Mailercloud for ChatGPT and AI Assistants: Privacy Notice
Last updated: October 8, 2026
This notice explains how the Mailercloud app for ChatGPT and other AI assistants (the "App") handles data. The App connects an AI assistant to your Mailercloud account through the Model Context Protocol (MCP). This notice adds to our main Privacy Policy , our Data Processing Agreement and our Sub-processor list . If this notice and the main Privacy Policy conflict on how the App handles data, this notice applies.
1. What the App does
When you ask your AI assistant to work with Mailercloud, the assistant calls the App's tools. Each tool reads or changes data in your own Mailercloud account, using your account's permissions. For example, the App can list campaigns, create a contact or send a test email.
2. Who is responsible for what
- Your account and connection data. Mailercloud is the controller for your account details, your connection credentials and our server logs.
- Your contacts' data. You control your contacts' data. When you use the App with it, you choose to share it with your AI assistant provider, and you are responsible for having a lawful basis to do so. Mailercloud processes that data on your instructions under our Data Processing Agreement.
3. Data the App receives (tool inputs)
The assistant sends the App only what a tool needs to carry out your request:
- Contact details: email address, first and last name, phone number, company, job title, department, city, state, country, tags, and values for custom fields you have defined in your account.
- Campaign and template content: campaign name, subject, preheader, HTML or text content, sender and reply-to addresses, schedule time, and list, segment or tag IDs.
- Email recipients: addresses you ask the App to send a test or transactional email to, plus CC, BCC and reply-to addresses, and attachment links.
- Webhook settings: webhook name, destination URL and events.
- Suppression entries: email addresses you add to or remove from your suppression list.
- Search filters: dates, IDs, search terms and page numbers.
Sensitive data. The contact tools accept only the fields listed above. Custom fields and email content are free text, though, so please don't put sensitive personal data in them. That includes health information, biometric data, government ID numbers, payment card details and passwords.
Your API key. Some tools accept your Mailercloud API key as an input. Connect through the App's sign-in page instead of pasting your key into a chat. Anything you type in a chat is shared with your AI assistant provider.
4. Data the App returns (tool outputs)
Tool results go back to your AI assistant so it can answer you. Depending on the tool, they can include:
- Contact data: contact ID, email address, name, phone number, company, job title and location.
- Account data: your account name and email, plan name and contact usage.
- Campaign and automation data:
- campaign, automation, step and trigger names;
- subjects and statuses;
- send, delivery, open, click, bounce, unsubscribe and complaint counts and rates;
- inbox-placement percentages by provider;
- per-recipient-domain statistics (domain names and counts only, not individual addresses).
- Sender settings: verified sender names and email addresses, and reply-to addresses.
- Templates: template names, categories and full template content.
- Webhooks: webhook names, URLs, events and status.
- Suppressions: suppressed email addresses, the reason, the scope, the date added and the receiving server's response text.
- Lists, segments, tags, custom fields and web forms: names, IDs and counts.
The App's MCP tools return only the fields listed above. Developers who use the App's REST interface receive the Mailercloud API's standard responses for the endpoints they call.
5. Why we use it
We use App data only to carry out the requests you make through your AI assistant, and to keep the App secure and working. We do not use App data for advertising, we do not sell it, and we do not use it to train AI models.
6. Who receives it
- Your AI assistant provider. Tool results go to the assistant you connected, for example OpenAI (ChatGPT). Other assistants you choose to connect, such as Claude or Cursor, are run by their own providers. Your AI assistant provider is not a Mailercloud sub-processor. Its own terms and privacy policy cover how it handles your data, including whether it keeps the data or uses it to train its models, which may depend on your settings with that provider.
- Mailercloud. Our servers process each request through the Mailercloud API.
- Webhook destinations and email recipients. If you create or enable a webhook, or send an email, the data goes to the destinations or recipients you chose.
7. International transfers
Your AI assistant provider may process data outside your country, for example in the United States. Our main Privacy Policy explains how Mailercloud protects personal data when it is transferred internationally.
8. Storage and retention
- Connection credentials. When you connect the App, you sign in on our authorization page with your Mailercloud API key. We store that key, together with your access token, on servers with restricted access, so the App can act for you.
- Access tokens expire after 1 hour. Refresh tokens expire after 90 days. Expired tokens can no longer be used.
- Server logs. We log the request method, path, status and duration, and a masked preview of your API key (its first and last 4 characters). We do not log the content of requests or responses.
- Logs are kept for a limited period and are deleted automatically as storage rotates.
- Your Mailercloud data. Data you create or change through the App is stored in your Mailercloud account and handled under our main Privacy Policy.
9. Your controls
- Disconnect. You can disconnect the App in your AI assistant's settings. In ChatGPT, this is under Settings → Apps & Connectors. Disconnecting stops the assistant from using the App. It does not delete the credential stored on our server.
- Revoke access immediately. In Mailercloud, go to Account → Integrations → API Keys and delete the API key you used to connect. The App stops working at once. Create a new key to reconnect.
- Delete stored credentials. Email [email protected] and we will delete the App credentials and tokens we hold for you.
- Your other rights. You can also use the rights in our main Privacy Policy, including access, correction, deletion and objection. If your contacts ask about their data, we will help you respond as described in our Data Processing Agreement.
10. Children
The App is not intended for anyone under 18.
11. Changes to this notice
We may update this notice. When we do, we will change the "Last updated" date. For material changes, we will also email the account owner at least 14 days before the changes take effect.
12. Contact
For questions about this notice, email [email protected].
Grow with Mailercloud
Try mailercloud for a simplified and empowering email marketing journey.
Already have an account ? Log in