Legal

Connectors and Plugins Privacy Policy

Last updated · October 8, 2026

Anakin Technologies, Inc. (anakin.io)

Effective Date: October 8, 2026

1. Scope

This policy covers Anakin's MCP server at https://mcp.anakin.io/mcpand the integrations built on it: the Anakin plugin for ChatGPT and Codex, the Anakin connector and plugin for Claude, and any other MCP client you connect to Anakin (together, the "Connector"). It also covers the Anakin MCP server package you run yourself, because it sends the same requests to the same Anakin services.

It explains what data the Connector's tools collect, why, who receives it, how long it is kept and how you control it. It supplements our general Privacy Policy, which also applies to your Anakin account.

The AI app you use (for example ChatGPT or Claude) receives the results of the tools it calls and handles them under its own provider's privacy policy.

2. Data We Collect

Account and sign-in

  • Your Anakin account identifier, received when you sign in to the Connector with OAuth 2.1. The AI app never receives your Anakin password.
  • A dedicated API key for each AI app you connect, named after it (for example "ChatGPT (MCP)" or "Claude (MCP)"), and the OAuth tokens that let the app use it. The token the app holds contains only a reference to the key, never the key itself.

What you ask the tools to do

The arguments of every tool call, which can include:

  • URLs to scrape, map, crawl or monitor, and the options for those requests
  • search queries, research prompts and the output schemas you supply
  • Wire action inputs, and the website and goal for a new Wire action
  • browser-task instructions
  • questions sent to AI answer engines through AI Visibility
  • monitor settings, schedules and alert destinations

What the tools return

Page content, structured data extracted from pages, search results, research answers and their sources, Wire action results, browser-task results and the screenshots taken while a browser task runs, monitor snapshots and detected changes, and the answers AI engines give in AI Visibility. Content retrieved from websites can contain personal data about other people. We process it only to carry out your request.

Logins for other websites (only if you use them)

  • Wire sign-in (wire_login): we use the login details you supply for your own account on another site to sign in. We keep the resulting session (cookies or tokens), encrypted, and do not store the password.
  • Login builds (wire_build with a credential): the credential is used once to sign in while the action is built and is not stored.
  • Identity sources: if you connect a password manager or key vault, we store the access credentials for it, encrypted, and fetch the specific login you choose when it is needed.
  • Saved browser sessions: login states you create in the Anakin dashboard, stored encrypted, which tools use to reach pages behind a login.

Monitor alerts

The webhook URL, webhook signing secret and email addresses you set for a monitor's alerts.

Usage and technical data

  • For each request to the MCP server: the tool name, your account identifier, the AI app and its version, the result status and how long it took. The MCP server does not log tool arguments or results.
  • For product analytics: the target URL, the requested country, your IP address and the type and outcome of scrape, map, crawl and research requests.
  • Service logs used to run and troubleshoot the platform.

3. How We Use It

  • To carry out the tool calls you or your AI app make, and return the results.
  • To sign you in, keep the connection secure and apply your plan's credits and limits.
  • To run your monitors on schedule and send the alerts you configured.
  • To keep the service reliable, troubleshoot problems and improve it.
  • To detect and prevent fraud, abuse and security incidents.
  • To understand how the product is used, through product analytics.

4. Who Receives It

Depending on the tool, we share data with the following kinds of recipients, only as needed to carry out your request or run the service:

  • The websites you target. Fetching a page or running an action sends a request to that site, through the location you choose with country when you set one.
  • Web-access providers: proxy networks, website-unblocking and backup scraping services, and CAPTCHA-solving services. They receive the URLs and request details, and page content passes through them.
  • Search providers, which receive your search and research queries.
  • AI model providers, which receive page content and instructions to extract structured data, write research answers, summarize AI Visibility results, decide whether a monitored change matters, drive browser tasks (task instructions and page screenshots) and build new Wire actions.
  • The AI answer engines you choose in AI Visibility, such as ChatGPT, Gemini and Google AI Overview, which receive your question.
  • Password managers or key vaults you connect, when we fetch a login you chose.
  • The alert destinations you set (your webhook URLs and email addresses), and the email delivery provider that sends alert emails.
  • A product analytics provider, which receives the usage data described in section 2.
  • Cloud hosting, storage and logging providers that run the service.

We may also disclose data where the law requires it or as part of a business transfer, as described in our general Privacy Policy. We do not sell your personal information.

5. How Long We Keep It

This is how long data is kept today:

  • Request records for scrape, map, crawl, search and research (the URL, request options and a reference to the result): deleted automatically after 1 year. You can delete individual records sooner from your dashboard.
  • Retrieved content and results stored for those requests: kept without a fixed expiry. Deleting a request record or your account does not currently remove them. To have them deleted, contact us (section 10).
  • Cached results: up to 24 hours.
  • Wire action runs (inputs and results), Wire build requests and AI Visibility searches and answers: kept without a fixed expiry. To have them deleted, contact us.
  • Wire sign-in sessions: each session stops working within 30 days, and its record is kept until you delete it. Identity-source credentials: kept until you delete the source.
  • Saved browser sessions: expire after 90 days without use. Deleting one removes the stored login state; its name and website remain in your account history.
  • Monitors, with their check history and detected changes: kept until you delete the monitor. Page snapshots stored for change detection can remain in storage after that. Records of alert deliveries are deleted after 30 days.
  • Browser tasks: run status and logs are kept for up to 24 hours. Working files created during a run can remain on processing servers longer.
  • API keys: kept until you revoke them. A revoked key is deactivated and can no longer be used.
  • OAuth tokens: access tokens last 1 hour and refresh tokens up to 14 days; expired tokens are deleted within about 15 minutes. The MCP server caches a resolved key for up to 60 seconds.
  • Service logs: generally 30 days.
  • Product analytics: kept without a fixed expiry. Your analytics profile is deleted when you delete your account.

When you delete your account, we delete it together with its request records, API keys, saved browser sessions and recordings, monitors and AI Visibility searches. Stored retrieved content, Wire data (sign-in sessions, identity sources, action runs and builds) and analytics events are not currently removed automatically; contact us to have them deleted. We keep a minimal record (a hashed email and billing reference) for 3 years after deletion for fraud prevention and accounting.

6. Your Controls

  • Disconnect an AI app: remove Anakin in the app, and revoke its key (for example "ChatGPT (MCP)" or "Claude (MCP)") in your Anakin dashboard.
  • Approve actions: tools that change something (Wire write actions and sign-ins, new Wire actions, creating or controlling monitors, deleting saved sessions, browser tasks) are marked so your AI app asks you before each call.
  • Delete data in the dashboard: individual request records, monitors, Wire identities and credentials, identity sources, saved browser sessions and API keys.
  • Delete your account from your account settings (see section 5 for what this removes).
  • Access, correction and deletion requests, including deletion of the data listed above that the dashboard cannot delete: use the data request form or email privacy@anakin.io.

7. Security

Data is encrypted in transit (HTTPS/TLS). API keys, Wire sign-in sessions, identity-source credentials and saved browser sessions are encrypted at rest. The MCP server holds no database credentials or encryption keys; it resolves your key over an internal, authenticated channel.

8. What We Do Not Do

  • We do not access your chat history, memory or files in ChatGPT, Claude or any other AI app.
  • We do not carry out purchases, payments or transfers of funds or assets; the Connector refuses payment-style actions.
  • Anakin does not use your tool inputs or results to train AI models.
  • We do not sell your personal information.

9. Children, Transfers and Changes

The Connector is not intended for anyone under 18. Data may be processed outside your country, including in the United States and India, with the safeguards described in our general Privacy Policy. We will update this page when what we collect, who receives it or how long we keep it changes, and change the date at the top.

10. Contact

Anakin Technologies, Inc.

1111B S Governors Ave, STE 25606, Dover, DE 19904, United States

Privacy and data requests: privacy@anakin.io

Support: support@anakin.io

See also our general Privacy Policy and Terms of Service.