Skip to main content

Optmyzr MCP Integration - Data Privacy & Security

Written by Radhika Shenoy

Optmyzr MCP Server

How the MCP Integration Works

1. What is the Optmyzr MCP server?

Optmyzr runs an MCP (Model Context Protocol) server that exposes your ad account data and Optmyzr tools to AI clients. This allows AI assistants to read campaign data, run analyses, and take actions within Optmyzr on your behalf.

2. Which AI clients can connect to it?

Any MCP-compatible AI client can connect — including Claude Desktop, Claude Code, ChatGPT (with MCP support), Cursor, and others. Optmyzr does not restrict which client you use. The choice of AI client is yours.

3. Is Anthropic involved in the MCP integration?

Not directly. Optmyzr’s MCP server does not send data to Anthropic. If you choose to use a Claude-based client (e.g. Claude Desktop) to connect to Optmyzr’s MCP, any data that passes through that client is governed by your relationship with Anthropic under your Anthropic terms — not Optmyzr’s. The same principle applies to any other AI client you choose: OpenAI, Microsoft, or otherwise.

4. Who is responsible for data once it leaves Optmyzr’s MCP server?

Once data is transmitted to your chosen AI client, the data handling obligations belong to that client’s provider — under your agreement with them. Optmyzr recommends customers review the data handling terms of their chosen AI client before connecting it to Optmyzr.

Data Access & Scope

1. What data does the Optmyzr MCP server expose?

The MCP server exposes the ad account data and Optmyzr tools that your account has access to. This includes campaign performance data, settings, and the ability to run Optmyzr tools depending on which MCP tools are enabled. See the full list of supported tools and functions here.

2. Does connecting an AI client give it access to all of my accounts?

Access is determined by the accounts linked to your Optmyzr instance. When an AI client connects via MCP, it can access the accounts that Optmyzr already has permission to manage on your behalf.

3. Does the MCP expose personal or sensitive data (e.g. customer audience lists)?

Whether personal data is surfaced depends on the contents of your ad accounts. For example, if your account contains customer match lists or audience data that includes personal information, this data may be accessible through the MCP.

Authentication & Security

1. How do AI clients authenticate with Optmyzr’s MCP server?

AI clients must authenticate with Optmyzr’s MCP server before accessing any data. Access is controlled by Optmyzr’s authentication mechanism. You can read about how to generate an API key and set up the Optmyzr MCP here.

2. Does Optmyzr log requests made to the MCP server?

Optmyzr maintains server-side logs indefinitely for operational and security purposes. We only store the query and related metadata, like the tools called, response time, etc.

Optmyzr’s Internal AI Features (OpenAI)

How Optmyzr Uses AI Internally

1. Does Optmyzr use AI for any of its own features?

Yes, Optmyzr makes server-side LLM calls to power certain product features, such as ad text generation and automated insights. These calls are made directly by Optmyzr’s servers and are separate from the MCP integration.

2. Which AI provider does Optmyzr use for these features?

Optmyzr currently uses the OpenAI API for its internal AI features. OpenAI is a subprocessor in this data flow. Anthropic is not involved in Optmyzr’s internal AI features.

Data Handling & Privacy

1. What data does Optmyzr send to OpenAI?

When you use Optmyzr features powered by AI, relevant portions of your ad account data are sent to OpenAI’s API to generate a response. This data is used only for the purpose of generating your requested output and is not used to train OpenAI’s models under the API terms.

2. Does OpenAI use our data to train its models?

Under OpenAI’s API terms, data submitted via the API is not used to train OpenAI’s models by default. This is distinct from OpenAI’s consumer products (ChatGPT Free/Plus), which have different terms.

3. How long does OpenAI retain data sent by Optmyzr?

Data sent to OpenAI via Optmyzr's internal AI features is handled in accordance with OpenAI's API data usage policies. For details on retention periods and data handling, please refer to OpenAI's business data privacy page. If your organisation has specific contractual requirements around retention, please raise these with your IT or legal team in conjunction with OpenAI's enterprise sales.

General Security & Vendor Due Diligence

1. What happens in the event of a data breach?

Optmyzr has an incident response plan in place. In the event of a data breach, affected customers are notified in accordance with GDPR requirements and applicable contractual obligations.

2. Can we complete a vendor security questionnaire (VSA/SIG) for Optmyzr?

Yes. If your organisation requires a completed vendor security questionnaire as part of onboarding or an annual review, please contact support@optmyzr.com. We can provide responses to standard questionnaires or work with your IT/security team on a custom one.

Did this answer your question?