Last updated: August 2026
MCP Privacy Policy
This addendum describes how TickM collects, uses, and retains data when you connect an AI assistant to TickM through the Model Context Protocol (MCP). It supplements our Privacy Policy. For setup and usage instructions, see MCP documentation.
1. What MCP tools can access
When you authorize a TickM MCP connector, the connected assistant may read and write data in your TickM organization through OAuth-scoped API tools. Depending on your role, this can include:
• Time entries — search, create, edit, and delete your own entries (including running timers). • Projects — list active projects; managers may create or edit projects. • Clients — managers on Team plans and above may create or edit client records. • Organization membership — your display name, email, and role within the connected organization, as needed to attribute entries and enforce permissions.
MCP tools cannot access billing, subscription management, license purchases, user invitations, or report exports.
2. Organization and role scope
All MCP access is limited to the TickM organization you select when connecting. If you belong to multiple organizations, you pin one organization in the connector URL (orgSlug parameter) or through the OAuth consent flow.
Within that organization, each tool call runs as you — the authenticated user who approved consent. You can only access data your role already permits in the TickM web app. For example, only managers can create or edit projects and clients; standard users can manage their own time entries only.
TickM does not grant MCP access across organizations or to other users' private data beyond what your role allows in the web app.
3. OAuth tokens and retention
MCP connectors authenticate with OAuth 2.0. When you approve consent, TickM issues access and refresh tokens scoped to MCP time-entry access.
• Tokens rotate on use; refresh tokens are replaced when refreshed. • If a connector is unused for 14 consecutive days, the refresh token expires and you must reconnect. • Regardless of activity, tokens expire after 30 days from issuance; you must approve consent again.
TickM stores OAuth tokens only as needed to maintain your authorized connection. Revoking access in the TickM app or disconnecting the connector invalidates the tokens.
If reconnection fails, see MCP troubleshooting.
4. What we do not store
TickM does not receive, process, or store conversation content from your AI assistant — including prompts, chat history, or model responses from AuditionAI, Claude, ChatGPT, Cursor, or any other client.
Only the specific tool calls your assistant sends to TickM's MCP API are processed (for example, “add a 45-minute entry on Project X”). Those requests contain the parameters needed to execute the tool, not your full conversation.
5. Changes and contact
We may update this MCP Privacy Policy from time to time. Material changes will be posted on this page. Continued use of MCP after changes constitutes acceptance of the updated policy.
Questions about MCP data handling? Contact us at [email protected].