Extenshi MCP connector — privacy policy
Last updated: 2026-06-25
This policy covers the remote Extenshi MCP connector (the OAuth-protected server at this domain) that connects Claude to your Extenshi account and the Extenshi extension catalog. It does not cover the Extenshi website or other products, which have their own terms.
What Claude sends us
When you invoke a tool, Claude sends only that tool's inputs — for example a search phrase, a numeric catalog ID, store/category filters, or a documentation query. We do not receive your wider Claude conversation.
What we access on your behalf
After you authorize the connector, we read the public Extenshi catalog (extensions, security findings, market statistics, docs) and associate each request with your Extenshi account so your usage allowance applies. We never see your Extenshi password — sign-in happens on Extenshi's own login.
What we store
- OAuth tokens. Access and refresh tokens are stored only as salted hashes, bound to your account identifier and email and a token audience; they are not recoverable from our records. No passwords are stored.
- Anonymous usage telemetry. We record which tool ran, how long it took, and a coarse success/error category, tied to an anonymous install identifier — never the text of your queries, tool results, or any conversation content.
We do not store the content of your tool calls or their results beyond the anonymous, aggregate telemetry above.
Retention
Tokens persist until they expire or you revoke access; revoking from your Extenshi account invalidates them. Aggregate telemetry is retained for product analytics.
Third parties
Anonymous product analytics are processed by PostHog (EU region). Authentication uses Extenshi's own identity service. We do not sell personal data.
Your choices
You can disconnect the connector or revoke its access at any time from your Extenshi account, which immediately stops further access. Telemetry can be disabled via the documented opt-out.
Contact
Questions or data requests: [email protected].