AutoboundAutobound

Privacy notice for AI tool integrations

Last updated October 1, 2026. Supplements the Autobound Privacy Policy and the Master Services Agreement.

What this covers

This notice applies when you connect an AI tool such as Claude, ChatGPT, Cursor or Claude Code to Autobound through the Model Context Protocol (MCP) at mcp.autobound.ai, and when you sign in to authorize that connection at signalapi.autobound.ai.

What we collect

  • Account identity: your Autobound account id, email, and the workspace you choose at consent.
  • Connection records: the name of the AI tool, when it was connected, when it was last used, and the credentials we issue to it (access tokens, refresh tokens, and a hidden per-connection API key). Tokens and keys are stored hashed or encrypted.
  • Requests the AI tool makes: the tool called, the search terms, company domains, contact names, email addresses or LinkedIn URLs the tool sends on your behalf, the time, response size, status, and credits charged. This is the same request log kept for direct API use.
  • Technical data: IP address, user agent, and client identifiers sent by the AI tool.

We do not receive your conversation with the AI tool. We only receive the specific requests the tool sends to Autobound.

How we use it

  • To authenticate the AI tool and return the data it requests from your workspace.
  • To meter credits and rate limits for your workspace.
  • To show you connected tools and let you disconnect them.
  • To monitor reliability, prevent abuse, and provide support.
  • To understand product usage in aggregate (for example, which tools are used and how often).

We do not sell this data and we do not use the content of your requests to train AI models.

Who we share it with

  • The AI tool you connected receives the data it requests. Its handling of that data is governed by its own privacy policy (for example Anthropic for Claude, OpenAI for ChatGPT, Anysphere for Cursor).
  • Service providers that host and monitor Autobound: Google Cloud (hosting and storage), Sentry (error monitoring), PostHog (product analytics). They process data under contract and only for us.
  • We do not share connection or request data with other third parties, except when the law requires it.

How long we keep it

  • Connection records: until you disconnect the tool, plus 30 days. Tokens expire after 1 hour (access) and 30 days of inactivity (refresh); a disconnected connection stops working within one minute.
  • Request logs: 13 months, for billing reconciliation and abuse prevention.
  • Error and analytics events: 90 days.
  • Account data: as described in the Autobound Privacy Policy.

Your controls

  • Disconnect any AI tool at any time from Integrations & MCP in the portal. Workspace owners and admins can disconnect any member's tool.
  • Deny the connection on the consent screen; nothing is stored beyond the attempt.
  • Request access to or deletion of your data by email (below).

Contact

Questions, access or deletion requests: support@autobound.ai.

Autobound, Inc. · www.autobound.ai