Privacy policy for Refsee AI integrations.
Effective and last updated: September 17, 2026.
This policy describes Refsee connections to ChatGPT, Claude and other clients that use the Model Context Protocol (MCP). It supplements the general Refsee Privacy Policy. If this policy is more specific about an AI connection, this policy controls for that connection.
Refsee is the provider and controller of the Refsee account and MCP service described here. Contact hello@refsee.com with privacy questions or requests.
What the connection can access
You choose an AI application and authorize specific permissions. The AI application decides when to call a Refsee tool based on your request. Refsee receives only the tool name, arguments and connection credentials needed to perform that call, not your complete AI conversation or the AI provider's separate account data.
- Connection and security data: your Refsee account ID; the AI application's supplied name, client identifier and callback address; granted permissions; connection, expiry, revocation and last-use times; OAuth state, PKCE challenges and hashed token identifiers; IP address, user agent, request path, timestamps, rate-limit events and security/error diagnostics.
- Account tool (
get_account): no input beyond the call itself. Output is your Refsee user ID, display name or username, plan and remaining credits. It does not return your email address, password, payment details or staff status. - Search and suggestion tools (
search_references,searchandsuggest_searches): search text and optional library mode, category, aspect ratio, framing, sort and page filters. Outputs can include the original or translated query, result counts, frame and video identifiers, titles, authors, tags, colours, reference type, thumbnails, Refsee source links and whether metadata is restricted by your plan. - Frame, related-reference and display tools (
get_frame,get_related_referencesandshow_references): frame identifiers, frame type, selected reference identifiers and a gallery title. Outputs can include frame metadata, thumbnail and source links, visually related references and plan-access status. Displaying or opening a frame may be recorded in normal Refsee recent-view history. - Video and fetch tools (
get_videoandfetch): a Refsee video or result identifier. Outputs can include title, author, description, duration, source link and ordered frame metadata. Opening video details uses your Refsee video-view allowance and records that usage. - Moodboard tools (
list_moodboards,get_moodboard,create_moodboard,update_moodboard,add_to_moodboardandshow_moodboard): board ID or share hash, pagination, a title and description, and frame IDs selected for saving. Outputs can include board ID, title, description, visibility, editable status, frame count, board link and frame metadata. Create, update and add actions store the requested private moodboard content in your Refsee account. - History tool (
get_search_history): no input beyond the call itself. With the history permission, output contains up to eight recent Refsee search terms and up to four recently viewed reference frames. - Interactive gallery: search filters, selected frame IDs and save choices you make in the embedded gallery. “Use in chat” sends the exact selected Refsee frame IDs to your AI conversation. Search, related-reference and moodboard actions in the gallery call the same tools and follow the same rules above.
Refsee does not intentionally collect sensitive personal information through these tools. Do not place confidential, health, financial, biometric or other sensitive personal information in search text, moodboard titles or descriptions.
How we use the data
- Authenticate the connection, enforce the permissions you approved and prevent token replay, abuse and unauthorized access.
- Perform the tool action you requested, return the result to your AI application, render the interactive gallery and keep account-owned moodboards in sync.
- Apply your Refsee subscription, credits, search limits and video-view allowance.
- Maintain recent searches and viewed references when the action normally contributes to Refsee history.
- Operate, secure, troubleshoot and improve reliability using bounded rate-limit, request and error information.
- Comply with law, enforce our terms and protect users, Refsee and the public.
We do not sell AI-connection data, use tool inputs or outputs for targeted advertising, or use them to train a Refsee generative model. The integration pages do not add advertising pixels or a separate advertising tracker.
Who receives data
- Your chosen AI provider and client (for example, OpenAI for ChatGPT or Anthropic for Claude) receives tool outputs and gallery messages so it can answer your request. It may also receive the tool inputs it generated from your prompt. Its retention, training and conversation controls are governed by its own terms and privacy policy. Refsee does not control copies already delivered to it.
- Refsee infrastructure providers process data only to deliver and protect the service: Cloudflare provides network, DNS and tunnel protection; Hetzner hosts the application and databases; Datadog and Sentry may receive operational telemetry and error diagnostics. We do not intentionally send moodboard content or tool-result bodies to monitoring providers, but diagnostics can include account or connection identifiers, request metadata and error context.
- Authorized Refsee personnel and contractors may access the minimum information necessary for security, support and incident investigation, subject to confidentiality obligations.
- Authorities or affected parties may receive information when required by law or when reasonably necessary to prevent fraud, security incidents or harm and to protect legal rights.
Data may be processed outside your country where these providers operate. We require service providers to protect data and process it for contracted purposes. We do not share AI-connection data with unrelated data brokers.
Credentials and security
Your Refsee password, payment credentials and browser session cookie are not shared with the MCP client. Authorization codes and client access and refresh tokens are stored only as cryptographic hashes. The separate credential used by the MCP service to call Refsee is encrypted at rest. Connections use OAuth, short-lived authorization codes and PKCE. Access is checked again for every operation, including scope, account ownership, plan and revocation status.
Retention
- Pending authorization requests expire after 5 minutes; authorization codes expire after 2 minutes and are single-use.
- MCP access tokens expire after 1 hour. Rotating refresh tokens expire after 30 days. Security records for a spent refresh token remain only until that token's original expiry so replay can revoke its token family.
- Dynamic OAuth client registrations are kept for up to 365 days so a client can reconnect.
- A Refsee account connection and its encrypted delegated credential expire after 90 days unless you revoke or reconnect. The connection record, client name, granted scopes and use timestamps are deleted within 30 days after expiry or revocation.
- Per-minute rate-limit counters expire after approximately 65 seconds.
- Operational application logs, monitoring events and security diagnostics are retained for up to 90 days, except when a longer period is required to investigate an active security incident or comply with law.
- Search terms, viewed-reference history, created moodboards and saved frame membership are normal Refsee account data. They remain while your account or the relevant moodboard exists, unless you delete the content or request deletion. Only the most recent eight terms and four viewed frames are returned by the history tool.
- Encrypted MCP authorization-database backups are retained for up to 30 days. Deleted connection data can remain in a protected backup until that backup expires; backups are used only for disaster recovery and are not restored to recover an individual deleted record.
Your choices and controls
- Review requested permissions before connecting and decline the request if you do not agree.
- Manage Refsee connections to inspect the client and permissions or revoke access immediately. Revocation prevents new tool calls and starts the deletion period described above.
- Delete or edit moodboards and their descriptions in Refsee. You can avoid granting board-write or history access when a client supports narrower scopes.
- Use your AI provider's controls to delete conversations, disable model training where offered, disconnect the application or remove data already delivered to that provider.
- Contact hello@refsee.com to request access, correction, export or deletion of your Refsee personal data, or to object to or restrict processing where applicable. We may need to verify that you own the account.
Deleting or revoking data at Refsee cannot erase copies already included in an AI conversation, exported by you, or retained by an AI provider under its own policy.
Changes
We may update this policy when tools, data uses, providers or legal requirements change. We will change the date above and provide additional notice when required. Material new permissions require a new authorization from you.