Security

Security & data handling

This page is maintained by the ghlmcp.io team to answer common security and privacy questions in plain language.

Data we access

Your GoHighLevel session token, so we can operate on your behalf, and a pairing key you provide to link your extension to your ghlmcp.io account. That's it.

Data we do not collect

We do not collect or store your GoHighLevel password or any login credentials. We do not read anything from non-GoHighLevel sites.

Where it goes

Your session token is sent only to your ghlmcp.io account endpoint, over HTTPS. GoHighLevel session tokens are short-lived and refresh through your own session.

Storage & encryption

Tokens are stored securely and encrypted at rest. They are used only to authenticate GoHighLevel requests that you (or an AI client you have connected) initiate.

Your controls

You can disconnect at any time — from the Chrome extension or from your ghlmcp.io dashboard. Disconnecting stops all syncing immediately and removes your session from our systems.

Not sold or shared

We never sell or share your data. It is used only to operate the connection between your AI client and your GoHighLevel account.

Sub-account isolation

Each connection is locked to the GoHighLevel sub-account you choose. A token bound to one sub-account cannot be used to reach another.