Data and permissions
This page is the short, practical version for anyone evaluating the connector — a user deciding whether to connect it, or a platform reviewing it. The complete and binding account is the Privacy Policy.
Authentication
Amplifiers uses OAuth 2.1 with PKCE. Your assistant never sees your password.
- Authorisation server:
auth.aiblewmymind.com - Discovery:
https://mcp.getamplifiers.com/.well-known/oauth-authorization-server - Dynamic client registration is supported — no pre-issued client ID or secret is required.
- Tokens are bearer tokens scoped to your account, and can be revoked at any time by resetting your password with sign out everywhere, which revokes every connected assistant at once.
What the connector receives
Each call carries your token and only what that specific call needs:
| On this kind of call | We receive |
|---|---|
Discovery (find_amplifiers) | A short description of what you're after, written by your assistant, plus any filters |
A data tool (run_tool) | That tool's input — a URL, a search term, a company name |
| Image generation | Your image prompt, and any reference image you uploaded |
| Saving a prompt | The prompt text you chose to save |
| Everything | Your account identifier and email; standard network metadata |
What the connector never receives
- Your chat history. What you and the assistant said before or after the call.
- Anything on your device you did not explicitly upload.
- Your name, unless you gave it to Stripe when paying.
- Your other apps — no email, calendar, files, contacts or messages. Amplifiers requests no such access, from any platform.
What we store, and for how long
| What | Retention |
|---|---|
| Your account (email, identifier) | Until you delete your account |
| Files you generate or upload | Until you delete them, or your account |
| Image prompts and long-running tool inputs | Kept, so you can reopen and refine a session later |
| Inputs to tools that finish immediately | Not stored |
| Search log (the intent your assistant wrote) | 90 days, then deleted automatically |
| Per-action usage and billing records | Kept for billing, quota and abuse prevention |
| Sign-in security log, including IP addresses | Kept indefinitely — this is what we investigate account compromise from |
Full detail, including the places we currently keep things longer than we'd like, is in Privacy Policy §7.
Who else sees your data
To fulfil a call we pass the minimum to the vendor behind it — and nothing that identifies you. A scraping vendor receives the URL you asked about and our credential; not your name, your email, your account identity, or anything from any other call.
Named sub-processors, what each receives, and where they are, are listed in Privacy Policy §5.
The commitments
- We do not sell your personal data.
- We do not train any AI model on your data, and we do not licence it to anyone who would.
- We do not use anything from inside Amplifiers for advertising. Advertising measurement exists only on the marketing website
getamplifiers.com, never inside the connector — and in the EEA, the UK and Switzerland nothing advertising-related loads until you agree. - We are an EU controller (Romania). All data Amplifiers stores about you sits in the EU: the server in Romania, the database, file storage and diagnostics in Frankfurt.
Two things worth knowing
- Generated images live at public links. An image you generate sits at a long, unguessable web address that needs no login. It is not listed, indexed or searchable, but anyone you send the link to can open it. Treat it like an unlisted video. Reference images you upload are private.
- Review Room links are capability links. If you share one, anyone holding it can see what you shared and leave comments. That's the feature; share accordingly.
Your controls
All self-service, all from getamplifiers.com/account or your assistant:
- Browse, open and delete anything in your library — deleting removes the file, not just the listing.
- Share a single item by a link that stops working after ten minutes.
- Erase your entire account — 30-day grace period, cancellable.
- Sign out of every device at once if you think your account is compromised.
- Delete any API key you gave us.
Rights requests under GDPR — access, rectification, erasure, portability, objection — go to support@aiblewmymind.com from the address on your account. See Privacy Policy §8.
Age
Amplifiers is not for anyone under 16.
Security contact
Report a vulnerability to support@aiblewmymind.com. We take it seriously and we will credit you if you'd like.