Who we are and who this applies to
Clay Digital Consulting, 71 Dowlen Rd, Hixson, TN 37343.
This policy applies to customers (people and organizations with a CortexMCP account), authorized users (individuals invited into a customer’s account as Owner, Member, or Client), and visitors to cortexmcp.io.
Where our customers are the controller. When a customer uses CortexMCP to analyze their own website, their own marketing data, or the websites of their own clients, the customer decides what data enters the Service and why. In that relationship the customer is the data controller and CortexMCP acts as a processor on their instructions. This matters most for our website analytics feature (§4).
Information we collect
Account and identity information
Name, email address, password (stored as a salted hash — we never store or can retrieve your plaintext password), organization name, role, and account preferences. If you sign in with Google, we receive your email address and basic profile information from Google.
Billing information
Subscription tier, billing status, renewal dates, and transaction history. Payment card details are never transmitted to or stored by CortexMCP — payments are processed by our payment processor, which handles card data directly.
Business context you provide
The core of the Service is business memory: information you deliberately enter or upload — business identity, positioning, target audience, offers and pricing, objectives, competitive notes, brand voice and guidelines, customer avatars, and project notes. It may include commercially sensitive information. It is stored under your account and is not shared with other customers.
Connected property data
Where you connect a website, we store site URLs, page content, page structure, internal links, structured data, published and draft content, and — for WordPress connections via TheSystem — the credentials required to publish, stored in encrypted form.
Google user data
Where you connect a Google service, we access and store the data described in §3.
Third-party data about you and your market
To perform research and audits, the Service retrieves publicly available data from third-party providers — search results, keyword metrics, backlink data, competitor page content, and responses from AI assistants. This is data about websites and markets, not about you personally, though it may include content you have published.
Website analytics data collected on your behalf
If you install our first-party analytics script on your website, we collect pageviews, referrers, campaign parameters, device and browser type, approximate geographic location derived from IP address, and page-to-page navigation for your visitors. See §4.
Usage and technical data
Log data, IP address, browser and device information, tool and feature usage, API and MCP call records, credit consumption, error traces, and performance telemetry. We use this to operate the Service, debug failures, prevent abuse, and understand which features are used.
Communications
Support tickets, bug reports, and email correspondence with us.
We do not knowingly collect information from anyone under 18. The Service is a business product and is not directed at children. If we learn we have collected such information, we delete it.
Google user data
CortexMCP requests access to Google services only when you initiate a connection, through Google’s standard OAuth 2.0 consent flow. Nothing is connected by default. Each integration is independent — connecting Calendar does not grant access to Search Console.
Scopes we request, and why
| Scope | What it grants | What we do with it | What we store | Retention |
|---|---|---|---|---|
https://www.googleapis.com/auth/webmasters.readonly | Read-only access to your Google Search Console properties | List your verified properties so you can match one to a project; retrieve search performance data (query, page, clicks, impressions, click-through rate, average position) to display performance, detect pages competing for the same query, identify content gaps, and measure whether published work improved rankings | Your property list and the retrieved performance rows, associated with your project | While the connection is active; performance rows kept for rolling historical comparison; deleted within 30 days of disconnection or account deletion |
https://www.googleapis.com/auth/analytics.readonly | Read-only access to your Google Analytics data | Retrieve traffic and engagement metrics so Google Analytics figures can be displayed alongside CortexMCP’s own analytics and attributed to specific content and campaigns | Aggregated metric rows, associated with your project | Same as above |
https://www.googleapis.com/auth/business.manage | Manage the Google Business Profiles you administer | Read your business locations and profile details for local-visibility auditing and competitive comparison; create posts on a Business Profile only when you explicitly compose and publish or schedule one through CortexMCP. We do not alter your business name, address, hours, categories, or reviews | Location identifiers, business name, category, and the content of posts you created through the Service | While the connection is active; deleted within 30 days of disconnection or account deletion |
https://www.googleapis.com/auth/calendar and https://www.googleapis.com/auth/calendar.events | Read and write your calendar events | Build daily briefings and end-of-day reviews, detect scheduling conflicts, compute availability, protect focus time, and attach relevant business context to upcoming meetings. Events are created, updated, or deleted only in response to your explicit instruction | A cached copy of upcoming events (title, time, attendees, location, description) to generate briefings without repeatedly re-fetching | Cache kept while the connection is active; deleted on disconnection |
https://www.googleapis.com/auth/tasks | Read and write your Google Tasks | Include tasks in briefings and keep Google Tasks synchronized with tasks created in CortexMCP, so one list works in both places | Task title, notes, due date, status, and the mapping between the Google task and the CortexMCP task | While the connection is active; deleted on disconnection |
https://www.googleapis.com/auth/userinfo.email | Your Google account email address | Show you which Google account is connected, and match your Search Console properties to the correct site | Email address on the connection record | While the connection is active |
Where Google offers a narrower alternative for a given function, we request the narrower scope. We request write scopes for Calendar and Tasks because the assistant’s purpose is to create and modify events and tasks on your behalf; read-only scopes would make those features impossible.
What we never do with Google user data
- We do not sell it, rent it, or trade it.
- We do not use it for advertising or transfer it to any advertising platform, ad network, or data broker.
- We do not use it to develop, improve, or train generalized artificial intelligence or machine-learning models, our own or anyone else’s.
- We do not use it to build profiles for purposes unrelated to the features you connected it for.
- We do not permit our staff to read it, except in the limited circumstances below.
Human access
Employees and contractors do not access your Google user data except: with your explicit, case-specific consent (for example, when you ask us to investigate a problem with your Search Console connection); where necessary for security purposes, such as investigating suspected abuse or a security incident; to comply with applicable law; or where the data has been aggregated and de-identified such that it no longer identifies you, and is used only for internal operational metrics.
Revoking access
You may revoke CortexMCP’s access to any Google service at any time through your Google account at myaccount.google.com/permissions; our access ends immediately, and the associated cached data is removed on our next scheduled cleanup, within 30 days. Where a disconnect control is available in Settings → Integrations, disconnecting deletes the stored credentials and cached data for that connection, and for Search Console it also revokes our authorization with Google.
Website analytics collected on your behalf
If you install the CortexMCP analytics script on a website you operate, we collect data about your visitors on your instruction. For that data, you are the controller and we are your processor.
- The script is cookieless. It does not set advertising or cross-site tracking identifiers, and does not follow visitors across other websites.
- IP addresses are used to derive approximate location (country, region, city) and are not retained in full alongside the pageview record.
- We do not use your visitors’ data for our own purposes, do not combine it across customers, and do not sell it.
- You are responsible for having a lawful basis for this collection and for disclosing it in your own website’s privacy notice, including any notice or consent your jurisdiction requires.
- Visitor data is deleted within 30 days of your account’s deletion or your removal of the site.
How we use information
We use the information described above to:
- Provide the Service — run the features you asked for.
- Load your business context into the platform’s analysis, planning, and drafting functions.
- Generate content, briefs, audits, and recommendations at your direction.
- Publish to destinations you have connected, when you instruct us to.
- Authenticate you and secure your account.
- Bill you and manage your subscription.
- Provide support, and diagnose and fix defects.
- Monitor performance, prevent abuse, and enforce usage limits.
- Communicate with you about the Service — changes, incidents, and, where you have not opted out, product updates.
- Comply with legal obligations.
AI processing. The Service uses third-party large language models to generate and evaluate content. Your business context and connected-site content may be transmitted to these providers as part of a request so the output reflects your business. These providers are contractually bound not to use content submitted through their business APIs to train their models. Google user data is not sent to these providers for model training and is not used to train any model. Where an analysis requires Google-derived figures, only the minimum necessary aggregate values are included, never raw credentials.
We do not use your business context, your content, or your Google user data to train our own models, and we do not use one customer’s data to improve outcomes for another customer.
Storage and security
- Credentials. OAuth access and refresh tokens for connected Google and third-party services are encrypted at rest. WordPress application passwords and third-party API keys are likewise encrypted. Your CortexMCP password is stored only as a salted hash.
- In transit. All traffic to and from the Service uses TLS.
- Tenant isolation. Every record is scoped to an account and, within an account, to a project. Isolation is enforced at the database layer through row-level security, not only in application code. An agency’s client projects are isolated from one another.
- Access control. Roles are Owner, Member, and Client, with permissions appropriate to each. Administrative access by our staff is limited, logged, and used for support and incident response.
- Logging. Authentication events and significant project activity are logged for security and audit purposes.
- Hosting. Data is stored on infrastructure located in the United States.
No system is perfectly secure. We cannot guarantee absolute security, but we work to protect your information and will notify you and, where required, the relevant supervisory authority of a breach affecting your personal data without undue delay.
Sub-processors and disclosure
We share information only as described here. We do not sell personal information.
Service providers. We use third parties to operate the Service. Each is bound by contract to process data only on our instructions and to maintain appropriate security. We will notify customers of material changes to the providers we rely on.
| Provider(s) | Purpose | Data involved | Processing location |
|---|---|---|---|
| Hostinger (VPS) — self-managed PostgreSQL | Cloud hosting and database — running the Service and storing data | All categories | United States |
| Together AI, Anthropic, Perplexity | AI model providers — content generation, classification, and evaluation (and any provider whose key you supply) | Business context, site content, prompt text | United States |
| DataForSEO | Search and SEO data — keyword, ranking, backlink, and competitor data | Domains and keywords you research | United States |
| Cloudflare (R2 object storage, CDN) | Asset storage and content delivery | Uploaded and generated assets; requested pages | United States / global edge |
| SendGrid | Email delivery — transactional and notification email | Name, email address, message content | United States |
| SamCart | Payment processing and subscription billing | Billing contact and transaction data; card data handled directly by the processor | United States |
| Higgsfield, Hume AI | Optional media features — image generation and voice-interview analysis | Prompts and content you submit to those features | United States |
| ip-api | Geolocation lookup — deriving approximate visitor location from IP | IP address | United States |
| Sentry | Error and performance monitoring — diagnosing failures | Technical logs, which may include identifiers | United States |
Other disclosures.
- At your direction — for example, publishing content to a WordPress site or a Google Business Profile you connected, or sharing a client dashboard through a link you generated.
- Within your account — other authorized users of your account can see the account’s data according to their role.
- Legal — where required by law, subpoena, or valid legal process, or to establish or defend legal claims. We will notify you unless legally prohibited.
- Business transfer — if the business is acquired or merged, information may transfer as part of that transaction. You will be notified, and this policy will continue to apply until replaced by a policy you are given notice of.
Retention
| Data | Retained |
|---|---|
| Account and billing records | For the life of the account, then as required for tax and legal purposes |
| Business context and brand library | For the life of the account; deleted within 30 days of account deletion |
| Generated content and audits | For the life of the account, unless you delete it sooner |
| Google user data | While the connection is active; deleted within 30 days of disconnection or account deletion |
| Visitor analytics data | While the site is registered; deleted within 30 days of removal or account deletion |
| Logs and telemetry | Up to 12 months |
| Backups | Rolling backups retained up to 35 days; deleted data persists in backups until they age out |
Your rights and how to exercise them
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined. Residents of the EEA and UK have rights under the GDPR, and may lodge a complaint with their supervisory authority.
Deletion. You can delete most data directly in the dashboard. To delete your entire account and all associated data, email privacy@cortexmcp.io from the address on your account, or use the account deletion option in Settings. We will confirm the request, complete deletion within 30 days, and confirm when it is done. Data in backups is removed as those backups age out, within 35 days. We may retain the minimum records required for legal, tax, or fraud-prevention purposes, and will tell you what those are.
Google data specifically. Disconnecting an integration (§3) deletes the credentials and cached data for that integration without deleting your CortexMCP account.
We respond to rights requests within 30 days. We do not charge for the first request in a 12-month period. We may need to verify your identity before acting.
International transfers
The Service is operated from the United States, and information is processed there. If you access the Service from outside the United States, you are transferring information to a country whose data protection laws may differ from your own. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism with our sub-processors.
Limited Use of Google user data
CortexMCP’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, and without limiting the statement above:
- We use Google user data only to provide and improve the user-facing features described in §3 — features that are visible and useful to the person who granted access.
- We do not transfer Google user data to others except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with notice and continued protection.
- We do not use Google user data for serving advertising, and do not transfer it to advertising platforms or data brokers.
- We do not allow humans to read Google user data except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and de-identified for internal operations.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
Changes to this policy
We may update this policy. When we do, we will change the “Last updated” date at the top and record the change in the amendment log below. For material changes — particularly changes to what Google user data we access or how we use it — we will notify account owners by email at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.
Contact
- Privacy questions and data requests: privacy@cortexmcp.io
- General support: support@cortexmcp.io
- Mail: Clay Digital Consulting, 71 Dowlen Rd, Hixson, TN 37343
We aim to respond within five business days, and to complete formal rights requests within 30 days.
Amendment log
| Date | Change |
|---|---|
| July 25, 2026 | Initial publication. |