and others listed in our catalog), using the service necessarily means the request you make is shared with whichever server(s) are relevant to it. Each provider’s own privacy policy governs what they do with that request once received. We list each server’s vendor and access model in its catalog entry so you know who you’re talking to before you use it.

5. Data retention

We retain account data for as long as your account is active. Routing logs used for catalog accuracy and abuse prevention are kept only for as long as they serve those purposes, then deleted or anonymized. The exact retention period is still being settled and will be stated here before we leave early access. You can request deletion of your account and associated data at any time (see Section 7).

6. Cookies

We use only the cookies necessary to keep you signed in and remember basic preferences (like light/dark theme). We do not currently use third-party advertising or tracking cookies.

7. Your rights

You can access, correct, or delete your account information at any time. To request a full export or deletion of your data, email privacy@mcphub.travel.

8. Children’s privacy

MCPHub.travel is not directed at children under 16, and we do not knowingly collect personal information from them.

9. Changes to this policy

If we make material changes to this policy, we’ll update the date at the top of this page and, where required, notify account holders directly.

10. Contact

Questions about this policy: privacy@mcphub.travel