Privacy Policy
Last updated: 2026-08-16
1. Scope
This policy describes what connacto ("we", "us") collects when you use connacto.com, our API, and our MCP server (the "Service"), and what we do with it. It is part of our Terms of Service.
2. What we collect
Account data. Your name, email address, and a hash of your password. If you sign in with Google, we receive your name, email, and profile image from Google; we never see your Google password.
Content you store. The entries written to your databases through our tools, and any photos you attach. This is whatever you or your AI assistant choose to log. It can include information you consider sensitive, such as diet, body metrics, or spending; we store it only to show it back to you.
Billing data. Payments are processed by Stripe. We store your Stripe customer ID and subscription status; we never see or store card numbers.
Technical data. Standard server logs (IP address, user agent, timestamps) and a session cookie used to keep you signed in.
3. How we use it
- to operate the Service: store your entries and return them when asked;
- to authenticate you and secure your account;
- to process subscription payments;
- to send transactional email such as password resets;
- to send a periodic digest email summarizing what you logged, if you have that turned on;
- to debug problems and prevent abuse.
We do not sell your data, we do not show ads, and we do not use your content to train AI models.
The digest email is on by default and can be turned off or changed from account Settings, or from the "Manage email settings" link at the bottom of any digest email, which works without signing in.
4. Service providers
Your data is processed by the providers we build on, each only to the extent needed to run the Service:
- Vercel: application hosting and private photo storage;
- Turso: the database that holds your account and entries;
- Stripe: payment processing;
- Resend: transactional email delivery;
- Google: sign-in, if you choose Google sign-in.
5. AI assistants
You use connacto through an AI assistant or MCP client that you choose (for example Claude). Anything you tell that assistant is handled under its provider's own privacy policy before it ever reaches us; we receive only the tool calls the assistant makes against your account. We do not control, and are not responsible for, how your assistant's provider handles your conversations.
6. Cookies
We use a session cookie for authentication and a CSRF cookie for form security. There are no advertising or cross-site tracking cookies.
7. Retention and deletion
We keep your data while your account exists. Deactivating a module keeps its data; deleting entries through the tools removes them. To delete your account and all associated content, email support@connacto.com from your account address; we will delete it within 30 days, except records we must keep for legal or billing reasons.
8. Security
All traffic is encrypted in transit (TLS). Passwords are stored as bcrypt hashes. Photos are private blobs served only through ownership-checked routes. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
9. Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email support@connacto.com. We do not discriminate against you for exercising them.
10. Children
The Service is not directed to children under 13 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes
We may update this policy. The date above reflects the current version. For material changes we will give notice on the site or by email before the change takes effect.
12. Contact
Privacy questions: support@connacto.com.