CORTEX | MCP STATUS OPERATIONAL BUILD 2026.07

Privacy Policy

Effective date: July 25, 2026  ·  Last updated: July 25, 2026

This Privacy Policy explains how Clay Digital Consulting (“CortexMCP”, “we”, “us”) collects, uses, stores, shares, and deletes information in connection with the CortexMCP platform at cortexmcp.io, the dashboard, the Model Context Protocol interface, and the TheSystem WordPress plugin (together, the “Service”). This is a standalone document; our Terms of Service are separate.

Who we are and who this applies to

Clay Digital Consulting, 71 Dowlen Rd, Hixson, TN 37343.

This policy applies to customers (people and organizations with a CortexMCP account), authorized users (individuals invited into a customer’s account as Owner, Member, or Client), and visitors to cortexmcp.io.

Where our customers are the controller. When a customer uses CortexMCP to analyze their own website, their own marketing data, or the websites of their own clients, the customer decides what data enters the Service and why. In that relationship the customer is the data controller and CortexMCP acts as a processor on their instructions. This matters most for our website analytics feature (§4).

Information we collect

Account and identity information

Name, email address, password (stored as a salted hash — we never store or can retrieve your plaintext password), organization name, role, and account preferences. If you sign in with Google, we receive your email address and basic profile information from Google.

Billing information

Subscription tier, billing status, renewal dates, and transaction history. Payment card details are never transmitted to or stored by CortexMCP — payments are processed by our payment processor, which handles card data directly.

Business context you provide

The core of the Service is business memory: information you deliberately enter or upload — business identity, positioning, target audience, offers and pricing, objectives, competitive notes, brand voice and guidelines, customer avatars, and project notes. It may include commercially sensitive information. It is stored under your account and is not shared with other customers.

Connected property data

Where you connect a website, we store site URLs, page content, page structure, internal links, structured data, published and draft content, and — for WordPress connections via TheSystem — the credentials required to publish, stored in encrypted form.

Google user data

Where you connect a Google service, we access and store the data described in §3.

Third-party data about you and your market

To perform research and audits, the Service retrieves publicly available data from third-party providers — search results, keyword metrics, backlink data, competitor page content, and responses from AI assistants. This is data about websites and markets, not about you personally, though it may include content you have published.

Website analytics data collected on your behalf

If you install our first-party analytics script on your website, we collect pageviews, referrers, campaign parameters, device and browser type, approximate geographic location derived from IP address, and page-to-page navigation for your visitors. See §4.

Usage and technical data

Log data, IP address, browser and device information, tool and feature usage, API and MCP call records, credit consumption, error traces, and performance telemetry. We use this to operate the Service, debug failures, prevent abuse, and understand which features are used.

Communications

Support tickets, bug reports, and email correspondence with us.

We do not knowingly collect information from anyone under 18. The Service is a business product and is not directed at children. If we learn we have collected such information, we delete it.

Google user data

CortexMCP requests access to Google services only when you initiate a connection, through Google’s standard OAuth 2.0 consent flow. Nothing is connected by default. Each integration is independent — connecting Calendar does not grant access to Search Console.

Scopes we request, and why

ScopeWhat it grantsWhat we do with itWhat we storeRetention
https://www.googleapis.com/auth/webmasters.readonlyRead-only access to your Google Search Console propertiesList your verified properties so you can match one to a project; retrieve search performance data (query, page, clicks, impressions, click-through rate, average position) to display performance, detect pages competing for the same query, identify content gaps, and measure whether published work improved rankingsYour property list and the retrieved performance rows, associated with your projectWhile the connection is active; performance rows kept for rolling historical comparison; deleted within 30 days of disconnection or account deletion
https://www.googleapis.com/auth/analytics.readonlyRead-only access to your Google Analytics dataRetrieve traffic and engagement metrics so Google Analytics figures can be displayed alongside CortexMCP’s own analytics and attributed to specific content and campaignsAggregated metric rows, associated with your projectSame as above
https://www.googleapis.com/auth/business.manageManage the Google Business Profiles you administerRead your business locations and profile details for local-visibility auditing and competitive comparison; create posts on a Business Profile only when you explicitly compose and publish or schedule one through CortexMCP. We do not alter your business name, address, hours, categories, or reviewsLocation identifiers, business name, category, and the content of posts you created through the ServiceWhile the connection is active; deleted within 30 days of disconnection or account deletion
https://www.googleapis.com/auth/calendar and https://www.googleapis.com/auth/calendar.eventsRead and write your calendar eventsBuild daily briefings and end-of-day reviews, detect scheduling conflicts, compute availability, protect focus time, and attach relevant business context to upcoming meetings. Events are created, updated, or deleted only in response to your explicit instructionA cached copy of upcoming events (title, time, attendees, location, description) to generate briefings without repeatedly re-fetchingCache kept while the connection is active; deleted on disconnection
https://www.googleapis.com/auth/tasksRead and write your Google TasksInclude tasks in briefings and keep Google Tasks synchronized with tasks created in CortexMCP, so one list works in both placesTask title, notes, due date, status, and the mapping between the Google task and the CortexMCP taskWhile the connection is active; deleted on disconnection
https://www.googleapis.com/auth/userinfo.emailYour Google account email addressShow you which Google account is connected, and match your Search Console properties to the correct siteEmail address on the connection recordWhile the connection is active

Where Google offers a narrower alternative for a given function, we request the narrower scope. We request write scopes for Calendar and Tasks because the assistant’s purpose is to create and modify events and tasks on your behalf; read-only scopes would make those features impossible.

What we never do with Google user data

  • We do not sell it, rent it, or trade it.
  • We do not use it for advertising or transfer it to any advertising platform, ad network, or data broker.
  • We do not use it to develop, improve, or train generalized artificial intelligence or machine-learning models, our own or anyone else’s.
  • We do not use it to build profiles for purposes unrelated to the features you connected it for.
  • We do not permit our staff to read it, except in the limited circumstances below.

Human access

Employees and contractors do not access your Google user data except: with your explicit, case-specific consent (for example, when you ask us to investigate a problem with your Search Console connection); where necessary for security purposes, such as investigating suspected abuse or a security incident; to comply with applicable law; or where the data has been aggregated and de-identified such that it no longer identifies you, and is used only for internal operational metrics.

Revoking access

You may revoke CortexMCP’s access to any Google service at any time through your Google account at myaccount.google.com/permissions; our access ends immediately, and the associated cached data is removed on our next scheduled cleanup, within 30 days. Where a disconnect control is available in Settings → Integrations, disconnecting deletes the stored credentials and cached data for that connection, and for Search Console it also revokes our authorization with Google.

Website analytics collected on your behalf

If you install the CortexMCP analytics script on a website you operate, we collect data about your visitors on your instruction. For that data, you are the controller and we are your processor.

  • The script is cookieless. It does not set advertising or cross-site tracking identifiers, and does not follow visitors across other websites.
  • IP addresses are used to derive approximate location (country, region, city) and are not retained in full alongside the pageview record.
  • We do not use your visitors’ data for our own purposes, do not combine it across customers, and do not sell it.
  • You are responsible for having a lawful basis for this collection and for disclosing it in your own website’s privacy notice, including any notice or consent your jurisdiction requires.
  • Visitor data is deleted within 30 days of your account’s deletion or your removal of the site.

How we use information

We use the information described above to:

  1. Provide the Service — run the features you asked for.
  2. Load your business context into the platform’s analysis, planning, and drafting functions.
  3. Generate content, briefs, audits, and recommendations at your direction.
  4. Publish to destinations you have connected, when you instruct us to.
  5. Authenticate you and secure your account.
  6. Bill you and manage your subscription.
  7. Provide support, and diagnose and fix defects.
  8. Monitor performance, prevent abuse, and enforce usage limits.
  9. Communicate with you about the Service — changes, incidents, and, where you have not opted out, product updates.
  10. Comply with legal obligations.

AI processing. The Service uses third-party large language models to generate and evaluate content. Your business context and connected-site content may be transmitted to these providers as part of a request so the output reflects your business. These providers are contractually bound not to use content submitted through their business APIs to train their models. Google user data is not sent to these providers for model training and is not used to train any model. Where an analysis requires Google-derived figures, only the minimum necessary aggregate values are included, never raw credentials.

We do not use your business context, your content, or your Google user data to train our own models, and we do not use one customer’s data to improve outcomes for another customer.

Storage and security

  • Credentials. OAuth access and refresh tokens for connected Google and third-party services are encrypted at rest. WordPress application passwords and third-party API keys are likewise encrypted. Your CortexMCP password is stored only as a salted hash.
  • In transit. All traffic to and from the Service uses TLS.
  • Tenant isolation. Every record is scoped to an account and, within an account, to a project. Isolation is enforced at the database layer through row-level security, not only in application code. An agency’s client projects are isolated from one another.
  • Access control. Roles are Owner, Member, and Client, with permissions appropriate to each. Administrative access by our staff is limited, logged, and used for support and incident response.
  • Logging. Authentication events and significant project activity are logged for security and audit purposes.
  • Hosting. Data is stored on infrastructure located in the United States.

No system is perfectly secure. We cannot guarantee absolute security, but we work to protect your information and will notify you and, where required, the relevant supervisory authority of a breach affecting your personal data without undue delay.

Sub-processors and disclosure

We share information only as described here. We do not sell personal information.

Service providers. We use third parties to operate the Service. Each is bound by contract to process data only on our instructions and to maintain appropriate security. We will notify customers of material changes to the providers we rely on.

Provider(s)PurposeData involvedProcessing location
Hostinger (VPS) — self-managed PostgreSQLCloud hosting and database — running the Service and storing dataAll categoriesUnited States
Together AI, Anthropic, PerplexityAI model providers — content generation, classification, and evaluation (and any provider whose key you supply)Business context, site content, prompt textUnited States
DataForSEOSearch and SEO data — keyword, ranking, backlink, and competitor dataDomains and keywords you researchUnited States
Cloudflare (R2 object storage, CDN)Asset storage and content deliveryUploaded and generated assets; requested pagesUnited States / global edge
SendGridEmail delivery — transactional and notification emailName, email address, message contentUnited States
SamCartPayment processing and subscription billingBilling contact and transaction data; card data handled directly by the processorUnited States
Higgsfield, Hume AIOptional media features — image generation and voice-interview analysisPrompts and content you submit to those featuresUnited States
ip-apiGeolocation lookup — deriving approximate visitor location from IPIP addressUnited States
SentryError and performance monitoring — diagnosing failuresTechnical logs, which may include identifiersUnited States

Other disclosures.

  • At your direction — for example, publishing content to a WordPress site or a Google Business Profile you connected, or sharing a client dashboard through a link you generated.
  • Within your account — other authorized users of your account can see the account’s data according to their role.
  • Legal — where required by law, subpoena, or valid legal process, or to establish or defend legal claims. We will notify you unless legally prohibited.
  • Business transfer — if the business is acquired or merged, information may transfer as part of that transaction. You will be notified, and this policy will continue to apply until replaced by a policy you are given notice of.

Retention

DataRetained
Account and billing recordsFor the life of the account, then as required for tax and legal purposes
Business context and brand libraryFor the life of the account; deleted within 30 days of account deletion
Generated content and auditsFor the life of the account, unless you delete it sooner
Google user dataWhile the connection is active; deleted within 30 days of disconnection or account deletion
Visitor analytics dataWhile the site is registered; deleted within 30 days of removal or account deletion
Logs and telemetryUp to 12 months
BackupsRolling backups retained up to 35 days; deleted data persists in backups until they age out

Your rights and how to exercise them

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined. Residents of the EEA and UK have rights under the GDPR, and may lodge a complaint with their supervisory authority.

Deletion. You can delete most data directly in the dashboard. To delete your entire account and all associated data, email privacy@cortexmcp.io from the address on your account, or use the account deletion option in Settings. We will confirm the request, complete deletion within 30 days, and confirm when it is done. Data in backups is removed as those backups age out, within 35 days. We may retain the minimum records required for legal, tax, or fraud-prevention purposes, and will tell you what those are.

Google data specifically. Disconnecting an integration (§3) deletes the credentials and cached data for that integration without deleting your CortexMCP account.

We respond to rights requests within 30 days. We do not charge for the first request in a 12-month period. We may need to verify your identity before acting.

International transfers

The Service is operated from the United States, and information is processed there. If you access the Service from outside the United States, you are transferring information to a country whose data protection laws may differ from your own. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism with our sub-processors.

Limited Use of Google user data

CortexMCP’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, and without limiting the statement above:

  1. We use Google user data only to provide and improve the user-facing features described in §3 — features that are visible and useful to the person who granted access.
  2. We do not transfer Google user data to others except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with notice and continued protection.
  3. We do not use Google user data for serving advertising, and do not transfer it to advertising platforms or data brokers.
  4. We do not allow humans to read Google user data except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and de-identified for internal operations.
  5. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.

Changes to this policy

We may update this policy. When we do, we will change the “Last updated” date at the top and record the change in the amendment log below. For material changes — particularly changes to what Google user data we access or how we use it — we will notify account owners by email at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.

Contact

We aim to respond within five business days, and to complete formal rights requests within 30 days.

Amendment log

DateChange
July 25, 2026Initial publication.