AI Connector

Security & privacy

What the AI Connector can access, how it’s protected, and how to shut it off.

What it can access

Read-only access to one company’s data: appointments, payments, payouts, quotes, customers, and business reports. It cannot create, edit, or delete anything, and it can never see another company’s data.

How it’s protected

  • Every request is authenticated by a token that maps to exactly one company.
  • Tokens are stored hashed, shown once, and revocable — access ends within a minute.
  • Every lookup is rate-limited and written to an audit log (which tool ran, when, and how many rows — never the data itself).
  • All traffic is served over HTTPS; tokens are never accepted over plain HTTP.

Turn it off

Revoke any token from Settings → API & Developer, or downgrade below Scale to disable the connector entirely.

This page is the public disclosure for the AI Connector — the same information Apple’s App Store review and the Claude connector directory ask for.