Legal

MCP connector privacy policy

What the Turbodato connector for Claude and other MCP clients receives, what we log, and what we don't.

This policy covers the Turbodato MCP server at https://app.turbodato.com/api/mcp and its sign-in flow. For the Turbodato platform as a whole, see the general privacy policy (in Spanish), which also applies.

Data controller: Turbodato, El Salvador 5635, CABA, Argentina. Contact: santiago@turbodato.com.

The short version

  • The connector is read-only: it returns price-monitoring data from the dashboards your Turbodato user can already see, and cannot change anything.
  • Turbodato never receives your conversations with Claude. We only receive the tool calls Claude decides to make, with their arguments.
  • We log which tool was called, when, by which user and whether it worked — not the questions you asked or the answers Claude wrote.
  • We don't sell this data, don't use it for advertising and don't use it to train AI models.

What the connector receives

When you connect

You sign in on a Turbodato page with your normal Turbodato credentials and approve the connection. Your password is entered on Turbodato, never on Claude, and is never shared with the MCP client. The client registers itself with its name and the address it redirects back to; Turbodato only accepts redirects to claude.ai, chatgpt.com or your own computer (for local clients such as Claude Code).

Turbodato then issues the client an access token (valid for one hour) and a refresh token (valid for 30 days), scoped to turbodato:read and to your user. These tokens are signed, self-contained credentials: Turbodato does not store them in a database. They are held by the MCP client (for Claude, by Anthropic) until you disconnect.

On every tool call

  • The access token, which identifies your Turbodato user.
  • The tool name and its arguments — a dashboard id and optional filters such as a brand, category, site, seller, date or a search text Claude wrote from your question.
  • Technical request data: IP address, the client's user agent and, at connection time, the client's declared name and version (for example “claude-ai”).

What the connector returns

Your organization's own price-monitoring data: dashboard names, product names and identifiers (EAN, SKU), brands, categories, the retailers and sellers monitored, observed prices and price comparisons. This is business data that you or your organization already see in the Turbodato dashboard. The connector returns no personal data about other people.

Once returned, this data is processed by the MCP client you chose, under that client's own terms and privacy policy — for Claude, Anthropic's privacy policy. Turbodato does not control how the client stores or uses it.

What we log, and why

To operate, secure and improve the connector we record, for each tool call:

  • your Turbodato username;
  • the tool name, the dashboard id, whether it succeeded or failed (with a short error reason) and how long it took;
  • the MCP client's name and version.

We also keep a per-user counter to enforce the rate limit (60 calls per minute), and our hosting provider keeps standard request logs (time, path, status, IP address). If a call fails because of a bug on our side, the error is written to our server logs so we can fix it.

We do not log the search text or other filter values you pass, nor the data returned, and we never receive the content of your conversations.

Who we share it with

No one outside Turbodato, except the providers that run the service on our behalf and under our instructions:

  • PostHog — product analytics; receives the usage events described above.
  • Vercel — hosts the MCP server and keeps request logs.
  • Amazon Web Services — database and infrastructure where your dashboard data lives.

These providers process data mainly in the United States. We may also disclose information if a competent authority legally requires it.

How long we keep it

  • Access tokens expire after one hour and refresh tokens after 30 days. Disconnecting in Claude deletes the tokens the client holds; removing a user from Turbodato cuts their connector within the hour.
  • Rate-limit counters last one minute.
  • Usage events are kept while your account is active and as long as needed to provide the service. Hosting request logs are kept for the provider's short default retention period.

Your rights and choices

You can disconnect at any time from Settings → Connectors in Claude. You can ask us to access, correct or delete the personal data we hold about you — including the connector's usage events — by writing to santiago@turbodato.com. We answer within the time limits set by Argentina's personal data protection law (Law 25,326).

Security

All traffic goes over HTTPS. Tokens are signed and audience-bound, so a connector token cannot be used against other Turbodato APIs. Dashboard access is re-checked on every call against the same permissions as the Turbodato dashboard. Cross-origin browser requests to the server are rejected.

Children

Turbodato is a professional tool. It is not directed at anyone under 18.

Changes

If this policy changes we update the date above. If a change expands what we collect or who we share it with, we will also let you know by email or in the app.