Skip to main content

Jiminny MCP - Security & Privacy

How the Jiminny MCP Connector is secured: access model, what data is reachable, the data flow, where your data goes, and how to control or block it.

Written by James Graham

The Jiminny MCP Connector lets your team query Jiminny data (calls, transcripts, insights and deals) from the AI tools you already use, such as Claude and ChatGPT. This page explains how that connection is secured, what data can and cannot be accessed, where your data goes, and how your organization controls or blocks access.

At a glance

  • Added by an admin, then authorized per user. An administrator in your AI tool adds the connector for your workspace, and then each user authorizes their own Jiminny account. Until both happen, no one in your organization can connect.

  • Per-user authorization. Each user authorizes their own Jiminny account using OAuth 2.0. Access is scoped to exactly what that user is already permitted to see in Jiminny.

  • Read-only. The connector can read data only. It cannot create, change or delete anything in Jiminny, and cannot take actions on your behalf.

  • Your Jiminny visibility applies, exactly. The connector returns only what the signed-in user can already see in Jiminny, and nothing more. It does not widen anyone's access.

  • Your data region is respected. Requests are served from your Jiminny region, EU or US.

  • You stay in control. Your AI tool administrators can remove or restrict the connector, and individual users can revoke their own authorization at any time.

How access works

Setting up the connector is a two-step process:

  1. An administrator in your AI tool adds the Jiminny connector for your workspace (for example, a Claude or ChatGPT workspace admin). Until this is done, no one in your organization can connect.

  2. Each user authorizes their own Jiminny account through OAuth 2.0. During authorization the user reviews the data scopes and signs in to Jiminny. The connection is tied to that individual user.

Because every connection is authenticated per user, the AI tool only ever sees data that the signed-in user is already permitted to see in Jiminny. Your existing team visibility and permission rules apply unchanged.

Read-only by design

The Jiminny MCP Connector provides read-only access. It can retrieve and search data; it cannot create, modify or delete records, send anything, or take any action in Jiminny or any connected system.

What data can be accessed

Within the limits of each user's permissions, the connector can read call details and full transcripts, AI call insights, and deal data, and can search across calls and deals. It is read-only, so none of this can be changed. The full breakdown of fields is in the main Jiminny MCP article.

Because full transcript text can be returned into the connected AI tool, it is worth being deliberate about which AI tools your organization approves (see the section "How to control or block access").

Data flow

  1. A user asks a question in their AI tool (Claude, ChatGPT, or another MCP-compatible tool).

  2. The AI tool sends a read request to the Jiminny MCP server in your region, carrying the user's OAuth 2.0 token.

  3. Jiminny checks the request against that user's existing permissions and visibility, and returns nothing they could not already see in Jiminny.

  4. Jiminny returns only the data that user is allowed to see, read-only. Each access is recorded.

  5. The AI tool uses that data to answer the user. From that point the data sits inside your AI tool and is handled under your own agreement with that AI provider.

Where your data goes

The AI tool you connect is your tool, chosen and controlled by your organization. When data is returned into it, that data is then held and processed by your AI provider under the agreement between you and that provider. That AI provider is not a Jiminny sub-processor, and what it does with the data, including any retention or model training, is governed by your arrangement with it, not by Jiminny. Jiminny's processing of your data within the Jiminny platform continues to be governed by the Jiminny Data Processing Addendum.

How Jiminny handles the data

  • In transit: all connections use encrypted HTTPS/TLS.

  • Data region: requests are served from your Jiminny region, EU (mcp.jiminny.eu) or US (mcp.jiminny.com).

  • No training on your data by Jiminny: Jiminny does not use data accessed through the MCP connector to train models.

  • Access logging: every request made through the MCP connector is recorded in an audit log. The log holds metadata only: the user and AI client that made the request, the tool or action invoked and its parameters, the time, the outcome, and the number of records returned. It does not store transcript or message content. Audit log entries are retained for one year and then deleted.

  • Wider security posture: see the Jiminny Trust Center at https://trust.jiminny.com and the Jiminny Data Processing Addendum.

How to control or block access

Your organization controls access through your AI tool, and each user controls their own connection:

  • Manage it in your AI tool. The connector is added, removed and restricted by an administrator in your AI tool. They can remove it, or limit which users can use it, with your AI tool's controls for custom connectors (available on the business and enterprise tiers of tools such as Claude and ChatGPT). This is the primary way to control or block access across your organization.

  • Per-user revocation. Any user can revoke their own Jiminny authorization from their AI tool at any time, which immediately ends that user's access.

Questions

For security or privacy questions about Jiminny MCP, contact your Customer Success Manager or visit the Jiminny Trust Center at https://trust.jiminny.com.

For details of how Jiminny processes personal data, see the Jiminny Data Processing Addendum.

Did this answer your question?