Competiscan
AI Privacy Policy
This AI Privacy Policy describes how Competiscan (“we,” “us,”
or “our”) collects, uses, and protects information in connection with
the Competiscan MCP server (the “MCP Server”) — the Model
Context Protocol interface that exposes our direct mail archive as tools
(search_campaigns, read_piece,
discover_filters) to Claude and other MCP clients. This policy
supplements our general Privacy Policy.
Where the underlying data comes from.
Competiscan’s direct mail archive is built from a panel of individuals
across the United States who forward the marketing mail they receive to
Competiscan. Personally identifiable information on each piece — such as
the panelist’s name and address — is redacted before a piece is
catalogued, so the archive these tools search and read from does not carry
panelist PII.
Information We Collect
- Archive Data. The direct mail campaign archive the MCP Server
searches and reads from — including OCR-extracted text and campaign
metadata — is collected in advance through the panelist network
described above, and already resides in our database before any tool is
called.
- Tool Call Data. When you or your MCP client call a tool, we
receive the arguments you submit — such as search filters, date
ranges, company names, OCR search terms, or entry IDs — in order to
run the request and return matching results.
- Account & Authentication Data. Each request is tied to an
API key or a Cognito-authenticated identity linked to a Competiscan
account, including the account name, tier, and monthly quota.
- Request Metadata. For every call, we log operational details
— timestamp, the tool and endpoint called, response time, row count,
status code, IP address, and user agent — to authenticate requests,
enforce rate limits and quotas, and secure the service.
How We Use The Information
- Fulfilling Tool Calls. Arguments you submit are used only to run
the requested search, read, or filter-discovery operation against the
archive and return the result to you.
- Authentication & Quota Enforcement. Account and request
metadata authenticate each call and enforce your service tier’s rate
limits and monthly quota.
- Service Operation, Monitoring & Security. Request metadata
helps us monitor performance, investigate errors, detect abuse, and secure
the service.
- Your Account Portal. Aggregated usage figures — calls
made, quota remaining, and recent call history — are shown back to
you in your account portal.
- Compliance. We may use this information to comply with
applicable laws and regulations and to respond to legal process.
Data Security
We implement reasonable and appropriate security measures to protect your
information from unauthorized access, use, or disclosure. These measures
include encryption, access controls, and secure server infrastructure.
However, no method of transmission over the internet, or method of
electronic storage, is 100% secure.
Specifically, our infrastructure is built on Amazon Web Services with security controls at each layer:
- Encrypted in transit. All traffic is served over HTTPS, with
certificates issued and rotated automatically through AWS Certificate
Manager.
- Network isolation. The application and data layers run inside a
private virtual network (VPC) and are not directly reachable from the
public internet.
- Authenticated access. Every request is authenticated by a
managed identity provider before it reaches the application layer.
- Encrypted at rest. Stored documents and data are held in
access-controlled, encrypted AWS data stores.
- No model training on your data. Tool arguments and results are
used only to serve your request — they are not used to train any AI
model, ours or a third party’s.
Data Retention
- Archive Data. Retained indefinitely as part of Competiscan’s
ongoing direct mail archive, per our general Privacy Policy.
- Tool Call Arguments & Request Metadata. Retained for as long
as needed to operate the service — including quota enforcement, the
usage history shown in your account portal, and investigating security
incidents — after which it is deleted or aggregated.
- Account Data. Retained for as long as your account is active,
and for a limited period afterward as required for billing, legal, or
security purposes.
Data Sharing
We do not sell tool call arguments or request metadata. We do not share
them with third parties except as required by law, to comply with legal
process, or with service providers — such as our cloud infrastructure
provider — who process it on our behalf under confidentiality
obligations. The archive data returned by the MCP Server is subject to the
data-sharing provisions of our general Privacy Policy and your Competiscan
subscription agreement.
User Control
Using the MCP Server is opt-in: it requires a Competiscan API key or a
Cognito-authenticated sign-in, and you control which tool calls your MCP
client makes. You can revoke access at any time by rotating or deleting
your API key from your account portal, or by contacting us.
Changes to This Privacy Policy
We may update this AI Privacy Policy from time to time. We will notify you
of any material changes by email.
Questions or Concerns
If you have any questions or concerns regarding our AI Privacy Policy,
please do not hesitate to contact us at: