Privacy Policy
Last updated: [DATE]. This policy explains what MCP for HighLevel, operated by HighLevel Automation Lab ("we", "us"), does with data.
The short version
We store the details needed to connect to your GoHighLevel sub-accounts, and a log of which tools were called and when. We do not store your CRM contents. Your contacts, conversations, deals and invoices stay in GoHighLevel; we pass requests through and return the results without keeping them.
What we collect
| Data | Why | Kept |
|---|---|---|
| Your email address and account id | To create your account and contact you about the service | Until you delete your account |
| Sub-account name, GoHighLevel Location ID, and Private Integration token | To call the GoHighLevel API on your behalf | Until you delete that sub-account |
| Audit log: which tool was called, for which sub-account, whether it succeeded, and when | Troubleshooting, abuse prevention, and usage statistics | [RETENTION PERIOD, e.g. 90 days] |
| PayPal subscription id and status | To bill you correctly | As long as required for accounting |
The audit log records tool names, not tool arguments or results. We do not log the contents of your contacts or messages.
How your token is protected
Your GoHighLevel Private Integration token is encrypted with AES-256-GCM before it is written to our database, using a key held separately as a platform secret. It is decrypted only at the moment we need to make a GoHighLevel API call on your behalf, or when you press Test.
It is never returned by any part of our API, never displayed back to you in full (you see
only a masked hint such as pit-f855...4182), and never sent to Claude or any
other AI system. AI clients only ever see your private link.
Who we share it with
We do not sell data. We share only with the processors needed to run the service:
- Cloudflare — hosting, database and caching
- Clerk — account sign-in
- PayPal — payments (we never see your card or PayPal password)
- GoHighLevel — the API we call on your instruction
We may disclose data where legally required.
AI processing
When you connect a link to an AI client, that client sends instructions to us and receives the GoHighLevel data it requested. That data is then handled under your AI provider's terms, not ours. Choose the scopes on your token with that in mind.
Our AI image generation tool sends your prompt to Cloudflare Workers AI and writes the result into your GoHighLevel media library.
Your rights
You can see your connected sub-accounts at any time in your dashboard, and delete any of them, which erases the stored token immediately. You can ask us to delete your whole account and everything attached to it by emailing support@mcphighlevel.com; we action deletion requests within 30 days.
Depending on where you live you may also have rights to access, correct, export or object to processing of your data. Email us and we will help.
Security incidents
If we become aware of a breach affecting your stored credentials, we will notify affected customers by email without undue delay and tell you what to revoke. We recommend rotating a Private Integration token in GoHighLevel if you ever suspect a problem — it takes a minute and invalidates the old one.
Contact
support@mcphighlevel.com, or write to HighLevel Automation Lab, [REGISTERED ADDRESS].