Privacy & Data Handling
What happens to your data when you connect an AI client such as Claude to Simplio3D.
What a connection can access
- Only the one workspace you chose when you connected, and only with the role you hold there.
- Only the scopes you granted. New OAuth connections start read-only; customer quote requests (
quotes:read), your store catalog (commerce:read) and all write access are opt-in. - Never: passwords, SMTP credentials, webhook secrets, store credentials, payment details, share passwords, or another customer’s workspace.
Where your data goes
Your data stays in Simplio3D. When your AI client calls a tool, Simplio3D returns the result to that client only, and your AI provider processes it under its own terms, as with anything else you share in a conversation. Simplio3D does not receive your conversation. It receives only the tool calls your client sends: the tool name and its arguments.
Two groups of tools reach outside Simplio3D, and only when an agent calls them: the store tools read products from your own connected Shopify or WooCommerce store, and the texture import tools fetch from free public libraries (ambientCG, CGBookcase, Pixabay). No other tool contacts a third party.
What is stored, and for how long
| Record | Contents | Kept for |
|---|---|---|
| Connection | Workspace, granted scopes, client name, last-used time. Tokens are stored only as a one-way hash. | Until you revoke it. OAuth access tokens expire after 8 hours and refresh tokens after 60 days; dashboard tokens after 90 days. |
| Tool log | Tool name, account, workspace, duration and outcome. The names of the arguments, never their values, and never results. | 30 days |
| Security audit | Consents, refused calls, revoked workspace access and applied changes, with secrets redacted. | 180 days |
| Undo history | A snapshot of what a change replaced, so you can undo it. | 7 days |
| Proposed change | A high-risk change waiting for your approval. | 15 minutes, or until you apply or cancel it |
Revoke access
Open Dashboard → Integrations → AI Connections and revoke the connection. It stops working on the next request. Removing the connector in your AI client alone does not revoke the Simplio3D connection, so revoke it here too. Changes an agent already made stay in your project. Most can be undone for 7 days from Dashboard → AI Changes; new items it created (a duplicated project, an imported asset) are removed by deleting them.
The Simplio3D Privacy Policy covers your account data in full. Questions: contact Simplio3D.