Draft — not yet reviewed by a lawyer. The factual claims here match what the code actually does, but the legal framing needs professional review. Fill in the bracketed details and remove this notice before taking payment.

Privacy Policy

Last updated: [DATE]. This policy explains what MCP for HighLevel, operated by HighLevel Automation Lab ("we", "us"), does with data.

The short version

We store the details needed to connect to your GoHighLevel sub-accounts, and a log of which tools were called and when. We do not store your CRM contents. Your contacts, conversations, deals and invoices stay in GoHighLevel; we pass requests through and return the results without keeping them.

What we collect

DataWhyKept
Your email address and account id To create your account and contact you about the service Until you delete your account
Sub-account name, GoHighLevel Location ID, and Private Integration token To call the GoHighLevel API on your behalf Until you delete that sub-account
Audit log: which tool was called, for which sub-account, whether it succeeded, and when Troubleshooting, abuse prevention, and usage statistics [RETENTION PERIOD, e.g. 90 days]
PayPal subscription id and status To bill you correctly As long as required for accounting

The audit log records tool names, not tool arguments or results. We do not log the contents of your contacts or messages.

How your token is protected

Your GoHighLevel Private Integration token is encrypted with AES-256-GCM before it is written to our database, using a key held separately as a platform secret. It is decrypted only at the moment we need to make a GoHighLevel API call on your behalf, or when you press Test.

It is never returned by any part of our API, never displayed back to you in full (you see only a masked hint such as pit-f855...4182), and never sent to Claude or any other AI system. AI clients only ever see your private link.

Who we share it with

We do not sell data. We share only with the processors needed to run the service:

We may disclose data where legally required.

AI processing

When you connect a link to an AI client, that client sends instructions to us and receives the GoHighLevel data it requested. That data is then handled under your AI provider's terms, not ours. Choose the scopes on your token with that in mind.

Our AI image generation tool sends your prompt to Cloudflare Workers AI and writes the result into your GoHighLevel media library.

Your rights

You can see your connected sub-accounts at any time in your dashboard, and delete any of them, which erases the stored token immediately. You can ask us to delete your whole account and everything attached to it by emailing support@mcphighlevel.com; we action deletion requests within 30 days.

Depending on where you live you may also have rights to access, correct, export or object to processing of your data. Email us and we will help.

Security incidents

If we become aware of a breach affecting your stored credentials, we will notify affected customers by email without undue delay and tell you what to revoke. We recommend rotating a Private Integration token in GoHighLevel if you ever suspect a problem — it takes a minute and invalidates the old one.

Contact

support@mcphighlevel.com, or write to HighLevel Automation Lab, [REGISTERED ADDRESS].