Privacy policy
Small data footprint. Clear boundaries.
Effective September 26, 2026. GTM MCP provides read-only access to Google Tag Manager configuration for the user who explicitly connects it.
Data we process
We process your authentication identity, the minimum OAuth metadata needed to maintain a secure session, and Google Tag Manager configuration returned when you invoke a tool. The Google authorization asks only for https://www.googleapis.com/auth/tagmanager.readonly.
Token storage
Each Google refresh token is encrypted with AES-256-GCM before it is stored in persistent Postgres storage. It is keyed to the verified Auth0 subject for that user. Access tokens are refreshed as needed and are not used as MCP bearer tokens. We never use a shared Google account, service account, local token.json, or hardcoded container ID.
How data is used
Google data is used only to answer the read-only tool call you initiated: listing or inspecting accounts, containers, workspaces, tags, triggers, and variables, or running the requested configuration audit. This version cannot create, edit, delete, or publish GTM resources.
Sharing and retention
Authentication is provided by Auth0, hosting by Vercel, and persistent storage by Neon. Google configuration passes through the service to the requesting MCP client and is not intentionally retained by the application. The encrypted refresh token remains until you disconnect, revoke access in Google, or request deletion.
Disconnect and deletion
Use the Disconnect button on the Setup page. The service asks Google to revoke the credential and deletes the encrypted token from its database. You can also revoke the app from your Google Account security settings.
Security and contact
OAuth tokens are treated as secrets and are not written to application logs. No Internet service can promise absolute security. For privacy or deletion questions, email haseemsaffi@gmail.com.