Skip to main content

Security and privacy

Access controls

  • Every request is authenticated. You sign in with your UXCam account.

  • Every request is checked against your UXCam permissions. Your assistant can only reach apps you can access in UXCam, and cannot read anyone else's.

  • The connector is read-only. It cannot change your account, apps or settings.

Your data and your AI provider

When you use the MCP, the UXCam data your assistant retrieves is sent to your AI provider (for example Anthropic, OpenAI or Cursor) to answer your question. Review your provider's data handling policies before you connect, especially for apps that record personal data.

HIPAA compliance:

The UXCam MCP server does not currently support HIPAA requirements. UXCam’s Business Associate Agreement (BAA) does not cover data transmitted or processed via MCP endpoints or third-party AI agent environments. Customers handling Protected Health Information (PHI) should evaluate their AI toolchains independently before enabling MCP integrations.

Other things to consider

  • Some results include user identifiers, such as a user's alias or ID on a session. Treat assistant conversations that contain them with the same care as the UXCam dashboard.

  • In a shared AI workspace, your teammates may be able to see your conversation history.

  • Check any compliance requirements that apply to you (for example GDPR or CCPA) before connecting apps that hold personal data.

Did this answer your question?