Privacy Policy — Crisol MCP
1. Data Controller
- Owner: Sara Fernández Velasco
- NIF: 47528322H
- Address: Calle Carmen Burgos, n.º 96, 18100 Armilla, Granada
- Contact for privacy matters: privacidad@crisolmcp.com
2. What data do we process and where does it come from?
Crisol MCP is a subscription platform accessed by registering with your email address. Below we detail what data we process, organized by source:
2.1 Identity data (when you register and sign in)
Access is carried out without a password, via a magic link sent to your email; we do not use third-party sign-in. We store:
| Data | Description |
|---|---|
| Identifies your account and is the address to which the access link is sent | |
| Name | Your name, recorded when you sign up |
| Internal account identifier | An identifier specific to Crisol MCP, not linked to any external provider |
| Registration date | When you signed up for Crisol MCP |
| Last sign-in | Date of your most recent access |
| Role | Whether your account is administrator, client or guest |
2.1.bis Subscription data
If you contract a paid plan, we store the minimum data necessary to manage your subscription:
| Data | Description |
|---|---|
Stripe customer identifier (stripe_customer_id) |
A reference that lets us associate your account with your subscription in Stripe |
| Subscription status and plan | Whether your subscription is active, paused or canceled, and which plan it corresponds to |
We do not store your card data or your complete tax details (NIF/CIF, billing address): that data is collected and held directly by Stripe during the payment process (see Section 4).
2.2 Credentials for marketing tools you voluntarily connect
If you decide to connect your own accounts of Google Search Console, Google Analytics 4, Google Ads, Google Merchant Center, Meta Ads, Bing Webmaster Tools, IndexNow, PageSpeed Insights or your online store (WooCommerce, PrestaShop), we store the necessary credentials (OAuth tokens, API keys) always encrypted at rest:
- Encrypted using a Fernet token (AES-128 in CBC mode + HMAC-SHA256 authentication).
- The master encryption key is stored in the server environment, outside the database, never alongside the data it encrypts.
- None of these credentials is accessible in plaintext outside the server itself, not even by the artificial intelligence assistant integrated into the panel.
2.2.bis Your store's order and catalog data (if you connect an online store)
If you connect your online store (WooCommerce or PrestaShop), Crisol MCP reads, in read-only mode, your catalog data and your order ledger, so that you can analyze your real sales by cross-referencing them with your SEO and advertising data. Specifically:
| Category | What it includes |
|---|---|
| Product catalog | Product identifier and name, SKU, URL, status, type, prices, units sold, stock status, categories and SEO metadata |
| Orders | Order and line identifier, order number and date, status, currency, product identifier, quantities, and amounts (gross, refunded and net of taxes) |
| Buyer identifier | A pseudonymous identifier (an internal number assigned by your own store), which makes it possible to know that two orders belong to the same buyer without identifying who they are |
What we do NOT process. Crisol MCP extracts only a closed, predefined set of fields, and discards the rest of the order at the moment of reading, before any storage. We do not copy, transmit or store any identifying data of the buyer: neither their name, nor their email, nor their phone number, nor their address, nor their NIF, nor their IP address, nor advertising tracking identifiers (such as those that some store plugins might add).
About the pseudonymous buyer identifier. Although Crisol MCP cannot know who the person behind that identifier is, under the GDPR such an identifier is considered pseudonymized personal data (not anonymous), since you, as the store owner and with your own database, could re-identify it. That is why we treat it with the same security and isolation guarantees as the rest of the data, and its processing is further governed by the Data Processing Agreement (Annex I to the Terms), in which you act as controller and Crisol MCP as processor.
Retention periods for this data. The catalog is stored as a snapshot that is replaced on each synchronization (with no time-based expiration: whatever is no longer in your store is deleted). Orders are retained for 180 days and aggregated sales by product and day for 480 days, counted from the date of the order itself (not from the date on which they are copied); after that period, they are automatically deleted. This data is stored isolated per client, in accordance with Section 8.
2.3 Panel AI assistant history
The conversational AI assistant integrated into the panel, which helps you set up your connections and resolve questions about the product (what Crisol MCP does, the plans, the frequently asked questions or the glossary), does not store the content of the conversation on our servers. The history lives exclusively in the browser (local storage), with automatic deletion every 24 hours. The only thing we record in our audit log is technical metadata (date, user and number of tokens consumed), never the content of the messages.
2.4 Activity log (audit log)
For security and traceability reasons, we log certain relevant actions within your account: connecting or disconnecting tools, saving or deleting API keys, enabling or disabling features, submissions to IndexNow, and use of the AI assistant (only the token count). This log never contains the value of any credential, only the type of action performed (for example, "Bing key updated").
2.5 Public contact form
If you fill out the Site's contact form before having an account, we store the name, email and message you provide, so that we can reply to you.
2.6 Waiting list
If access to the Service is not open at the time and you decide to join the waiting list so that we can notify you when a spot becomes available, we process the following data:
| Data | Description |
|---|---|
| Email address | The address to which we will send the notice that a spot is available. It is the only data we ask you for |
| Sign-up date | When you signed up. It also serves as a record of your consent |
| Notice date | When we sent you the notice that a spot was available, if we have already sent it |
What we use it for and on what legal basis. We use it for the sole purpose of notifying you when a spot becomes available. The legal basis is your consent (Article 6(1)(a) GDPR), which you give by checking the box on the sign-up form. We do not use your email to send you commercial communications, newsletters or any communication other than that notice, unless you expressly authorize us to do so separately.
We do not cross-reference it with anything. The waiting list email is stored independently and is not associated with any user account, or with browsing data, or with any other information.
How long we keep it. We keep your email until the first of the following occurs: that you sign up for the Service, that you ask us to remove you from the list, or that 12 months elapse from your sign-up without our having been able to offer you a spot. In any of those cases, your email is deleted.
How to leave the list. You can ask us to delete your email at any time, without giving reasons, by writing to privacidad@crisolmcp.com. We will do so without delay. Withdrawing your consent does not affect the lawfulness of the processing carried out before its withdrawal. You are also entitled to the other rights described in Section 7.
2.7 Website usage analytics (only if you accept it)
If you accept the analytics cookies, we use Google Analytics 4 to understand how our website is used and to improve it.
| Data | Origin |
|---|---|
| Pseudonymous browser identifier | _ga and _ga_G4V3XE55JS cookies, installed by Google only if you give your consent |
| Pages visited, browsing order and origin of the visit | Collected by Google Analytics during your browsing |
| Approximate location (country, region and city) derived from your IP address, and characteristics of your device and browser | Derived by Google Analytics during your browsing. Google does not provide us with your full IP address, and under no circumstances do we obtain your exact location |
Nothing is installed before you accept. If you do not consent, the page we serve you does not contain any Google tag: no analytics cookie is installed and no data is sent, not even anonymously.
What we do not do. We do not use Google Analytics advertising features, or Google Signals, or remarketing, or ad personalization. We do not send Google any identifier linking you to your customer account, so that this data is never cross-referenced with your identity in Crisol MCP.
You can withdraw your consent whenever you want, from the "Cookie preferences" link in the footer of any page. Withdrawal does not affect the lawfulness of the processing carried out before withdrawing it. The full details are in our Cookie Policy.
2 bis. Use of Google API data (Limited Use)
Crisol MCP's use and transfer to any other application of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Crisol MCP uses the information obtained from Google APIs solely to make it available to the artificial intelligence assistant that you connect and control. Two of the four permissions (Search Console and Analytics 4) are read-only. The other two (Google Ads and Merchant Center) are requested in their only available form, since Google does not publish a read-only variant, and Crisol MCP uses them solely to read, without creating, modifying or deleting campaigns, properties, products or configurations. The only write operation that Crisol MCP performs against Google's data APIs is the registration and deregistration of our developer project in Merchant Center (registerGcp / unregisterGcp), a step that Google requires in order to read performance data; it is executed by the user themselves from the panel and does not alter product listings, prices or commercial configuration.
Consistent with the Limited Use requirements, Crisol MCP affirms that the information received from Google APIs:
- Is not used or transferred to display advertising, including personalized, targeted or retargeting advertising.
- Is not sold or transferred to data brokers, information resellers or third parties for commercial purposes unrelated to the provision of the Service.
- Is not used to train, fine-tune or improve artificial intelligence or machine learning models, whether our own or third-party.
- Is not read by humans, except: (a) with your explicit consent for support purposes; (b) for security reasons (for example, investigating abuse); or (c) where required by law.
2 ter. Transfer to your artificial intelligence assistant (MCP connector)
The main purpose of Crisol MCP is to act as an MCP server (Model Context Protocol) that connects your data sources with the artificial intelligence assistant that you choose and control (for example, Claude or ChatGPT).
When your AI assistant requests a query, Crisol MCP performs the read in read-only mode against the corresponding platform (Google, Meta, Bing) and returns the result directly to your AI assistant, which runs outside Crisol MCP and under your control. This transfer of data to your AI assistant is initiated and controlled by you: it is you who decides which assistant to connect and which queries to run.
Under no circumstances does Crisol MCP use your Google data to train, fine-tune or improve artificial intelligence models, whether our own or third-party. When your AI assistant processes the data, it does so under your control and in accordance with its provider's policy; Crisol MCP never sends it for training purposes.
It is important that you understand this architecture:
- Crisol MCP does not process your Google data with any of its own artificial intelligence models. It acts as a channel: it performs the read and delivers the result to your assistant. The analysis is carried out by the model you have connected, over which Crisol MCP has no control and whose data processing is governed by the privacy policy of that assistant's provider (Anthropic, OpenAI, etc.).
- Most queries are performed live, without intermediate storage: the data goes from the source platform to Crisol MCP and from there to your assistant, without passing through any cache.
- There is an optional local cache layer that is only used if you deliberately activate it (via the synchronization tools). In that case, the data is temporarily stored in a local database (SQLite) on our own server, to enable faster recurring analyses. If you never activate this synchronization, no data from your sources passes through that cache. In the case of marketing metrics (for example, clicks, impressions, positions), the cache contains no credentials or personal data. In the case of store data, the cache may contain the pseudonymous buyer identifier described in Section 2.2.bis, but never identifying data or credentials. Unlike credentials, which are always stored encrypted, this cache is not encrypted.
This cache is purged automatically by two mechanisms:
- By expiration (TTL): the data is deleted once it exceeds its retention period (for example, those described in Section 2.2.bis for store data).
-
By your plan's disk quota: if the volume of data you have cached exceeds the size included in your plan, the oldest history is automatically deleted until it fits again. This mechanism affects only search engine performance data (Search Console): it does not touch your store data, or your Analytics, Google Ads or Merchant Center data. It also never retains less than 365 days (one year) of history no matter what, and does not happen silently: you are notified in the response of the synchronization that triggers it.
-
Set-aside files due to a technical incident. Exceptionally, if the local database of your cache were to become corrupted, the system does not delete it: it sets it aside (renames it) and creates a clean database for you on your next access, so as not to destroy data due to a false positive. In that clean database, the retention periods apply again completely normally. The set-aside file is a static copy that is no longer processed; it contains data from your account and is retained until an administrator reviews and deletes it as part of an operational routine (it does not expire on its own). If you cancel your account, that file is deleted along with the rest of your data, within the period committed to in Section 6.
- The only internal AI model in Crisol MCP is the panel assistant described in Section 2.3 (which helps you set up your connections and resolve questions about the product), which only receives metadata about your account: which sources you have connected, your contracted plan and the panel screen you are on. It never receives the data from your sources or your credentials.
2 quater. Meta (Facebook) data and how to delete it
If you connect your Meta (Facebook/Instagram) ads account to Crisol MCP, the only data we store is the access token (System User Token) of your ads account, always stored encrypted at rest with the same treatment described in Section 2.2 (Fernet / AES-128-CBC + HMAC-SHA256 encryption, with the master key outside the database).
We do not store any data from your Facebook or Instagram profile: neither your name, nor your photo, nor your Facebook user identifier, nor your friends list, nor any other personal data from the social network. Meta acts solely as the source platform for the performance metrics of your ads, which Crisol MCP reads in read-only mode and returns to the artificial intelligence assistant that you control, in accordance with Sections 2 ter and 4 of this policy.
You can delete the Meta data we store (your access token) through any of these three routes:
- Immediate disconnection from the panel. On the Meta Ads screen of the Crisol MCP panel you will find a "Disconnect from Crisol" button. When you press it, we immediately delete your encrypted token and stop reading any Meta data. This action does not modify or delete your Meta account; it only cuts off Crisol MCP's access.
- Cancellation of your Crisol MCP account. If you close your account, all your data (including the Meta token) is deleted in accordance with the periods described in Section 6 of this policy.
- Request by email. You can request deletion by writing to privacidad@crisolmcp.com, as described in Section 7 ("Your rights").
3. Why do we process your data? (purposes and legal basis)
| Purpose | Legal basis (GDPR) |
|---|---|
| Manage your account and authenticate you via a magic link to your email | Performance of a contract/service relationship (Art. 6(1)(b)) |
| Manage your paid subscription (status, plan and customer reference in Stripe) | Performance of a contract/service relationship (Art. 6(1)(b)) |
| Provide the Service: allow you to connect your tools and have them queried through AI | Performance of a contract/service relationship (Art. 6(1)(b)) |
| Store in encrypted form the credentials you connect | Performance of a contract/service relationship (Art. 6(1)(b)) |
| Maintain the security audit log | Legitimate interest in ensuring the security of the Service and detecting misuse (Art. 6(1)(f)) |
| Respond to messages from the contact form | Data subject's consent when submitting the form (Art. 6(1)(a)) |
| Notify you when a spot becomes available, if you join the waiting list | Data subject's consent when checking the box on the form (Art. 6(1)(a)) |
| Measure website usage through Google Analytics 4 in order to improve it | Data subject's consent when accepting the analytics cookies (Art. 6(1)(a)) |
| Retain the record of your decision about cookies, in order to be able to demonstrate it | Compliance with a legal obligation (Arts. 6(1)(c) and 7(1)) |
3.1 Automated decisions
We do not carry out automated decisions, including profiling, that produce legal effects on you or similarly significantly affect you. The artificial intelligence assistant integrated into the Service generates analyses and guidance-only recommendations directed at the user who uses it, but it does not make automated decisions about natural persons.
4. Who do we share your data with?
We do not sell or transfer your data to third parties for commercial purposes. We work with the providers listed below. Those that process personal data on behalf of Crisol MCP (OVH, Resend, OpenRouter and, if you accept the analytics cookies, Google Ireland Limited) do so as data processors, under contract and in accordance with our instructions. Google, Meta and Microsoft are not processors of Crisol MCP: they are the source platforms of your own data, which you connect and control, and each one processes the information in accordance with its own privacy policy.
| Provider | Function | Location |
|---|---|---|
| OVH | Server hosting (VPS) | Gravelines, France (EU) |
| Resend | Delivery of the transactional email containing your magic access link. It only processes your email for the purpose of delivering that message | United States, subject to verification of the international transfer mechanism (see Section 5) |
| OpenRouter and the AI model provider to which each query is routed (currently, Google) | Inference of the panel's AI assistant. It only receives metadata about your account: which sources you have connected, your contracted plan and the screen you are on, never credentials or your marketing data | Typically United States, subject to verification of the international transfer mechanism (see Section 5) |
| Google Ireland Limited | Website analytics (Google Analytics 4), only if you accept the analytics cookies. It acts as data processor under Google's Data Processing Terms | Dublin, Ireland (EU) |
| If you connect your accounts, the source of the Search Console, Analytics 4, Ads and Merchant Center data that we query on your behalf in read-only mode | United States / EU depending on the service | |
| Meta, Microsoft (Bing) | Source of the data we query on your behalf, if you connect those tools | United States |
Payment and billing data — independent controller
When you contract a paid plan, Crisol MCP does not receive, store or process any data from your card or your payment method. The entire economic transaction is carried out through Stripe Managed Payments, operated by Stripe Payments Europe, Limited (SPEL), an Irish entity of the Stripe group responsible for processing the data of users located in the European Economic Area (including Spain).
For payment and billing data (name, billing email, payment method, tax address), SPEL acts as data controller independently of Crisol MCP. Crisol MCP does not have access to any of that data at any time. Stripe's Privacy Policy, available at stripe.com/privacy, governs the processing of such data. We recommend that you review it before completing a subscription.
5. International transfers
Some of the above providers (in particular, the transactional email delivery provider Resend, and the AI inference provider of the panel's assistant) may be based in the United States. When this occurs, the transfer relies on the EU-US Data Privacy Framework (if the specific provider is certified) or, failing that, on Standard Contractual Clauses approved by the European Commission. You can ask us for information about the safeguards applied in each case by writing to privacidad@crisolmcp.com.
Website analytics. Our counterparty for Google Analytics 4 is Google Ireland Limited, domiciled in Ireland, so that the analytics data is communicated to a recipient located within the European Union and that communication does not constitute an international transfer. Google Ireland Limited may in turn process that data in the United States through Google LLC as its sub-processor; in that case it is Google that carries out the transfer and is answerable for it, relying on the EU-US Data Privacy Framework (Google LLC is certified) and, where applicable, on the Standard Contractual Clauses provided for in its own Data Processing Terms.
6. Retention period
We retain your data for as long as your account remains active and it is necessary to provide you with the Service.
Account closure or cancellation. When you cancel your subscription or request closure, your account and its data are completely deleted from our system within a maximum of 14 days from the end of your access. Within that process, the deletion of your personal data and credentials in the production database is carried out within a maximum of 48 hours, and the purge of the encrypted backups is completed within a maximum of 7 days, in accordance with the backup retention system of our infrastructure provider (OVH). This includes your identity (email, name, internal account identifier), your subscription management data, the encrypted credentials of the tools you may have connected, the data from your store that we may have cached (catalog, orders and aggregated sales), and the audit log entries associated with your account.
Record of your decision about cookies. The consent record is retained for 36 months from the decision and is then automatically deleted. That period covers the 24 months of validity of the consent plus the time during which we may still be required to demonstrate that we obtained it correctly. If you withdraw your consent, the record is not deleted at that moment: the withdrawal date is noted and it is retained for the same period, because we need to be able to prove both that you consented and that we acted on your withdrawal. This record does not contain your IP address or any data that would make it possible to identify you, and it is independent of the life of your account: it is retained even if you are not a customer, and also after you close your account. The details are in the Cookie Policy.
Analytics data in Google Analytics. The user and event data collected by Google Analytics 4 is retained for 14 months, a period that allows us to compare the evolution of the site over a full annual cycle. Once that period has elapsed, Google deletes it automatically. The standard aggregated reports, which do not make it possible to identify any specific user, are not subject to that period.
Billing records in Stripe. The billing records of your subscriptions are retained by Stripe, in its capacity as legal seller (Merchant of Record), in accordance with its own legal and tax obligations. These records are not under our control and are not deleted by us.
Legal obligations. If there were a legal obligation to retain certain information for a longer period (for example, at the request of a competent authority), we would retain only that specific information for the legally required period, and nothing more.
7. Your rights
As a user, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data when it is no longer necessary.
- Object to the processing or restrict its scope.
- Portability: receive your data in a structured format.
You can exercise these rights by writing to privacidad@crisolmcp.com, attaching a copy of a document that proves your identity. We will respond within one month of receiving your request.
If you consider that we have not properly addressed your request, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
8. Security measures
We apply, among others, the following technical and organizational measures:
- Encryption at rest of all third-party credentials (Fernet/AES-128-CBC + HMAC-SHA256), with a master key separate from the database.
- Strict data isolation between users: one user's data is never accessible to another user.
- The integrated artificial intelligence assistant never accesses real credentials or the data from your sources, only metadata about your account (connected sources, contracted plan and the panel screen you are on).
- A strict Content Security Policy (CSP) in the panel, with no unauthorized third-party JavaScript.
- Encrypted communications (HTTPS) across the entire Site and panel.
9. Minors
The Service is directed at people who manage digital assets (websites, campaigns, online stores), whether for professional or personal purposes, and its use is reserved for adults, in accordance with Clause 3 of the Terms and Conditions. We do not knowingly collect data from minors; if we detect that an account has been created in a minor's name, we will delete it.
10. Changes to this policy
We may update this Privacy Policy to adapt it to regulatory changes or changes to the Service itself. We recommend that you review it periodically. The date of the last update appears at the end of this document.
This is a courtesy translation of the Spanish original. In the event of any discrepancy, the Spanish version published at https://crisolmcp.com/legal/privacy prevails.