Privacy policy
Applies to the hosted Perfex CRM Connector (MCP gateway) operated by Themesic.
What we store
- Connection grants. When you connect an AI assistant we store an OAuth grant in Cloudflare Workers KV. Your CRM address and API token in it are encrypted (AES-GCM) with a key that can only be unwrapped with a token issued to your assistant. The grant also holds a hashed identifier, the assistant's client ID and timestamps.
- OAuth client registrations made by AI assistants (name, redirect addresses).
- License status cache. Whether your CRM domain holds an active license, cached for up to 72 hours in Cloudflare's cache.
What we do not store
- Your CRM data. Requests and answers between your assistant and your CRM pass through the gateway in memory and are never stored.
- Your API token in logs. Operational logs contain only technical events (for example "license server unreachable") and never tokens or CRM content.
Who receives data
- Your own CRM, which receives the requests your assistant makes.
- Our license server, which receives only your CRM's host name.
- Cloudflare, which hosts the gateway.
Retention and deletion
A grant is kept until you disconnect the connector in your assistant (which revokes it) or until it has been unused for 90 days. Access tokens expire after 24 hours. Deleting or regenerating the API token in Perfex CRM immediately stops all access through the gateway.
Contact
Questions or deletion requests: support@themesic.com.