Podia MCP is designed with security and privacy in mind. Below, we explain how Podia MCP handles your account information and the customer data you manage, helping you make an informed decision about using it for your business.
What is an MCP?
MCP stands for Model Context Protocol. It’s an open standard that allows AI tools such as Claude, ChatGPT, and Cursor to connect directly to other software and perform supported actions within it.
Podia MCP lets you connect an AI tool to your Podia account to complete tasks such as drafting and editing emails, creating pages, updating products, organizing contacts, and more.
While Podia MCP can help automate your work, connected AI tools still have limitations and may occasionally produce inaccurate or unexpected results.
Because allowing an AI tool to make changes also requires giving it access to parts of your account, Podia MCP includes permissions that let you control what the tool can access and which actions it can perform.
Managing AI permissions through the MCP
When you connect an AI tool such as Claude, ChatGPT, or Cursor, the connection starts with read-only access. You can then review and approve additional permissions individually.
For example, you could allow the AI tool to draft emails without giving it permission to update your contacts.
Permissions for more sensitive actions, such as editing your site or managing account users, remain disabled unless you deliberately turn them on.
If you haven’t granted a permission, the AI tool can’t access that information or perform the corresponding action.
Reviewing every action the AI tool performs
You control how Podia MCP operates in two important ways.
First, AI tools such as Claude, ChatGPT, and Cursor ask for your approval before performing an action, including retrieving information or making changes.
These tools may offer an auto-approve setting that allows actions to proceed without confirmation, but we recommend leaving approval prompts turned on when using Podia MCP. This gives you an opportunity to review each request before it runs.
Second, actions performed through Podia MCP may produce different results. Some changes are saved as drafts that you can review before publishing, while others take effect immediately.
Before approving an action, check how it will be applied and whether you’ll have an opportunity to review the result first. Some actions take effect immediately and cannot be reversed.
How your account is protected
Podia MCP includes several safeguards designed to protect your account and data:
Podia MCP can only access the information and actions available to the account user who connected it. The connection is also limited to your Podia account and can’t access other accounts.
You can disconnect an AI tool at any time from Admin > Settings > Integrations. Connections that remain unused will also expire automatically.
Your connected AI tool can only perform actions or make changes if you grant the required permissions. Without these permissions, the connection remains read-only, and the tool can only view the information available to it.
Data & privacy
When you allow an AI tool to access information from your Podia account through Podia MCP, that information is shared with the AI provider you selected, such as Anthropic or OpenAI. The provider handles it according to its own terms and privacy policies.
Podia MCP does not send your account information to an AI provider automatically. Information is only shared after you connect an AI tool and ask it to complete a request. You choose the tool, set its permissions, and control which information it can access.
You remain responsible for the customer data you manage in Podia. If your connected AI tool processes customers’ personal information, you may need to identify that provider as a vendor in your privacy disclosures, depending on the privacy and data-protection requirements that apply to your business.
