Amplifiers/Docs/Data and permissions

Data and permissions

This page is the short, practical version for anyone evaluating the connector — a user deciding whether to connect it, or a platform reviewing it. The complete and binding account is the Privacy Policy.


Authentication

Amplifiers uses OAuth 2.1 with PKCE. Your assistant never sees your password.

  • Authorisation server: auth.aiblewmymind.com
  • Discovery: https://mcp.getamplifiers.com/.well-known/oauth-authorization-server
  • Dynamic client registration is supported — no pre-issued client ID or secret is required.
  • Tokens are bearer tokens scoped to your account, and can be revoked at any time by resetting your password with sign out everywhere, which revokes every connected assistant at once.

What the connector receives

Each call carries your token and only what that specific call needs:

On this kind of callWe receive
Discovery (find_amplifiers)A short description of what you're after, written by your assistant, plus any filters
A data tool (run_tool)That tool's input — a URL, a search term, a company name
Image generationYour image prompt, and any reference image you uploaded
Saving a promptThe prompt text you chose to save
EverythingYour account identifier and email; standard network metadata

What the connector never receives

  • Your chat history. What you and the assistant said before or after the call.
  • Anything on your device you did not explicitly upload.
  • Your name, unless you gave it to Stripe when paying.
  • Your other apps — no email, calendar, files, contacts or messages. Amplifiers requests no such access, from any platform.

What we store, and for how long

WhatRetention
Your account (email, identifier)Until you delete your account
Files you generate or uploadUntil you delete them, or your account
Image prompts and long-running tool inputsKept, so you can reopen and refine a session later
Inputs to tools that finish immediatelyNot stored
Search log (the intent your assistant wrote)90 days, then deleted automatically
Per-action usage and billing recordsKept for billing, quota and abuse prevention
Sign-in security log, including IP addressesKept indefinitely — this is what we investigate account compromise from

Full detail, including the places we currently keep things longer than we'd like, is in Privacy Policy §7.

Who else sees your data

To fulfil a call we pass the minimum to the vendor behind it — and nothing that identifies you. A scraping vendor receives the URL you asked about and our credential; not your name, your email, your account identity, or anything from any other call.

Named sub-processors, what each receives, and where they are, are listed in Privacy Policy §5.

The commitments

  • We do not sell your personal data.
  • We do not train any AI model on your data, and we do not licence it to anyone who would.
  • We do not use anything from inside Amplifiers for advertising. Advertising measurement exists only on the marketing website getamplifiers.com, never inside the connector — and in the EEA, the UK and Switzerland nothing advertising-related loads until you agree.
  • We are an EU controller (Romania). All data Amplifiers stores about you sits in the EU: the server in Romania, the database, file storage and diagnostics in Frankfurt.

Two things worth knowing

  1. Generated images live at public links. An image you generate sits at a long, unguessable web address that needs no login. It is not listed, indexed or searchable, but anyone you send the link to can open it. Treat it like an unlisted video. Reference images you upload are private.
  2. Review Room links are capability links. If you share one, anyone holding it can see what you shared and leave comments. That's the feature; share accordingly.

Your controls

All self-service, all from getamplifiers.com/account or your assistant:

  • Browse, open and delete anything in your library — deleting removes the file, not just the listing.
  • Share a single item by a link that stops working after ten minutes.
  • Erase your entire account — 30-day grace period, cancellable.
  • Sign out of every device at once if you think your account is compromised.
  • Delete any API key you gave us.

Rights requests under GDPR — access, rectification, erasure, portability, objection — go to support@aiblewmymind.com from the address on your account. See Privacy Policy §8.

Age

Amplifiers is not for anyone under 16.

Security contact

Report a vulnerability to support@aiblewmymind.com. We take it seriously and we will credit you if you'd like.