webmcp-tool

Legal

Privacy notice

Information under Articles 13 and 14 GDPR. The German version is the authoritative one; this is a translation for readers of the English site.

This site measures whether AI agents can read, understand and operate a website. The check itself needs no account and no data about you — only the address of the site to be checked. Personal data arises at three points: when you load a page, when you have the full report emailed to you, and when you write to us. Each is described separately below.

Hosting and server logs

The site runs on our own server rather than on a website builder or platform. The infrastructure is provided by NexoSystems IT-Solutions, Willy-Brandt-Straße 14, 52382 Niederzier, Germany, under a data processing agreement per Art. 28 GDPR.

Every request writes an entry to a log file: IP address, timestamp, requested address, HTTP status code, bytes transferred, referring page and user agent. This is technically necessary to serve the site, find faults and defend against abuse. It is not combined with other data and not used to recognise you.

Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in secure, reliable operation. Retention: 14 days, after which the logs are deleted automatically.

The check

When you submit an address, our server fetches that site and evaluates what it finds. We process the address you entered and the content of the site checked. The result is held in memory for up to one hour, so that checking the same address again does not trigger another full fetch. After that it expires. The result is not linked to you.

We also keep the technical outcome permanently — host name, time, score, and whether each individual check passed. That builds a record of how publicly reachable websites change with respect to AI agents. Who submitted the address is not stored: no IP, no identifier, no link to your request. What is kept is only what any visitor to the same public website could have seen. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is developing and checking the rule set. Retention: indefinite — the value of such a record is precisely its length.

What this means for the addresses you submit

A report is reachable at /r/<address>. Anyone who knows the host name can open the summary — the host name is enough, no link from us is needed. Do not submit addresses whose mere existence is confidential. This area is disallowed for search engines in robots.txt.

Some of what a report says cannot be settled by a rule. Whether an llms.txtwould really let an agent pick a page, or whether the text that arrives without JavaScript is the site's substance rather than its cookie notice, is a judgement rather than a measurement. For those questions we send excerpts of the publicly available content of the site being checked to TypeSafe AI, Inc. for automated assessment: the title, the meta description, the headings, the llms.txt, the names of any registered tools, and up to four thousand characters of the page text. Nothing about you goes with it — not the address you entered, not your IP address, not any identifier. TypeSafe states that input is not used to train models. Legal basis: Art. 6 (1) (f) GDPR; our legitimate interest is a check whose findings are useful rather than merely formal.

Legal basis: Art. 6 (1) (b) GDPR — running the check is the service you asked for.

The full report by email

The summary of the result is visible without giving us anything. For the full report — every check with its evidence — you provide an email address. With that we process:

  • Your email address, to send you the report and the durable link to it.
  • The result for the site checked (score, grade, both axes, the most important outstanding fix and the address) — stored alongside your address at our email provider, so that we know what a follow-up question is about.
  • The domain part of your email address with a daily counter, to enforce the limit of five reports per company per day. Only the part after the @ and a number are stored, in one file per day. Older daily files are never read again.

Legal basis: Art. 6 (1) (b) GDPR. You expressly request the report; the email is the service requested, not advertising. For the daily limit we additionally rely on Art. 6 (1) (f) GDPR (protection against abuse). Retention: the contact remains stored at our email provider until you object; the unlock link is valid for 90 days. An informal message to hi@webmcp-tool.com is enough to have it deleted, as is a reply to the report email.

After you give us an address we set one cookie, named wmt_unlock, so that the report stays open on later visits without entering the address again. It holds your email address in encoded form, an expiry, and a signature that prevents anyone from minting an unlock for someone else’s address. It is set HttpOnly and Secure and is therefore not readable by JavaScript. It expires after 90 days and can be deleted in your browser at any time.

We set no advertising, tracking or profiling cookies. Because the cookie above is strictly necessary for a function you explicitly requested, no consent is required under § 25 (2) no. 2 TDDDG — which is why there is no cookie banner here. Legal basis for the processing: Art. 6 (1) (b) GDPR.

Contact form and email

Through the contact form you submit a name, an email address, optionally the site in question, the type of enquiry and your message. These are not stored in a database; they are delivered directly to our inbox as an email, and you receive a confirmation at the address given. The message then remains in our inbox for as long as it is needed to handle the enquiry and any follow-up, and is deleted afterwards unless retention obligations apply.

Legal basis: Art. 6 (1) (b) GDPR for enquiries about possible work, otherwise Art. 6 (1) (f) GDPR (answering enquiries).

Recipients and processors

We do not pass your data to third parties for advertising and we do not sell it. Only the following providers are involved, each under a data processing agreement per Art. 28 GDPR:

RecipientFor whatLocated in
NexoSystems IT-SolutionsServer infrastructure, serving the siteNiederzier, Germany
Brevo GmbH
Köpenicker Str. 126, 10179 Berlin — subsidiary of Sendinblue SAS, Paris
Sending report and confirmation emails, storing the contactBerlin, Germany
TypeSafe AI, Inc.Automated assessment of publicly available content of the site being checkedUnited States

Transfers to third countries: one. NexoSystems and Brevo process within the European Union. TypeSafe processes in the United States; that transfer rests on the Standard Contractual Clauses under Art. 46 (2) (c) GDPR, which the agreement with TypeSafe incorporates, and it carries no data about you, only public content of the site being checked. The fonts used on this site are also served from our own server rather than fetched from an external provider — so loading a page transmits your IP address to no third party.

Analytics without cookies

To see which content gets read we use Plausible Analytics in an installation we run ourselves at analytics.polymarkt.de. The measurement works without cookies and creates no cross-device recognition. No full IP addresses are stored; to distinguish visits, Plausible derives a hash from IP address, user agent and domain using a key that rotates daily, so that after 24 hours at most, even we cannot attribute a visit. No personal profiles are created and the data is not shared.

Legal basis: Art. 6 (1) (f) GDPR — a legitimate interest in data-minimising analysis of usage. No consent is required because nothing is accessed on your device within the meaning of § 25 TDDDG.

Agent Tracking on customers' sites

Site owners can place our script agent.js on their own pages. For their visitors we then record, on their behalf: the page path without query string, whether the visit came from or was made by an AI assistant (matched from the referrer and the user agent against a published list), and for WebMCP tools the tool name, duration, success or failure, the error class and the names of the input keys, never their values. Each record carries a session id computed from a random daily salt, the site, a coarse browser class and the network address, hashed; the address itself is not stored, no cookie is set and nothing is written to the device. Raw records are deleted after 90 days; daily totals remain. The site owner is the controller for these records and we process them on their instruction; we do not use them for our own purposes and do not pass them to anyone else. The data stays on our server in Germany. The data processing agreement sets this out formally.

Use of our agent tools

This site carries our own agent.js snippet on every page, the same one customers install, so it measures itself. It records what the section on Agent Tracking below describes, with us as the controller: the page path, whether a visit came from or was made by an AI assistant, and WebMCP tool calls with the names of their input keys. No cookie, nothing on your device, the network address only inside a hash that changes daily. For this site we also count agent fetches from our web server's access log (see Hosting and server logs above); from a log line only the day, the agent name and the page path are kept. Legal basis is Art. 6 (1) (f) GDPR, our interest in knowing whether agents use the site we build for them.

This site offers tools that an AI agent can call — in the page via WebMCP, and over our MCP endpoint at /api/mcp. To see which of them are actually used we record, for each call: the time, the tool name, how long it took, whether it succeeded, and the names and types of the arguments — never their values. For calls over the MCP endpoint we also store the user agent and the MCP protocol headers your client sends, because they are part of the request. Calls over the MCP endpoint are also counted in our own Agent Tracking at agenttracking.co: tool name, time, success and a random identifier, nothing else.

No cookie is set for this and nothing is stored on your device. A random value generated per page view links the calls of one visit; it is not stored anywhere else and is gone when the page is reloaded. The records are kept for 30 days and then deleted automatically.

The ChatGPT plugin

The same checks are offered as a plugin in ChatGPT and Codex, served from /api/mcp/plugin. It offers four read-only tools: scoring a site, explaining a check, listing the rule set and returning the badge snippet. It never asks for your email address and starts no monitoring.

What we receive: the tool arguments, which is the website address you ask about or a check identifier, and the technical metadata ChatGPT attaches to each call, including an anonymized user identifier assigned by OpenAI (openai/subject) and, where provided, locale information. We do not request or receive your chat history, name, email address or OpenAI account details.

What we do with it: the address is scanned as described in "The check" above, and the result goes back to ChatGPT. The anonymized identifier is turned into a shortened SHA-256 hash and used only to apply rate limits per user; it is held only in server memory, never written to disk, and stops counting after one hour. Each call is logged as described above: tool name, timing, success and argument names, never their values. Each call is also counted in our own Agent Tracking at agenttracking.co with the tool name, the time, whether it succeeded and a random identifier; no address, argument, network address or OpenAI identifier is sent there.

Who receives it: OpenAI processes the result as part of your conversation under the OpenAI Privacy Policy; for that processing OpenAI is responsible. Scanned sites receive the ordinary requests of a single page visit. Our hosting is described under "Hosting and server logs".

Retention and your choices: call records are deleted after 30 days; the rate-limit hash is never stored on disk. Scan results are cached as described for the check. You can disconnect the plugin at any time in ChatGPT settings, and an informal message to hi@webmcp-tool.com is enough for access or deletion requests. Legal basis is Art. 6 (1) (b) GDPR for answering your request and Art. 6 (1) (f) GDPR for abuse protection.

The same log records the steps of our own check funnel: that a check was started, a result page was viewed, a share or copy button was pressed, an address was submitted, and whether the report was unlocked. Guide links to the check carry a short source tag through the URL so we can count which guides led to these steps. Entries carry the checked host, page language, button or guide tag, and nothing about you: no email address, cookie or identifier. Same 30 days, same deletion.

Legal basis: Art. 6 (1) (f) GDPR — a legitimate interest in knowing whether the interfaces we publish are used and whether they work. No consent is required because nothing is accessed on your device within the meaning of § 25 TDDDG.

How results are grouped

We automatically assign a result to one of four groups — whether a site is reachable for agents at all, whether it is readable but not operable, whether the foundations are in place but no agent protocols are set up, or whether both are present. What we send you follows from that. The grouping concerns the site checked, not you as a person, and has no legal effect on you. No automated decision within the meaning of Art. 22 GDPR is taken.

Your rights

You have the following rights in relation to us:

  • Access to whether and which data we process about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
  • Portability in a common format (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR) — here that is the analytics and the server logs
  • Withdrawal of a consent given, with effect for the future (Art. 7 (3) GDPR)

An informal message to hi@webmcp-tool.com is enough for any of these. We answer within the statutory period and ask for no special proof, as long as the request comes from the address concerned.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin.

Whether you have to provide data

You are under no statutory or contractual obligation to provide us with data. Without an email address we cannot send you a report, and without a message we cannot answer an enquiry. The summary of a result is visible in every case without giving us anything.

Changes

We update this notice when the processing described here changes. The version available here is the one that applies. As of 1 October 2026.

Something unclear, or an entry you want removed? An informal message is enough.

Get in touch →