Privacy Policy
Last updated: 2026-07-25
This policy covers the Manyreach MCP server and its authorization service (together, the "Service") — the components that connect AI assistants (Claude, ChatGPT, Cursor, and other MCP clients) to your Manyreach account. The Manyreach platform itself is governed by its own privacy policy at manyreach.com.
What we collect
Connection identity. When you connect, the Service validates your Manyreach API key and records the account email and user ID that Manyreach returns for it. A short hash derived from your key identifies your sessions in our telemetry.
Credentials. Your Manyreach API key is encrypted into the access token held by your AI client. We do not store the key server-side and it is never written to logs.
Usage telemetry. For each tool call the Service records: the operation name, the call parameters, the assistant's stated intent and its reflections on prior responses, result status and error codes, response sizes and latency, your AI client's name and version, network address, and timestamps.
Feedback. Free-text friction reports the assistant submits about documentation or API problems.
Client IP address and connection identifiers. The Service records the IP address of every request it receives, together with short one-way identifiers for your AI client's connection and session — for security and analytics — across all of its surfaces, including anonymous visits to this documentation site and the authorization flow, not only authenticated tool calls. They are retained under the same telemetry retention window described below.
What we do not collect. Your conversation with your assistant is never transmitted to us. The Service receives only the tool calls your assistant chooses to make — their arguments and stated intent — not the chat itself. The contents of API responses are never logged — your campaigns, prospects, and email messages pass through the Service but are not retained by it. We do not collect payment information.
Why we collect it
To operate and secure the Service, to debug failures, to prevent abuse, and to improve the product — the telemetry exists specifically to find where AI assistants struggle with our documentation and API so we can fix it.
Stated intent and reflections are collected for one additional, specific purpose: enabling collaboration among users of the same Manyreach account. Because an account may be shared by a team, the next collaborator's assistant may be shown an abstract of prior objectives so that work can be continued without repetition. This text is not used for behavioral tracking, profiling, or advertising. Submitting personal data or secrets in the intent or reflection fields is prohibited; assistants are expressly instructed — in the Service's documentation and in the tool schemas themselves — never to include them, and to reference records by identifier rather than by any detail identifying a person.
Storage and retention
Telemetry is stored on our infrastructure and retained for up to 12 months, after which it is deleted or reduced to aggregate statistics. Access tokens expire on their OAuth lifetimes.
Sharing
We do not sell your data and do not share it for marketing. Infrastructure subprocessors (server hosting, Cloudflare) process traffic to run the Service. When the assistant executes an operation on your behalf, that request flows to the Manyreach platform under your own account.
Security
All traffic is encrypted in transit (TLS). API keys are public-key-encrypted inside tokens.
Your choices
Disconnect the connector in your AI client at any time to stop all collection. Revoke or rotate your API key in Manyreach to invalidate existing tokens. Contact us to request deletion of telemetry tied to your account.
Contact
Changes
We will update this page when our practices change; material changes will be noted here with a new "last updated" date.