Claude, ChatGPT and MCP clients

AI connector privacy policy

What the Communik connector receives when an AI assistant edits your website for you, what it keeps, and how to switch it off. It complements our general privacy policy.

Last updated: 1 October 2026GDPR, French Data Protection Act

The short version

  • The connector only receives what the assistant sends to run an action: the tool name and its parameters.
  • It never receives your conversation history, your assistant's memory or files, or your Claude or ChatGPT credentials.
  • It can only reach the Communik sites you are a member of.
  • It publishes to a private preview by default. Your site goes publicly live only when you ask for it.
  • It cannot refund, charge or move money.
  • You can disconnect it at any time; its access tokens are then revoked.

Who is responsible

The Communik connector is published by Webevolutis, a French SARL with a share capital of 3,000 euros, registered under RCS Bordeaux 480 535 251 (SIRET 480 535 251 00049, VAT FR10480535251), whose registered office is 5 allée des Douves, 33470 Gujan-Mestras, France. Webevolutis is the data controller for the processing described here.

The connector lets an AI assistant compatible with the Model Context Protocol (Claude, ChatGPT and others) create, edit and publish the websites you manage on Communik, on your behalf and with your authorization. Privacy questions go to jeremy@communik.io.

What the connector processes

Account identity
Your Communik account identifier, and your email address when you sign in to approve the connection. Used to authenticate you and to limit access to your own sites.
Access tokens
An access token valid for one hour, and a refresh token valid for 60 days, stored only as a hash. Both are bound to your account and to the Communik connector.
Registered application
The name of the application you approved (for example Claude or ChatGPT) and its redirect addresses.
Content of your sites
The pages, texts, images, collections and settings the assistant reads or changes at your request, exactly as you would in the editor. This content is already hosted by Communik.
Technical log
For each call: the tool name, the account, the site, success or failure, the error code and the duration. The parameters of the call are not logged. Used for security, troubleshooting and usage statistics.
Connection data
IP address, date and time of requests. Used for rate limiting and security.

Legal basis: performance of the contract between you and us, and our legitimate interest in keeping the service secure. The data is not used to train AI models, not sold and not used for advertising.

Who else receives it

The connector relies on the providers listed in our general privacy policy, and only as needed for the action you request: hosting of the platform and databases, Cloudflare for media storage, Postmark for your site's emails if you enable them, Stripe for your site's payments if you enable them, and Google Fonts, which only receives the name of a font when you change your theme.

The AI assistant you use (Anthropic for Claude, OpenAI for ChatGPT, or another provider) receives the results of the tools it calls, under its own terms and privacy policy. Communik does not control that processing.

How long we keep it

Access token
One hour.
Refresh token
60 days, or until you disconnect the connector.
Technical log and connection data
12 months at most, then deleted.
Content of your sites
For as long as your account is open, as described in our general privacy policy. The history of changes (the previous state of each edited item, kept so that a change can be undone) is kept 30 days, and at most the last 500 changes per site.

Your controls and your rights

  • Disconnect the connector at any time from the connector settings of Claude or ChatGPT, or by writing to us: its tokens are revoked.
  • Every publication goes to a private preview first. Going publicly live requires your explicit request.
  • A deleted block goes to a trash and can be restored.

Under the GDPR and the French Data Protection Act, you may ask for access to your data, its correction or deletion, a portable copy, or the restriction of a processing, and you may object to a processing based on our legitimate interest. Write to jeremy@communik.io; we answer within one month. You can also lodge a complaint with the CNIL (www.cnil.fr).

Security

All traffic is encrypted (HTTPS). Authentication uses OAuth 2.1 with PKCE, tokens are bound to your account and to the Communik connector, and every call is checked against your membership of the site concerned.

Children, and changes to this policy

The connector is intended for professionals and not for people under 15.

We update this policy when the connector changes. The date at the top always reflects the current version.