ProjectSend Cloud — Privacy Policy: AI connectors
DRAFT — September 2026. Working draft for legal review. Bracketed items require business or legal decisions. This section supplements the Privacy Policy and does not replace it.
Effective date: [DATE]
This section describes what happens to your data when you connect an AI assistant (Claude, ChatGPT, Claude Code, Cursor, an automation tool, or an agent you run yourself) to your ProjectSend Cloud account through our connector. It applies to the hosted Service operated by Gallifrey AI Inc. only. Self-hosted ProjectSend installations do not include the connector.
1. What the connection is
The connector lets an assistant you choose operate your account on your behalf, with your explicit approval, through an open protocol (the Model Context Protocol). You authorise it on a page of your own ProjectSend site, after signing in and confirming your password. Nothing is shared with any assistant until you do, and you can end the connection at any time (section 7).
2. What the assistant can see and do
Free account. Your own files (names, sizes, dates), the private link of each, whether and when a link was downloaded, and how much space you have used. The assistant can save and upload files, get their private links, stop a link and delete a file. It only ever reaches your own files, never another account's. Files on the free plan are kept for 30 days after they are uploaded, as the Terms describe.
Pro and Business portal. What you choose when you approve it:
- Read: list files, links, download records and client accounts, as you see them on the web. Nothing changes.
- Operate: also save and upload files, share and revoke links, delete files, create client accounts and send them files.
The assistant never gets more than your own account's permissions allow. If your role on the portal changes, what the assistant can do changes with it.
3. What the connection never returns
The connector does not return the contents of your files to the assistant. It works with names, sizes, links and records, not with the bytes of a file. What you ask the assistant to save or upload does reach us, exactly like a file you upload yourself, and is Customer Content under section 1 of the Privacy Policy.
4. Your AI provider
The assistant's replies are generated by the AI provider you chose (for example Anthropic for Claude, or OpenAI for ChatGPT), under that provider's terms and privacy policy. That provider is not our subprocessor: we do not send your data to it. You do, by using an assistant with your account. What the assistant receives from the connector (file names, sizes, links, download records and, on Pro and Business, client names and email addresses) is handled by the provider as its own terms say.
If you are a Pro or Business customer, the data of your clients (End Users) in your portal is yours to control. Sharing it with an AI provider through the connector is your decision as the controller of that data, and your responsibility towards your clients.
5. What we store
- The assistant's registration: the name it presented, its identity (the public address where it publishes its details, when it has one) and the address your browser returns to after you approve.
- The connection: the credentials issued to the assistant, stored hashed; the access you granted (read, operate, or your own files); when it was created and when it was last used.
- Every action the assistant takes, in your account's activity log, marked as done by your AI assistant, with the assistant's name. Connecting and disconnecting are recorded too. No IP addresses are shown to the assistant.
- Where your account came from, if you created it from a link an assistant gave you (section 8).
6. Retention
- Authorisation codes: 60 seconds, single use.
- Access credentials: 1 hour, renewed automatically while the connection is live.
- A connection: 30 days from its last use. After that it expires and the assistant has to be connected again.
- A registered assistant with no live connection: 90 days.
- Expired credentials and connections are removed by a daily job.
- Activity log entries follow the audit history of your plan [Pro: 1 year; Business: as published on the plans page].
7. Ending a connection
Settings → AI connections in your ProjectSend site lists every assistant you have connected, what it may do and when it was last used. Disconnect takes effect immediately: the assistant's next request is refused. Removing the connector on the assistant's side does not by itself revoke the credentials on our side; disconnecting on our side does. Activity log entries remain, as a record of what happened in your account.
8. Sign-up attribution
When an assistant hands you a link to create a ProjectSend Cloud account or to choose a paid plan, the link carries tags saying that it came from an assistant and which one. We store those tags with the account to count how many accounts reached us through assistants. They do not grant, price or gate anything.
9. No model training
We do not use Customer Content, your files or the assistant's requests to train AI models, and the connector may not be used for that purpose.
10. Directories and listings
The connector may be listed in the directories of assistant providers [for example Anthropic's connector directory, OpenAI's plugin directory, or the official MCP registry]. A listing lets those providers show the connector to their users; it gives them no access to your account. [Confirm wording with counsel.]
11. Contact
Questions about this section: [[email protected] — mailbox to be set up before publication]. Requests about your personal data follow section 7 of the Privacy Policy.