Privacy & Your Data
This Trust Center covers in-platform AI (features inside impact.com) and external AI integrations via Impact MCP (connecting your own AI client to your account), and where those paths differ.
Our data commitments
Used only to serve your request. When you use an AI feature, your data is used only to generate a response for you or return tool results, never repurposed for unrelated ends.
Your data is never mixed. Both in-platform AI and MCP respect the same strict, user-based authorization that governs the entire platform. You can only query the data you're already entitled to see, and your data is never commingled with, or accessible to, other customers.
You're in control. In-platform AI features are opt-out. MCP stays off until your account enables it, and each user explicitly approves every AI client. In both cases, you only access data your role already allows, and you can decline use of your data to train our models.
Provider handling
In-platform AI: Our AI provider processes your data only to deliver the feature, under strict security and privacy requirements, and is contractually prohibited from using it to train their models.
Impact MCP: impact.com does not forward MCP tool data to LLM providers. If your AI client or model provider retains or processes prompts and tool results, that is governed by your agreement with them.
Data flow
Platform AI features
Here's what happens when you use an AI feature:
You make a request
Your request travels over an encrypted connection (TLS 1.2+).
We gather context
We securely retrieve only the data needed to answer, from your account (for analytics) or our knowledge base.
Secure AI processing
The request and context are sent to our AI provider on secure cloud infrastructure and used only for this request. Your data stays within impact.com's cloud environment.
You get a response
A response is generated and returned to you.
Nothing lingers with the provider
The provider does not retain your request data for its own purposes and does not use it to train its models.
Impact MCP
Here's what happens when you connect an AI client to mcp.impact.com:
You authorize your AI client
You sign in with your existing impact.com credentials and approve the client over an encrypted connection (TLS 1.2+). The client receives a scoped token limited to MCP access.
Your client calls a tool
Your AI client (for example, Claude, Cursor, or VS Code) sends an authenticated tool request to the mcp.impact.com gateway. The trust boundary sits at this gateway: everything on your side is your environment, and everything on ours is impact.com production infrastructure.
We validate and return results
The gateway checks your authorization, enforces your existing impact.com permissions, and runs the requested capability against our backend services. Tool results are returned to your AI client, not to a model provider.
Generative processing stays on your side
Your AI client may send prompts and tool results to your chosen model provider. That processing is governed by your relationship with that client and model provider. impact.com does not forward MCP tool data to LLM providers on your behalf.
We log for security
We log MCP call metadata needed for security and operations, such as who called, which capability was used, when, and the outcome, and retain those logs for at least 90 days. We do not log full tool request or response payloads in production.
For how we secure this data, see Security. For how we explain what the AI is doing, see Transparency.
Last updated
Was this helpful?