For the complete documentation index, see llms.txt. This page is also available as Markdown.

Privacy & Your Data

This Trust Center covers in-platform AI (features inside impact.com) and external AI integrations via Impact MCP (connecting your own AI client to your account), and where those paths differ.

Our data commitments

Provider handling

In-platform AI: Our AI provider processes your data only to deliver the feature, under strict security and privacy requirements, and is contractually prohibited from using it to train their models.

Impact MCP: impact.com does not forward MCP tool data to LLM providers. If your AI client or model provider retains or processes prompts and tool results, that is governed by your agreement with them.

Data flow

Platform AI features

Here's what happens when you use an AI feature:

1

You make a request

Your request travels over an encrypted connection (TLS 1.2+).

2

We gather context

We securely retrieve only the data needed to answer, from your account (for analytics) or our knowledge base.

3

Secure AI processing

The request and context are sent to our AI provider on secure cloud infrastructure and used only for this request. Your data stays within impact.com's cloud environment.

4

You get a response

A response is generated and returned to you.

5

Nothing lingers with the provider

The provider does not retain your request data for its own purposes and does not use it to train its models.

Impact MCP

Here's what happens when you connect an AI client to mcp.impact.com:

1

You authorize your AI client

You sign in with your existing impact.com credentials and approve the client over an encrypted connection (TLS 1.2+). The client receives a scoped token limited to MCP access.

2

Your client calls a tool

Your AI client (for example, Claude, Cursor, or VS Code) sends an authenticated tool request to the mcp.impact.com gateway. The trust boundary sits at this gateway: everything on your side is your environment, and everything on ours is impact.com production infrastructure.

3

We validate and return results

The gateway checks your authorization, enforces your existing impact.com permissions, and runs the requested capability against our backend services. Tool results are returned to your AI client, not to a model provider.

4

Generative processing stays on your side

Your AI client may send prompts and tool results to your chosen model provider. That processing is governed by your relationship with that client and model provider. impact.com does not forward MCP tool data to LLM providers on your behalf.

5

We log for security

We log MCP call metadata needed for security and operations, such as who called, which capability was used, when, and the outcome, and retain those logs for at least 90 days. We do not log full tool request or response payloads in production.


For how we secure this data, see Security. For how we explain what the AI is doing, see Transparency.

Last updated

Was this helpful?