Privacy
Privacy policy
This policy explains what Aparok collects, how it is used, and what product data is stored when teams use audits, prompt monitoring, and assistant traffic analytics.
Last updated: July 18, 2026
What we collect
Aparok stores workspace details, domains, crawl results, report data, prompt watchlists, prompt-run observations, and assistant-attributed traffic events sent by the installed snippet.
Snippet events can include URL, referrer, session identifier, conversion metadata, and rendered page metadata such as title, canonical URL, headings, and text length.
How data is used
Product data is used to generate audits, reports, executive summaries, prompt visibility analysis, and AI traffic insights. We also use configuration and access data to secure accounts and enforce workspace boundaries.
Prompt and model data
When prompt monitoring is enabled, Aparok sends configured prompts and grounded report context to third-party model providers such as OpenAI, Perplexity, or Google Gemini. Do not include secrets, credentials, or regulated data in prompts unless your own compliance review allows it.
Connected assistant providers, including OpenAI for ChatGPT and Anthropic for Claude, also process tool requests and responses when you enable Aparok in their products.
ChatGPT, Claude, and MCP connections
When you connect Aparok to an MCP-compatible assistant such as ChatGPT or Claude, the assistant can request Aparok data and actions that you authorize. Aparok stores OAuth client and grant records, token hashes, approved scopes, and expiration or revocation information needed to operate and secure the connection. Aparok does not store your ChatGPT or Claude password.
Connector responses can include workspace metrics, prompt observations, crawl findings, recommendations, traffic analytics, report data, and prospect-fit evidence. The connected assistant processes those responses under its own terms and privacy policy.
MCP usage analytics
Aparok records operational information about connector use, including the tool name, success or failure, duration, authentication type, and limited numeric or boolean request attributes. Analytics events use a pseudonymous hashed identifier. Aparok does not send workspace IDs, prospect domains, prompt text, credentials, authorization tokens, or full tool responses to Google Analytics through this MCP event tracking.
Prospect Fit data
Prospect Fit can process company names, domains, contact titles, public website evidence, inferred requirements, scores, and outreach recommendations. Fresh analyses may use third-party model providers and consume workspace credits. Aparok does not use the MCP connection to contact prospects or publish outreach on your behalf.
Retention and control
Workspaces can delete domains, reports, and prompt sets from the product. Operational logs, analytics records, and provider-side processing may have separate retention windows depending on your deployment and provider settings.
You can disconnect Aparok in the connected assistant and revoke an Aparok OAuth grant. Contact support to request help with access, deletion, or revocation.