Protocol Privacy Policy
Last updated: June 13, 2026
This Privacy Policy explains how Protocol (“Protocol,” “we,” “us,” or “our”) collects, uses, and shares personal information when you visit protocolgtm.com, submit a company domain or email address, create or use an account, access a Protocol MCP server, purchase a plan or add-on, communicate with us, or otherwise use our services (collectively, the “Services”).
Protocol LLC is a Pennsylvania limited liability company.
Protocol is a business-to-business service intended for business users, not for children or personal, family, or household use.
Questions and privacy requests may be sent to legal@protocolgtm.com.
1. Personal Information We Collect
Information you provide
We may collect:
- Account and contact information, such as your name, business or personal email address, company, role, company domain, profile information, and communication preferences.
- Signup and verification information, such as verification status, authentication identifiers, login events, fraud or abuse signals, and information needed to determine whether an email address or account is eligible for access.
- Customer Content, such as company domains and URLs, product-marketing materials, documents, briefs, frameworks, battle cards, instructions, edits, approvals, feedback, prompts, task assignments, and other information you submit to the Services.
- Communications, such as support requests, sales inquiries, survey responses, meeting notes, and other messages.
- Billing information, such as billing name, billing address, tax information, plan, subscription status, invoices, transaction amount, and payment status. Stripe processes payment-card and related payment information. We generally do not receive full payment-card numbers.
Information collected from your use of the Services
We may collect:
- Product usage and audit information, such as MCP and Smart Routing calls, selected context, components and documents used, prompts or request metadata, User, workspace, timestamps, actions taken, feedback, edits, rewrites, approvals, tasks, credit consumption, seat usage, and feature interactions.
- Website, device, and log information, such as pages viewed, referring pages, form submissions, IP address, browser type, operating system, device identifiers, approximate location inferred from IP address, error logs, and security events.
- Cookie and similar technology information used for authentication, preferences, security, analytics, and, if implemented and disclosed, advertising or attribution.
Information from public and third-party sources
When you submit a company domain or use the Services, we may collect:
- public information from the submitted website, linked pages, public company materials, social posts, product pages, documentation, blogs, public databases, search results, and other publicly available sources;
- company, professional, or contact information from data providers, integration partners, or business partners;
- authentication and account information from WorkOS or an identity provider;
- transaction, subscription, fraud, and payment-status information from Stripe; and
- information from MCP clients, AI tools, or other integrations you connect to Protocol.
Submitting a company domain does not establish that you own, control, or represent that company. We may keep records needed to prevent impersonation, abuse, or unauthorized access.
2. How We Use Personal Information
We may use personal information to:
- provide, operate, maintain, secure, and troubleshoot the Services;
- verify email addresses, authenticate Users, administer accounts and workspaces, and enforce seat and access controls;
- evaluate signup eligibility and detect disposable email addresses, fraud, spam, abuse, impersonation, sanctions risk, or security threats;
- research submitted domains and public sources and draft product-marketing, go-to-market, company, or market context;
- generate, route, display, edit, approve, and maintain Customer Content and AI-enabled output;
- provide and administer MCP servers, Smart Routing, the Audit Log, Task List, Drafted Suggestions, Active Context, and related features;
- meter credits, seats, storage, audits, and other plan limits;
- process subscriptions, payments, invoices, taxes, refunds, disputes, and purchases of additional capacity;
- provide support and respond to communications;
- analyze use, improve the Services, develop new features, and understand Product performance;
- send service, security, billing, legal, product, launch, research, and marketing communications;
- comply with law, enforce our agreements, establish or defend legal claims, and protect the rights, safety, and security of Protocol, our users, and others; and
- complete a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or transfer of the Services.
3. AI And Machine Learning
Protocol uses AI and machine-learning providers to research public company information, generate and route context, create suggestions and other output, identify patterns, and provide related features.
AI-generated information may be inaccurate or incomplete and should be reviewed by a person before use.
We may use public marketing material, non-sensitive Product feedback submitted to improve the Services, and aggregated or commercially reasonably de-identified usage data to evaluate and improve Protocol and related AI or machine-learning systems.
We do not use private or proprietary Customer Content, confidential Customer information, or sensitive personal information to train generalized AI or machine-learning models or to improve the Services for other customers. AI service providers may process Customer Content as needed to provide requested features, subject to our agreements with them.
Do not submit regulated or highly sensitive information unless Protocol has expressly agreed in writing to process it.
4. How We Share Personal Information
We may share personal information:
- With service providers that provide hosting, infrastructure, databases, authentication, email verification, security, fraud prevention, analytics, communications, customer support, AI, research, billing, payment, tax, and professional services.
- With Anthropic and OpenAI to provide AI-enabled research, generation, analysis, routing, and related Product features.
- With Sentry to monitor errors, reliability, performance, and security. We seek to limit the Customer Content and personal information included in diagnostic data.
- With WorkOS and identity providers to authenticate Users, verify emails, manage accounts and organizations, and prevent abuse.
- With Stripe and financial partners to process payments, subscriptions, refunds, disputes, fraud checks, invoices, and tax-related functions.
- With Attio to manage prospective-customer, customer-relationship, sales, support, and communication records.
- With integrations you direct us to use, including MCP clients, AI tools, identity providers, repositories, communications tools, and other connected services.
- Within a Customer account or workspace, including with administrators and other authorized Users. Workspace administrators may access, manage, export, or delete account information and Customer Content and may control User access.
- For legal and safety reasons, when reasonably necessary to comply with law or legal process, enforce agreements, investigate fraud or abuse, or protect rights, safety, and security.
- In a business transaction, such as a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or transfer of the Services.
- With your consent or at your direction.
- In aggregated or de-identified form that does not reasonably identify you.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless we first update this Privacy Policy and provide any notice or choice required by law.
5. Service Providers, Authentication, And Payments
Our current material subprocessors and service providers include Anthropic, OpenAI, Sentry, WorkOS, Stripe, and Attio. We may update that list as our Services and providers change.
We use WorkOS for authentication, account management, and related security functions. WorkOS may receive information such as your name, email address, identity-provider information, authentication events, device or network information, and organization membership.
We use Stripe for billing and payment processing. Stripe may collect and process payment method, billing, transaction, device, fraud, and identity-verification information under its own privacy policy and its role in the transaction.
Our current material subprocessors and service providers are listed on our Subprocessor List.
You should review:
6. Cookies And Similar Technologies
We may use:
- Strictly necessary technologies for authentication, session management, security, load balancing, and requested features;
- Preference technologies to remember settings;
- Analytics technologies to understand use and improve the Services; and
- Advertising or attribution technologies only if implemented and disclosed through an appropriate notice or consent mechanism.
You can control some cookies through your browser or any cookie controls we make available. Blocking necessary cookies may prevent account access or other Services from working.
7. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy. Our general retention schedule is:
- Active accounts and Customer Content: while the account is active.
- Terminated accounts and verified deletion requests: deletion or de-identification from active systems within 30 days.
- Routine backups: expiration or deletion within 90 days after deletion from active systems. Backups are maintained for recovery and are not returned to ordinary use; if restored, applicable deletion requests will be reapplied.
- Unverified or abandoned signups: generally deleted or de-identified within 90 days, except limited records needed to prevent fraud, abuse, or repeated ineligible signups.
- Authentication, security, system, and fraud-prevention logs: generally up to 12 months, and longer when reasonably necessary to investigate an incident or protect the Services.
- Sales, support, and business communications: generally up to 24 months after the last meaningful interaction, unless a longer period is needed for an active relationship or legal purpose.
- Billing, tax, accounting, and transaction records: up to seven years or any longer period required by law.
- Public-source material and aggregated or irreversibly de-identified information: may be retained for longer because it does not identify a User or contain private Customer Content.
We may retain specific information longer when required by law, subject to a legal hold, needed to resolve a dispute, or reasonably necessary for security, fraud prevention, or enforcement. When deletion is not technically immediate, we will restrict the information from ordinary use until deletion occurs.
8. Your Choices And Rights
You may:
- unsubscribe from marketing emails using the unsubscribe link;
- update certain account information through the Services;
- control certain cookies through your browser or available cookie controls;
- cancel a subscription through the Services or by contacting us; and
- request access, correction, deletion, or export of certain personal information by emailing legal@protocolgtm.com.
Depending on where you live and applicable legal thresholds, you may have additional rights, including rights to know, access, correct, delete, obtain a portable copy, restrict or object to processing, or opt out of certain disclosures or automated uses.
We may need to verify your identity and authority before completing a request. If your account is controlled by a Customer organization, we may refer your request to that organization’s administrator.
Authorized agents may submit requests where permitted by law, but we may require proof of authorization and identity verification.
You may appeal a denied privacy request by replying to our decision or emailing legal@protocolgtm.com with the subject line “Privacy Appeal.”
9. California And Other U.S. State Disclosures
Some U.S. state privacy laws apply only after a business meets specified thresholds or engages in specified activities. If an applicable law gives you rights, you may exercise them through the contact method above.
The categories of personal information we may collect are described in Section 1. The business and commercial purposes for collection and use are described in Section 2. The categories of recipients are described in Section 4. We do not knowingly sell personal information for money or share it for cross-context behavioral advertising.
We will not discriminate against you for exercising a privacy right protected by applicable law.
10. International Users
Protocol markets and directs the Services primarily to business users in the United States. The Services may nevertheless be accessible elsewhere. If you access the Services from another country, your information may be processed in the United States and other countries where we or our service providers operate, which may have different privacy protections than your country.
Access from another country does not waive rights that cannot lawfully be waived. Where applicable law gives you privacy rights, you may submit a request using the contact information below.
Protocol does not currently direct advertising or localized sales efforts to the European Union, European Economic Area, United Kingdom, Canada, or other non-U.S. regions. Before submitting personal data governed by the GDPR or similar laws as Customer Content, a Customer must enter into any Data Processing Agreement required by the Terms of Service or applicable law.
11. Security
We use commercially reasonable administrative, technical, and organizational measures designed to protect personal information. No system is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your login credentials, controlling access to your account and connected tools, and promptly notifying us of suspected unauthorized access.
12. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children. The Services are intended for people who are at least 18 years old and able to enter into a business contract.
13. Third-Party Services And Links
The Services may link to or interoperate with third-party websites, AI tools, MCP clients, identity providers, repositories, payment services, and other integrations. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices.
14. Changes To This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last updated” date. If changes are material, we will provide additional notice where required by law, such as by email or an in-product notice.
15. Contact
Protocol LLC
legal@protocolgtm.com