Esta página ainda não foi traduzida para o português; você está lendo a versão em inglês. Inglês
Docs menu

Where your data lives

Where Delta MCP keeps its files on your computer, what is protected, what never leaves it, the short list of what does, and how to erase it all.

On this page

Delta MCP keeps everything in one folder on your computer: .mcpdelta in your home folder (~/.mcpdelta). Developers can point it elsewhere with the MCPDELTA_HOME variable.

What’s in the folder

  • config.json: Your connectors: how to reach each, its mode, and its original entry in your apps.
  • settings.json: Language, appearance, the folder of shared shortcuts.
  • money.json: Your payments switch and your payment marks.
  • journal.jsonl: One line per read, change, refusal or switch, each chained to the one before: a removed or edited line shows.
  • tasks/: One file per task in Activity: its program, each change before and after, how to put it back.
  • deltas/: What was applied, and what Undo puts back, including an object as it was just before a change.
  • recipes/: Your shortcuts.
  • programs/: The programs your AI ran, by conversation, to keep a task as a shortcut. Removed after 60 days.
  • backups/: A dated copy of each settings file Delta MCP edited in your AI apps.
  • cache/: The tools last seen on each connector, and the shape of what its reads return, never values.
  • auth/: Your sign-ins, and a log of sign-in events without any token.
  • ledger.jsonl: Counts and sizes behind “tokens saved”. No content.
  • logs/gate.log: One line per event in a conversation, such as a restarted server. Starts again past 1 MB.

Small files hold the rest: trusted shortcuts, cards waiting, updates, renames. Tasks and the journal are never removed on their own.

Outside the folder, Delta MCP edits your AI apps’ settings files and writes the shortcuts you share (Documents/Delta, or the folder you pick in Settings). Adding a guide for your AI to its apps, the skill: not yet.

What’s protected

  • Only your user account can read the folder: permissions 700, and 600 on its files, on macOS and Linux.
  • A file is written whole, then renamed: never half-written. One writer at a time changes config.json.
  • A secret is hidden wherever Delta MCP shows or exports something: the journal, Activity, the card, the app. That covers fields named like a secret, environment values and password fields, even when your AI keeps the value in a variable.
  • Not yet: a connector call that names this folder asking you first. An AI with a shell of its own can reach any file you can.

The folder holds what your connectors and Undo need, including API keys and sign-in tokens. They are not in the system keychain yet. Don’t share the folder, and don’t commit it.

What never leaves your computer

Your conversations. Your servers’ data: tickets, pages, files and results go from your servers to your AI, never to us. Your keys and passwords. Your history: Activity, the journal and your shortcuts.

What leaves

In this version, Delta MCP sends nothing of its own. It talks to the servers you connect, to a service when you sign in to it, and to your own npm when mcpdelta refresh checks an npm connector.

Security and privacy lists what will leave. None of it is in this version yet:

  • One anonymous number a day, unless you turn it off. Your tokens saved that day, rounded down to the nearest thousand, with the method’s name and a random id. No names, tasks, results or app version. Asked once at first launch, off in Settings in one click. Not yet: the question, the setting and the sending.
  • A check for new versions. Every 6 hours, Delta MCP will ask GitHub whether one exists, sending nothing about you. Not yet.
  • Your email, if you make an account. The account will be optional. Not yet.
  • A card payment, if you support Delta MCP. Stripe will handle it in your browser. Not yet.

This website

mcpdelta.com sets no cookie. When you open the “coming soon” window, it counts the click by button. It also uses a one-day fingerprint, a keyed hash of your IP address and browser that changes every day and is never stored in readable form, only to estimate how many different people opened it that day. That count records nothing else, and sends nothing if your browser says Do Not Track or Global Privacy Control.

If you leave your email in that window or on the Download page, the site keeps it with the language of the page, the button you used and the date, to write to you once when Delta MCP is out. No newsletter, no sharing. Ask and it is deleted.

The only thing the site keeps in your browser is a small note that you closed its privacy notice. Like any website, the host that serves the pages sees each request. The privacy policy has the full list.

Erase everything

  1. Put everything back, so your AI apps stop depending on Delta MCP.
  2. Optional: in Settings, Export everything saves your history as a file without secrets.
  3. Quit Delta MCP, then move the .mcpdelta folder to the Trash. That removes tasks, journal, shortcuts, sign-ins and dated copies.
  4. If you shared shortcuts, delete Documents/Delta too.

Each service you signed in to also holds a registration named mcpdelta. Deleting the folder doesn’t remove it: use the service’s own settings.

Something missing or wrong? Open an issue

Coming soon

Delta MCP is almost here

The free app for Mac, Windows and Linux lands soon. Leave your email and you’ll hear the moment it’s out. No account needed.

We use your email only to tell you once when Delta MCP is out. No newsletter. Privacy policy