Participant data stays in Claimr
Claimr MCP doesn’t send participants’ personal data to your AI assistant. The assistant can’t read:- Participant names, emails, social handles, or wallet addresses.
- Form and quiz answers.
- Raffle candidates and winners.
- Tournament standings.
- The participants in a segment.
You choose what each connection can reach
When you authorize a connection, you pick its organizations, campaigns, and permissions. A connection can never do more than your own role allows. See Authorize a connection. Give each connection the least access it needs:- Pick specific campaigns instead of all campaigns.
- Grant Read only, if you just want the assistant to review or explain.
- Leave out Organization unless the assistant needs to create new campaigns.
- Leave out Segments unless you plan to work on audiences.
Sign-in and tokens
- You sign in on a Claimr page, not inside the assistant. Your password is never shared with the assistant.
- The connection uses OAuth 2.1 with PKCE. The assistant receives a token tied to your account and to the access you chose.
- Tokens refresh automatically while in use. Each refresh replaces the old token, so a stolen refresh token stops working as soon as the real assistant refreshes.
- A connection unused for 90 days expires.
Organization oversight
Organization admins see every connection that reaches the organization, including who made it and when it was last used, and can narrow or revoke it. See Manage connections.Confirm before changes
Most AI assistants show each tool call and ask for approval before changing data. Review changes before you approve them, especially:- Deleting groups, quests, tasks, forms, or images.
- Running a raffle draw.
- Starting or ending a tournament.