Privacy Addendum: Validity Engage MCP Connector
Effective date: 9/1/2026 · Applies to the MCP endpoint at https://engage-ai.vfe-prod.validityhq.net/mcp
1. What this Addendum covers
This Addendum supplements the Validity Privacy Policy at https://www.validity.com/privacy-policy/ (the "Privacy Policy") and describes how Validity, Inc. and its Affiliates ("Validity," "we," "our," "us") process information when you connect an AI assistant — such as Anthropic's Claude — to Validity Engage through our Model Context Protocol (MCP) connector, the Validity Engage SuperAgent (the "Connector"). It is additional to, not a replacement for, the Privacy Policy, which continues to govern your underlying Validity Engage account data. The Validity Data Processing Addendum and your service agreement continue to apply where Validity processes personal data on behalf of your organization. If there is a conflict between this Addendum and the Privacy Policy with respect to the Connector, this Addendum controls. For Engage user terms, please refer to https://www.validity.com/legal/engage/.
2. How the Connector works
The Connector lets an AI assistant (currently, only available on Claude) you authorize query your Validity Engage services conversationally. When you ask a question in Claude, Claude sends a request to the Connector; a supervisor agent validates the request, routes it to a specialized sub-agent, retrieves only the data needed to answer — filtered to what your account is permitted to access — and returns a response. Data is retrieved on demand per request; the Connector does not give the assistant bulk access to, or a background index of, your account. No tool runs without your explicit OAuth consent, and you can revoke access at any time.
3. Information we collect through the Connector
In addition to the categories in Section III of the Privacy Policy, the Connector processes the following:
| Category | What it includes | Retention |
|---|---|---|
| Authentication and identity data | An encrypted OAuth grant: the opaque access token issued by our authorization server (Litmus), the scopes you approved, and an identity mapping linking your Litmus account to your Everest and Certification user records so the connector can resolve your permissions. | Grant: until revoked or expired. Identity mapping: retained while the connection is active and purged within 30 days after you disconnect or your account is deprovisioned |
| Requests made on your behalf | The tool name and arguments Claude sends when you ask a question (which may echo parts of your prompt), the routing decision to a sub-agent, and the results of guardrail checks applied to inputs and outputs. | Operational logs, which may include request and response content, are retained for 30 days |
| Conversation memory | The content of your exchanges with the connector, retained between sessions so the assistant can maintain context, and an adaptive profile summarizing your recurring topics and configuration to improve responses over time. | 30 days; deleted earlier on a verified erasure request |
| Files you attach | Images or documents you submit through Claude for the connector to analyze. | Stored for 30 days |
| Usage records | A per-invocation entry in our credit and usage ledger (which agent ran, when, for which account) used for metering and billing. | Retained for billing and audit purposes 18 months |
| Service data retrieved for you | Records fetched from Validity Engage services (Litmus, Everest, Certification) to answer your question, filtered to what your account is permitted to access. | Not newly copied by the connector except where written into conversation memory; source data governed by the main Privacy Policy |
We do not sell your Personal Data, and we do not use data processed through the Connector for advertising.
4. How we use this information
We use Connector data to (a) authenticate and resolve your permissions, (b) answer user questions, (c) maintain conversational context between sessions, (d) apply safety guardrails that validate inputs and screen outputs for sensitive data and scope, (e) meter usage for billing, (f) secure, troubleshoot, and improve the service, and (g) comply with applicable law.
Purpose limitation. The identity mapping described in Section 3 is used to resolve your permissions when you use the Connector. This MCP identity mapping is the same coordination used for Validity's current Services (such as Litmus/Everest/Engage).
5. Authentication and security
The Connector uses OAuth 2.1 with PKCE and dynamic client registration. You authenticate directly with Validity's authorization service; your password is never shared with Anthropic or any other subprocessor. The connector client holds an opaque, audience-bound access token, which the Connector verifies with our authorization server on every request, checking that it is active and carries the required scopes. Requests are protected in transit with TLS. Inputs pass through intent validation and outputs are screened before they are returned. For more information, please refer to the security measures described in Section VIII of the Privacy Policy which apply to the Connector.
What you are told at authorization. When you connect, you are shown a consent screen operated by Litmus, Validity's authorization service, which identifies the connector requesting access and the permission it is asking for. Your approval is what authorizes the connector. If you do not approve, no access token is issued, the connector is not authorized to reach any Validity data, and no connection is established.
Logging. The Connector generates operational and audit logs that may include the content of requests and responses, such as the text of questions routed to the Connector and the data returned. Logs are stored in our logging platform (DataSet, operated by SentinelOne) and retained for 30 days, after which they are deleted.
6. Third parties
Your AI client (e.g., Anthropic Claude). When the Connector returns data to answer your question, that data becomes part of your conversation in the AI client and is thereafter handled under the AI client's own privacy terms — see Section 7. Please refer to our AI Providers Terms and Conditions at Section 3 of our Engage Terms of Service.
Language-model providers. The Connector's agents are powered by Anthropic Claude models (currently Sonnet and Haiku), accessed through Amazon Web Services (Amazon Bedrock) and directly from Anthropic; the Ignite agent additionally uses Google Gemini. These providers process request content to generate responses. Anthropic and Gemini do not use your content to train their models.
Hosting and infrastructure providers. The Connector runs on Validity-operated infrastructure at Validity's U.S. data center, where Connector data is stored and processed. Infrastructure providers process data in transit and retain short-lived operational logs under their own terms.
We do not share Connector data with any other third party except as described in the Privacy Policy (for example, service providers under contract, or where required by law).
7. What happens to data inside your AI client
Once the Connector returns data to Claude, that data is processed on Anthropic's systems and becomes part of your Claude conversation history. How Anthropic stores and retains it — and whether it may be used for model training — depends on your Claude plan, not on Validity. On "Claude for Work" plans (Team and Enterprise), Anthropic acts as a data processor and does not train on your content by default. On consumer plans (Free, Pro, Max), Anthropic may use conversations, including data retrieved through this Connector, to improve its models unless you disable that setting. We encourage you to review your Claude plan's data controls and Anthropic's privacy documentation at https://privacy.claude.com before connecting, and to avoid retrieving sensitive records into conversations governed by settings you have not reviewed. Validity is not responsible for the AI client's handling of data after delivery.
8. Data retention and deletion
Retention periods for each category are summarized in Section 3. In general, we retain Connector data only as long as needed for the purposes described in this Addendum, after which it is deleted or aggregated consistent with Section 10 of the Privacy Policy. Conversation memory and the adaptive profile are retained for 30 days. Operational logs are retained for 30 days. When you revoke the Connector's access or your account is deprovisioned, the assistant can no longer retrieve data on your behalf, and the identity mapping is purged within 30 days. Conversation memory and usage records are not deleted by revocation alone; you may request deletion as described in Section 9. Usage ledger entries may be retained longer where required for billing, accounting, or audit.
9. Your rights and choices
Revoke access at any time. Remove the Connector in your AI client (in Claude: Settings → Connectors) or revoke the grant from your Validity account. Revocation takes effect for new requests immediately.
Exercise privacy rights. You may exercise the rights described in Sections XVI–XVII of the Privacy Policy — including access, correction, deletion, and objection — through the request forms linked there or by contacting privacy@validity.com. If you are an end user of a Validity customer, we may direct your request to that organization as required by law. Deletion requests covering the Connector are handled through Validity's established data-subject-request process. You may also raise a request through Validity support.
10. International transfers
Connector data may be stored and processed in the United States and other countries where Validity or its service providers operate. Validity adheres to the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF, and uses appropriate safeguards, including Standard Contractual Clauses where required, as described in Sections 14–15 of the Privacy Policy.
11. Changes to this Addendum
We may update this Addendum as the Connector evolves. Material changes will be reflected in the effective date above.
12. Security incident notification
In the event of a security breach affecting the Connector, Validity will follow its notification process listed within the Data Processing Addendum, found at https://www.validity.com/legal/data-processing-addendum/.
13. Contact
Validity, Inc., Attn: Privacy Department, 100 Summer Street, Suite 2900, Boston, MA 02110, United States · privacy@validity.com · For security concerns relating to the Connector, contact security@validity.com.