Privacy policy
Last modified on August 26th, 2026
This policy describes the data handled by the BeBranded MCP Connector, available at https://mcp.bebranded.xyz. It covers this service only.
1. Who we are
BeBranded SAS, a company with capital of 10 000 euros, registered with the BOBIGNY Trade and Companies Register under SIREN number 984 530 212, whose registered office is located at 34 Avenue Chanzy, 93250 Villemomble, France, represented by Maxime Konzelmann, duly authorised.
For any question or request about your data: [email protected]
2. What the connector does
The connector is a bridge between your AI assistant (Claude, or any other MCP-compatible client) and your own Google Search Console and Google Analytics 4 accounts.
You sign in on our portal, you authorise access to your Google accounts once, and your assistant can then query your data — only yours, and only the properties the Google account you signed in with can already reach. The connector never widens your permissions; it borrows them.
The Google data you ask for — impressions, clicks, sessions, pages — passes through our server on its way back to your assistant. It is never written to our database, never kept after the response, and never used for anything else.
3. Data we keep
What the usage counters do — and do not — contain
A counter is one row: account, day, Google product, name of the tool called, number of calls, number of errors. No query parameters, no property identifiers, no results. We can see that an account ran the GA4 report tool forty times on Tuesday; we cannot see what it asked for, or what Google answered.
What we do not collect
No cookies, no trackers, no analytics on the portal. The service collects no IP address for analytics purposes and no browsing data, and performs no profiling or automated decision-making.
4. Access to your Google data
The connector requests exactly three Google permissions, and nothing else:
Two technical permissions complete the list (openid and your Google account email address). They exist solely to know which account a connection belongs to.
Actions that actually change something on your side — submitting a sitemap, creating a GA4 dimension, deleting an item — happen only when you explicitly ask for them in the conversation.
Google Limited Use disclosure
The BeBranded MCP Connector's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, data from your Google accounts:
- is used only to answer the requests you make from your AI assistant;
- is never sold, transferred, or used for advertising purposes;
- is never used to train artificial intelligence models, generalised or otherwise;
- is read by a human at BeBranded in three cases only: with your explicit consent, to comply with a legal obligation, or where strictly necessary for security operations (incident response, abuse prevention).
5. Where your data goes
We do not sell or share your data. It is processed by a deliberately small set of technical providers:
Transfers outside the European Union. The server that runs your requests is hosted in the United States: your session identifiers and the Google data you request pass through it for the duration of processing, without being stored there. The database itself stays in France. These transfers rely on the European Commission's Standard Contractual Clauses concluded with those providers.
Your AI assistant. The data you request is returned to the MCP client you connected — Claude or another. What that client does with it is governed by its own privacy policy, over which BeBranded has no control. You decide which assistant you open the connector to.
6. Security
- The database is reachable only by the connector's server: row-level security is enabled with no public policy, which rules out any access other than our own service.
- Passwords are stored only as a salted cryptographic hash, never in clear text and never reversibly.
- Every access token we issue is signed and bound to one account: two connected clients are structurally unable to see each other's data.
- All traffic is encrypted in transit (HTTPS/TLS).
- An account is temporarily locked after repeated failed sign-in attempts.
In the event of a data breach likely to create a risk to your rights, we notify the CNIL within 72 hours and inform you without delay where the risk is high.
7. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. Write to [email protected] and we will answer within one month.
Revoking access to your Google accounts — at any time, without going through us: visit myaccount.google.com/permissions and revoke access for the BeBranded MCP Connector. Revocation takes effect immediately on Google's side; write to us as well if you would like the now-unusable token erased from our database.
Deleting your account: an email is enough. We erase the account, the associated Google tokens and the usage counters attached to it.
You may also lodge a complaint with the CNIL, the French data protection authority (cnil.fr).
8. Changes
Any change to this policy will be published on this page with an updated date. A change affecting the nature of the data processed, or the Google permissions requested, will be notified to you by email before it takes effect.