This policy covers the Tenderlake connector for AI assistants (the Tenderlake MCP connector), used from Claude, ChatGPT and similar AI assistants. It supplements the Tenderlake Privacy Policy, which continues to apply to your Tenderlake account as a whole. The data controller is Tenderlake Ltd. (United Kingdom). Contact: privacy@tenderlake.com.
Last updated: 17 July 2026.
Connection and identity data. When you approve a connection, we record which Tenderlake user and workgroup the connection belongs to, and we issue the AI assistant short-lived access tokens tied to that identity (access tokens expire after about an hour and are renewed automatically while the connection remains approved). We use this to authenticate every request and to enforce your workgroup's plan entitlements.
Request logs. For each tool call the assistant makes, we log the tool name, the request parameters relevant to auditing it (for example folder ids, date ranges, or search keywords), result counts, timestamps, and a trace id. This is the same information your own software would generate if it called the Tenderlake API directly. We use it for security auditing, troubleshooting, abuse prevention, and service improvement.
Usage metering. For workgroups on the Tenderlake Analyst surface, metered tool calls are recorded in a credit ledger (tool, rows returned, credits drawn, balance) so that usage-based billing is accurate, transparent and auditable.
We do not receive, store, or have any access to your conversation with the AI assistant: not your questions, not the assistant's reasoning, not its answers, and not any other content of your chat. The connector receives only the parameters of each individual data request. We do not use connector data to train AI models.
To your AI assistant provider. The data our API returns (notices, folders, analytics results) is delivered to the AI assistant you connected, where it becomes part of your conversation. From that point it is processed by your assistant provider (for example Anthropic or OpenAI) under your agreement with that provider – their privacy terms, not this policy, govern what happens to your conversations.
Within Tenderlake. Connector requests are processed and stored on the same United Kingdom-based infrastructure as the rest of the Tenderlake service, under the main Tenderlake Privacy Policy. We do not sell, rent, or share the personal information involved in connector use with third parties.
Connection tokens expire automatically (access tokens after about an hour; a dormant connection's renewal ability lapses after 90 days). Request logs and the credit ledger are retained while your account is active, and as needed for billing, security auditing and legal obligations, in line with the main Tenderlake Privacy Policy.
Revoking disables the connection's tokens; the audit log of past requests is retained as described above.
Your rights over your personal data (access, correction, deletion) are as described in the Tenderlake Privacy Policy. For any question about this connector's data handling, contact privacy@tenderlake.com.