Privacy Policy / GrowByData MCP Privacy Policy
GrowByData MCP Privacy Policy
Additional privacy terms that apply specifically to your use of the GrowByData Compass MCP Connector to connect a third-party AI assistant to your Compass data. These terms supplement, and do not replace, the general GrowByData Privacy Policy available at growbydata.com/privacy-policy.
Effective 16 September 2026 · Last updated 16 September 2026
What this document does — and doesn't — cover
This policy covers only what's specific to how personal and account data is handled when the MCP Connector is used. Read it alongside the MCP Connector Terms, which govern your use of the connector itself.
It does not establish terms for account eligibility, fees, data ownership and export, or general liability — those are governed by the Master Service Agreement (MSA), your Statement of Work (SOW), and the MCP Connector Terms. Where anything here conflicts with those documents, they control.
1.Purpose and scope
This addendum applies when you authorize a third-party AI assistant — such as Claude, ChatGPT, or Microsoft Copilot Studio — to query your Compass data through the GrowByData Model Context Protocol server (the "MCP Connector"). It describes what data we collect, use, and share as a result of that connection, and the choices available to you.
For our general data practices outside the MCP Connector, see the GrowByData Privacy Policy.
2.Information we collect
Account & authentication data
- Your Compass account and tenant identifiers
- OAuth tokens and refresh tokens issued when you authorize the connection, and a record of the consent decision itself (what you were shown, when, and from what IP address)
- The identity of the AI assistant platform you connected and the scopes you granted it
Tool inputs
The parameters your assistant sends when it calls a Compass tool on your behalf — for example, domains, keywords, competitor names, brand terms, date ranges, or account references drawn from your prompt.
Tool outputs
The data Compass returns in response, such as organic ranking positions, share-of-voice figures, SERP feature ownership, keyword and competitor gap data, ad copy, and AI-search presence data. This is business and market data tied to your tracked Accounts; it isn't intended to include personal information about identifiable individuals.
Connector usage & technical logs
- Which tools were called and when
- Session and request metadata (request identifiers, response times, error codes)
- The originating IP address of the request, where made available to us by the connecting platform
3.How we use it
- To authenticate your connector session and confirm you're authorized to access the requested Account
- To execute the specific query a tool call requests and return the corresponding data
- To maintain connector logs for troubleshooting, reliability, and abuse prevention
- To monitor and improve the performance and accuracy of the MCP Connector and its tools
- To support your account, including billing tied to connector usage tiers
- We do not use this data to build advertising profiles or sell it
4.Who we share it with
- Cloud hosting & infrastructure providers — host the MCP Connector and the underlying data it queries against.
- Our identity provider — manages OAuth authentication and token issuance for connector sessions.
- The AI assistant platform you connect (e.g., Anthropic/Claude, OpenAI/ChatGPT, Microsoft Copilot Studio) — acts as the conduit for your request: it necessarily transmits your prompt-derived tool inputs to us and relays our tool outputs back to you as part of normal MCP operation. Each platform's own privacy policy governs its handling of that data on its side; it's a third-party service we don't control.
- Service providers under contract — limited technical support and infrastructure providers bound to confidentiality and use restrictions consistent with this addendum.
5.Retention
- OAuth tokens: retained until you disconnect the integration or the session is revoked, whichever comes first.
- Consent records: retained while the grant is live and for a reasonable period afterward, for audit purposes.
- Tool-call logs (inputs, outputs, request metadata): retained for 90 days for support, reliability, and security purposes, then deleted or anonymized.
- Underlying tracked SERP/ranking data in Compass: retained per your Account's standard Compass data-retention settings, independent of connector access.
6.Your choices
- Disconnect at any time. Revoke the connector from your Compass account settings or from your AI assistant's connected-apps settings. Revocation invalidates the associated refresh token immediately.
- Request your connector logs. Contact us at clientsuccess@growbydata.com for a copy of your tool-call history. Certain records are retained for the periods described above regardless of this request, for security, support, and legal purposes.
- Manage scopes. Where your assistant platform supports granular permissions, you can limit which Compass tools it's authorized to call.
7.Security
Connector sessions are authenticated via OAuth 2.0, and tool traffic is encrypted in transit. Access to tool-call logs is limited to personnel who need it for support and platform operations. As with our main Privacy Policy, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8.Children
The MCP Connector is a business tool and is not directed to, and may not be used by, anyone under 13 years of age, consistent with the main Privacy Policy.
9.Changes to this addendum
We may update this addendum. The "Last updated" date above reflects the current version. For material changes affecting how connector data is collected, used, or shared, we'll give notice — in the application, by email, or by asking you to re-consent the next time you authorize a connection — before they take effect.
10.Contact
Postal address — GrowByData, 4 Militia Drive, Suite 27, Lexington, MA 02421, USA
For anything not covered here — accounts, fees, data ownership and export, intellectual property, general liability — refer to the MSA and your SOW, the MCP Connector Terms, or contact Client Success.