MCP for Zotero

Privacy

Last updated 1 August 2026

This page says what this service keeps, what it does not, and how to remove it. It is short because the answer is short.

What is stored

  • Your Google account details — name, email address and profile picture — so you can sign in without a new password.
  • Your Zotero API key, encrypted before it is written to disk. It is used only to make requests to Zotero on your behalf.
  • MCP tokens, kept only as one-way hashes. We cannot read a token back; a lost one is replaced, never recovered.
  • Which AI clients you authorised, so you can see and revoke them.
  • One record per tool call: which tool ran, whether it succeeded, how long it took and when. Not the arguments — not what you searched for, not what you added.
  • Any message you send us through the dashboard, and our reply.

What is never stored

Your library content. No items, no notes, no PDFs, no attachments, no tags. Every operation goes straight to Zotero and the result goes straight back to your assistant, without being kept here.

Who else is involved

Google, which handles sign-in, and Zotero, whose API holds your library. Nothing is sold, and there is no advertising or third-party analytics on this site.

Your controls

  • Revoke the Zotero API key at any time from your Zotero settings. This service loses access immediately.
  • Revoke any MCP token, or any authorised client, from your dashboard.
  • Delete your account from the dashboard. That removes everything listed above, permanently and at once.

Questions

Write through the Messages panel in your dashboard. Every message gets an answer.