This policy explains what data the theMarketer MCP Server (https://mcp.themarketer.com/mcp) processes when you connect it to an AI assistant such as Claude, ChatGPT or OpenClaw. It supplements the general theMarketer Privacy Policy, which continues to apply to your theMarketer account and the data stored in it.
The MCP Server is a gateway between your AI assistant and your existing theMarketer account. It exposes theMarketer features (subscribers, campaigns, e-commerce data, reports, transactional messaging and others) as tools that the assistant can call on your behalf. It does not create a new copy of your theMarketer data and it does not train or operate any AI model itself.
Access is granted through OAuth 2.1. When you connect, you sign in with your theMarketer ID on theMarketer's own authentication service and approve the requested scopes. The MCP Server never sees your password. It receives access and refresh tokens, which it stores encrypted at rest and uses only to call the theMarketer API on your behalf. You can revoke access at any time by disconnecting the connector in your AI assistant.
| Data | Purpose | Stored by the MCP Server? |
|---|---|---|
| Your theMarketer user ID and the domain(s) you act on | Authorization, scoping every request to your account | Yes, in request logs |
| OAuth client registrations, access and refresh tokens | Keeping your connection alive | Yes, encrypted |
| Tool name and the arguments sent by your assistant (which may include personal data of your subscribers, e.g. email addresses or phone numbers) | Executing the request, troubleshooting, abuse prevention | Yes, in request logs |
| Tool results returned from theMarketer | Answering the request | No, passed through only |
| Outcome, error code, duration, trace and session identifiers, client user agent | Reliability monitoring and support | Yes, in request logs |
| Your conversation with the assistant | - | No, never received |
The MCP Server only receives the specific tool calls the assistant makes. It has no access to the rest of your conversation, the assistant's memory or your files.
Tool calls and their results travel through the AI assistant you use (for example Anthropic for Claude, or OpenAI for ChatGPT). How that provider handles the data is governed by its own privacy policy and your agreement with it. We recommend reviewing those terms, in particular regarding data retention and model training.
Data processed by the MCP Server is shared only with theMarketer's own systems (the theMarketer API and authentication service) and with the AI assistant provider you chose to connect. We do not sell data and we do not share it with advertisers or other third parties. Infrastructure providers hosting the MCP Server act as processors under contract.
All traffic is encrypted in transit (HTTPS). Tokens are encrypted at rest. Access to request logs is restricted to authorized theMarketer staff for support and security purposes.
Depending on where you live you may have the right to access, correct, delete or export your personal data, and to object to or restrict its processing. Requests regarding the MCP Server can be sent to the contact below; requests regarding your theMarketer account follow the general Privacy Policy.
theMarketer · privacy@themarketer.com
We may update this policy as the MCP Server evolves. The date at the top shows the latest revision.