ghlmcp.io ("we", "us") connects your AI assistant (such as Claude or ChatGPT) to your own GoHighLevel account so the AI can build and manage your GoHighLevel workflows on your behalf. This policy explains what data we collect, how we use it, how we store it, and how we share it.
1. Data We Collect
- Authentication information: your active GoHighLevel session token. The ghlmcp.io Workflow Connector reads this token from your browser (only on GoHighLevel domains) and sends it to your ghlmcp.io account. This token is what allows the service to act on your behalf inside GoHighLevel. It is the core data this extension handles.
- Account identifiers: your GoHighLevel sub-account (location) ID and a pairing key you provide, used to link the session to the correct ghlmcp.io account.
- We do NOT collect your GoHighLevel password or login credentials. We do not collect browsing history, and the extension does not read or operate on any website other than GoHighLevel.
2. How We Use the Data
We use your GoHighLevel session token solely to authenticate the GoHighLevel API requests you initiate through your AI assistant (for example, listing, creating, editing, or auditing your workflows). We do not use your data for advertising, profiling, or any purpose unrelated to operating your ghlmcp.io connection.
We also collect internal product analytics inside the signed-in dashboard: pages visited, buttons used, errors encountered, and a technical recording of the dashboard interface so we can diagnose problems and improve the product. Form inputs, tokens and payment fields are masked and never recorded. This data is used only by our own team and is never sold or shared with advertisers. Screen recordings are deleted automatically after 48 hours, and usage events after 30 days.
3. How We Store and Secure the Data
- Your session token and account identifiers are transmitted only over encrypted HTTPS to your own ghlmcp.io account endpoint.
- They are stored securely (encrypted at rest) on ghlmcp.io's servers and used only to authenticate your GoHighLevel requests.
- GoHighLevel session tokens are short-lived and are refreshed automatically while your connection is active.
4. Data Retention and Deletion
- We retain your session token only while your connection is active. When you disconnect (from the extension or your ghlmcp.io dashboard), syncing stops immediately and the stored session token is deleted.
- You may request deletion of all associated data at any time by contacting us at the address below.
5. How We Share the Data
- We do NOT sell, rent, or trade your data.
- We do NOT share your data with third parties for their own purposes.
- Your data is sent only to your own ghlmcp.io account endpoint to operate the service you requested. We may use standard infrastructure providers (e.g., hosting) solely to run the service, under confidentiality obligations.
6. Your Choices and Controls
You can disconnect at any time, which stops all data collection and deletes the stored session token. You control which GoHighLevel sub-account is connected.
7. Children's Privacy
The service is intended for business users and is not directed to children under 13.
8. Changes to This Policy
We may update this policy; the effective date above reflects the latest version.
9. Contact
Questions or data-deletion requests: autogencrm@gmail.com
