Privacy Policy
Last updated: August 28, 2026
This is an English translation provided for convenience; the French version prevails.
Alpative MCP ("we", "the service") is a service published by Alpative that lets a user connect their own accounts (Google and others) to their AI assistant in order to analyze them in read mode and, if they explicitly enable it, to perform certain actions at their request. This policy explains which data we process and how.
1. Data controller
Alpative, contact: contact@alpative.com.
2. Google data we access
When you connect a Google account, you explicitly authorize us, through the Google consent screen, to access the data listed below, solely to return it to your AI assistant at your request. Access is read-only by default; write permissions are only used under the conditions described in section 3.
analytics.readonly: Google Analytics 4 reports, to generate your audience and conversion analyses. Read-only.webmasters.readonly: Google Search Console data, for your SEO analyses (clicks, impressions, positions, URL inspection). Read-only.business.manage: Google Business Profile listings, reviews and statistics, for your local visibility analyses. We use it read-only: Alpative MCP does not edit your listings and does not post replies to reviews.adwords: Google Ads reports, for your advertising performance analyses. Read by default; actions (pausing a campaign, adjusting a budget, applying a recommendation) fall under section 3.spreadsheets: read and write access to the Google Sheets spreadsheets you designate, to read from them or export your reports to them. We have no access to your Drive file list: you provide the ID of the spreadsheet concerned.tagmanager.readonly: read the configuration of your Google Tag Manager containers (tags, triggers, variables, versions), to audit your tracking. Read-only.tagmanager.edit.containers: create or edit tags, triggers and variables in a workspace (draft), at your request. A draft has no effect on your website until it is published.tagmanager.publish: publish a Google Tag Manager version or workspace, that is, put the configuration live on your website. See the conditions in section 3.
We do not access any other Google data. All operations are triggered by you, through your AI assistant.
3. Write actions and publishing (Actions mode)
No write action, and no publishing, is ever performed automatically, silently, or as a side effect of another request. An action is only possible when all four of the following conditions are met:
- your plan allows it (actions belong to the Expert plan);
- Actions mode is enabled in your Alpative console: it is off by default, and you can turn it off again at any time;
- you explicitly ask your AI assistant to perform the operation;
- for a Google Tag Manager publication, you additionally confirm the operation: the assistant must obtain your explicit approval before going live.
In practice, your assistant can prepare a tracking fix in a GTM draft, show it to you, then publish it only after your approval. Every publication is logged on your account. Without Actions mode, the service stays strictly read-only.
4. Limited Use (Google user data policy)
Alpative's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we only use Google data to provide and improve user-facing features; we do not transfer it to third parties except to your AI assistant, at your request, or if required by law; we never use it for advertising purposes; we do not sell it; it is not used to train artificial intelligence models; and no human reads it, except with your explicit consent, for security/compliance reasons, or if required by law.
5. Other services you can connect
Alpative MCP also lets you connect non-Google services. As with Google, the connection is triggered by you, access is limited to the accounts you authorize, and the data is only used to answer your requests:
- Meta (Facebook, Instagram): advertising statistics and organic statistics for the Pages and Instagram accounts you authorize. Read-only.
- LinkedIn: campaign reporting, ad library, page statistics. Publishing a post falls under the Actions mode described in section 3.
- TikTok Ads and Microsoft Ads: reporting on your campaigns. Read-only.
- Bing Webmaster Tools: search data for your sites and URL submission for indexing (submission falls under Actions mode). The connection uses an API key you provide; it is encrypted at rest.
- PageSpeed Insights: performance measurement of a public URL you provide. No account to connect.
Data from these services is never sold, never used for advertising, and never used to train models.
6. Your Alpative account data
To run the service, we also process:
- Account and authentication: your email address, your name if your sign-in method provides one, and your console language. Authentication is handled by our processor Clerk; we store no passwords.
- Connected accounts: the OAuth tokens (or API keys) for each service you connect, encrypted at rest, plus a label for the account so you can recognize it in your console.
- Usage log: for each call, the name of the tool used and its timestamp, in order to count your monthly quota and display it to you. We do not record your questions, the answers, or the content of your reports.
- Subscription and payment: your plan, its status and any quota purchases. Payments are processed by Stripe: we neither see nor store your card details.
- Agent keys (optional): if you create a key for a browser-less agent, only its fingerprint (hash) is stored, never the key itself. You can revoke it at any time.
- Account memory (Expert plan, optional): the context notes you ask your assistant to remember (for example your goals or naming conventions) and the log of actions performed. This memory is yours: you can read it and delete it from your assistant or on request.
7. Retention and storage
OAuth tokens and API keys are encrypted at rest (AES-256-GCM) on our servers located in the European Union (Hetzner Online GmbH, Nuremberg data centre, Germany). We do not store your reports: they pass through to your AI assistant and are not retained. The usage log (tool name and timestamp, with no content) is kept for 13 months, then deleted automatically: that period covers your quota calculation, a possible dispute over an annual invoice, and year-on-year comparison. Other account data is kept for as long as your account exists, then deleted when it is closed. Your account memory and your action log are never deleted automatically: they are yours, and you erase them whenever you want from your console or your assistant. You can revoke access at any time from your Google account (myaccount.google.com/permissions), from each other service's own settings, from your Alpative console, or by contacting us; disconnecting deletes our tokens.
8. Sharing and processors
We do not sell or rent your data. It is shared with the AI assistant you connect, at your request, and with the technical processors strictly necessary to run the service:
- Clerk, Inc. (660 King Street, San Francisco, California, USA): authentication and account management (email address, sign-in identifiers, IP address and device information). Clerk hosts this data on Google Cloud and Cloudflare. Their own sub-processors.
- Stripe Payments Europe, Limited (3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland): payments and subscriptions. Card details are handled by Stripe, never by us. Their own sub-processors.
- Hetzner Online GmbH: hosting of our servers and database, Nuremberg data centre (Germany), within the European Union.
We may also disclose data if required by law. No other sharing takes place.
9. Transfers outside the European Union
Your marketing data and your connection tokens stay in the European Union: they are hosted on our servers in Germany. Two ancillary processing activities do involve transfers to the United States, in both cases covered by the provider's certification under the EU-U.S. Data Privacy Framework and, failing that, by the European Commission's Standard Contractual Clauses:
- Authentication (Clerk, Inc., a company established in the United States): email address, sign-in identifiers, IP address, device information.
- Payment: our contract is with the Irish entity Stripe Payments Europe, Limited; some operations may involve a transfer to Stripe in the United States (fraud prevention, regulatory obligations).
Your Google data, and the data from the other services you connect, is never transferred to these providers: it only travels between the service concerned, our European servers and the AI assistant you chose.
10. Your rights (GDPR)
You have the right to access, rectify, erase and port your data. To exercise these rights: contact@alpative.com.