AI Connector
Security & privacy
What the AI Connector can access, how it’s protected, and how to shut it off.
What it can access
Read-only access to one company’s data: appointments, payments, payouts, quotes, customers, and business reports. It cannot create, edit, or delete anything, and it can never see another company’s data.
How it’s protected
- Every request is authenticated by a token that maps to exactly one company.
- Tokens are stored hashed, shown once, and revocable — access ends within a minute.
- Every lookup is rate-limited and written to an audit log (which tool ran, when, and how many rows — never the data itself).
- All traffic is served over HTTPS; tokens are never accepted over plain HTTP.
Turn it off
Revoke any token from Settings → API & Developer, or downgrade below Scale to disable the connector entirely.
This page is the public disclosure for the AI Connector — the same information Apple’s App Store review and the Claude connector directory ask for.
