Who we are and what this covers
Scalix MCP for Claude is built and operated by ScalixAI (“we”). This policy covers this website, the Scalix console where you sign in and connect ad accounts, and the MCP server that Claude talks to. Clients of the ScalixAI agency are also covered by the agency’s own privacy policy at scalixai.com; where the two overlap, this one applies to Scalix MCP.
What we collect
- Your account. The name, email address and profile picture from the Google account you sign in with.
- Your connections. The OAuth tokens that let the server call Google Ads and LinkedIn on your behalf, and the IDs and names of the ad accounts you choose to make visible. Tokens are stored encrypted; see Security.
- Your access keys. The keys you create to connect Claude. We store only a keyed hash of each key, never the key itself, together with its label, creation time and last use.
- An audit record of every change. For each write Claude asks for and you approve: the time, the instruction, what the platform held before and after, and the result. This log exists so that you can see exactly what changed and when.
- Technical logs. Request metadata and errors, with tokens and keys redacted, used for security and troubleshooting.
- Ad-platform data in transit. Campaign, performance, keyword, audience and lead data that your Claude conversation asks for passes through the server to your Claude client. We do not keep it beyond serving the request and short-lived caches, except as described for LinkedIn below.
- Messages you send us. Email and support correspondence.
This website sets no analytics or tracking cookies. The console uses only the cookies and browser storage needed to keep you signed in.
How we use it
- To run the service: authenticate you, call the platforms you connected, preview and apply the changes you approve, enforce the policy guard, and keep the audit log.
- To keep it secure: detect abuse, revoke compromised keys, and investigate incidents.
- To support you and to answer your requests.
- To meet the terms of the platforms we integrate with.
We do not sell your data, advertise to you on the basis of your ad-account data, pool or benchmark your accounts against anyone else’s, or use your data to train models.
Platform rules we follow
Google. Our use of data received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements: the data is used only to provide and improve the features you see, is never used for advertising or sold, and is read by people only with your consent, for security, or where the law requires.
LinkedIn. We follow the LinkedIn Marketing API terms and data-storage rules. Member profile data is kept no longer than 24 hours and member social-activity data no longer than 48 hours; a scheduled job purges it. Lead-form responses are forwarded only to your own connected systems with your consent. Member data is never used to enrich a CRM, build prospecting lists, or for any account other than the one it came from.
Who else sees it
- Google Cloud, which hosts the service (compute, database, key management, secrets, logging).
- Google (sign-in and the Google Ads API) and LinkedIn (the Marketing API), which receive the requests made on your behalf.
- Anthropic, through the Claude client you use: the data your conversation requests is delivered to Claude and handled under Anthropic’s terms and your Claude plan.
- Your own CRM (for example HubSpot or Salesforce), only if you connect one and only the data you send to it.
Beyond these, we disclose data only where the law requires it, or as part of a business transfer, in which case we will tell you first.
How long we keep it
- Account details: while your account exists.
- OAuth tokens: until you disconnect the platform or revoke access, when they are deleted.
- Access-key hashes: until you revoke the key; revoked keys are kept as records for your own review.
- The audit log: while your account exists, so you can review every change; deleted with the account.
- LinkedIn member data: 24 hours for profile data, 48 hours for social-activity data.
- Technical logs: 30 days.
Your controls
- Choose which ad accounts the connector can see.
- Disconnect a platform at any time; this revokes the grant and deletes its tokens.
- Revoke any access key, or all of them, instantly.
- Revoke access from your Google Account or LinkedIn settings, which takes effect at once.
- Ask us to access, correct, export or delete your data, or object to a use of it, by writing to privacy@scalixai.com. We answer within 30 days.
Security
Data is encrypted in transit and at rest. Tokens are protected with envelope encryption under keys held in Cloud KMS, access keys are stored only as keyed hashes, every request runs in the context of one account, and every write needs your explicit approval. The Security page describes the design.
Where it is processed
The service runs on Google Cloud. Your data may be processed in the Google Cloud regions we deploy to, and where a transfer across borders is required by that, it happens under Google Cloud’s data-processing terms and the safeguards they provide.
Children
Scalix MCP is a business service and is not directed at anyone under 18.
Changes
When this policy changes we update the date at the top of this page and, for material changes, tell you by email or in the console before they take effect.
Contact
ScalixAI · privacy@scalixai.com