MCP Data Handling & Security

Last updated: April 20, 2026

Learn how we handle your data for 📄 Model Context Protocol (MCP). For full details on data collection, storage, retention, and third-party sharing, see our privacy policy.

What Data Flows Through MCP?

Only data required for the specific tool call you make:

  • Tool requests — the tool name and parameters (e.g., "create_asset" with a template ID)

  • Tool responses — the result from Mutiny (e.g., asset details, template lists)

The connector does not transmit your full workspace data, CRM records, analytics, or billing information.

Authentication

  • All connections use OAuth 2.0 with PKCE — your Mutiny password is never shared with the AI assistant

  • Tokens are scoped to specific permissions and can be revoked at any time

  • All traffic uses HTTPS (TLS 1.2+)

What Mutiny Does NOT Store

  • Conversation content — Mutiny does not receive or log your prompts or chat history

  • Other tool results — if you use other connectors in the same conversation, Mutiny has no access to that data

What Mutiny DOES Store

  • Assets and library content you create — stored in your workspace, same as if created in the Mutiny app

Mutiny uses third-party data processors with limited data retention for observability and logging necessary to maintain our systems.

Related Articles

📄 What Can You Do with Mutiny + AI?

📄 Mutiny + Model Context Protocol (MCP)

Need Help?

If you have questions or need help, the Mutiny Support team is here for you! You can submit a support ticket using the Submit a ticket button at the top of this page, or reach us at support@mutinyhq.com.