MSPStuff Privacy Policy

Last updated:

This Privacy Policy explains what information AutomatedMSP, LLC, doing business as MSPStuff ("MSPStuff", "we", "us"), collects through the MSPStuff website, the Switchboard web app, our AI engine and our MCP server at https://www.mspstuff.io/mcp (together, the "Service"), how we use and share it, how long we keep it, and the choices you have.

The Service is for businesses, mainly managed service providers (MSPs). Our customer is the business that holds the MSPStuff organization account ("Customer"). Words that are defined in our Terms of Service (https://www.mspstuff.io/terms) have the same meaning here.

1. Who we are and how to contact us

AutomatedMSP, LLC1315 Wooten RdNesbit, MS 38651United StatesEmail: bkelly@automatedmsp.com

Send any privacy question or request to that address.

2. The two roles we play

We handle two kinds of information, and our role is different for each.

2.1 Customer Data (we act for the Customer). When a Customer connects its business systems, we process data from those systems, such as tickets, devices, clients, billing and security alerts, along with the questions, chats and saved work of its Members. We process this data only on the Customer's behalf and on its instructions, as set out in our Terms of Service. The Customer decides what systems to connect and who can see what. If you are an employee of an MSP, or a client of an MSP, and you have a question about data that an MSP has connected to MSPStuff, please contact that MSP first. We will help them respond.

2.2 Account, billing, website and application data (we decide how it is used). For information about the people who use our website, apply for the beta, create accounts or pay us, we decide how it is used, and this Privacy Policy describes how.

3. Information we collect

3.1 Account information. Name, work email, company, role, and sign-in details, including password (stored hashed), two-factor authentication settings, and Google or Microsoft sign-in identifiers if you choose those options.

3.2 Beta applications. Contact details, company, information about your technology stack, and a one-way hash derived from your IP address that we use to prevent abuse. We do not store the IP address itself for this purpose.

3.3 Billing information. Plan, subscription status and billing contact. Card details are collected and stored by Stripe. We do not receive or store full card numbers.

3.4 Data from Connected Systems (Customer Data). Depending on which systems a Customer connects and which data areas it turns on, we keep cached copies of:

  • a fleet map of the Customer's clients, devices and servers;
  • a mirror of PSA data, including tickets, time entries and their notes, projects and agreements;
  • billing and licensing data from systems such as Pax8, Xero and Microsoft 365;
  • security alerts; and
  • health results we derive from that data.

This data can include names, email addresses, phone numbers, device names and other information about the Customer's staff and its clients' staff, depending on what is stored in those systems.

3.5 Content created in the Service. Questions, chat history, AI memory notes, saved reports, files, dashboards, schedules, comments and items shared with Viewers.

3.6 Credentials. Connection credentials for Connected Systems, kept in a secrets vault and never shown to the AI. MSPStuff API keys, stored only in hashed form.

3.7 Audit and security logs. A record of every tool call the AI makes, sign-in events, and server logs, which can include IP addresses, browser and device information, and timestamps.

3.8 Website and product analytics. Pages visited, features used, approximate location derived from IP address, referring site, and similar usage information, collected with PostHog. Error reports collected with Sentry, which can include technical details about the error and the account it occurred in.

3.9 Communications. Emails and support requests you send us.

3.10 Viewers. If someone shares an item with you, we receive your name and email address from Google or Microsoft when you sign in, and we keep the comments you post.

4. How we use information

We use information to:

  • (a) provide the Service, including answering Members' questions from the data they are allowed to see;
  • (b) keep the Service secure, prevent abuse and fraud, and enforce our Terms;
  • (c) manage accounts, process payments and send service and billing messages;
  • (d) provide support;
  • (e) understand how the Service is used and improve it, using analytics and error data;
  • (f) send product updates to account holders, which you can opt out of at any time (service and billing messages are not optional while you have an account); and
  • (g) comply with law.

We use Customer Data only for purposes (a), (b), (d) and (g), and only as the Customer instructs.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

We do not use Customer Data to train AI models, and the terms we have with our AI model providers do not allow them to train their models on the data we send them.

5. How the AI works with your data

5.1 In the MSPStuff web app. When a Member asks a question, our engine runs on our own servers and uses AI models from third-party AI model providers. To answer, the engine retrieves data one tool call at a time, and only from the systems and data areas that the asking Member is permitted to see. The question and the retrieved data are sent to an AI model provider to produce the answer. Each AI model provider acts as our sub-processor and is named on our sub-processor list (Section 6.1). Every tool call is recorded in the audit log.

5.2 In your own AI Client. When a Customer connects an AI Client such as Claude, ChatGPT, Microsoft Copilot, Claude Code or Cursor to our MCP server, the same permission rules apply to what our server returns. Questions and answers then pass through the AI Client's provider under the Customer's own agreement with that provider. That provider is not our sub-processor, and its handling of data is governed by its own terms and privacy policy.

5.3 Read-only. The Service only reads from Connected Systems. It does not change them.

5.4 No automated decisions about people. We do not use AI to make decisions that have legal or similarly significant effects on individuals.

6. How we share information

We share information only as follows:

6.1 Service providers (sub-processors). We use service providers to run the Service. They may process personal data only to provide their services to us, under contracts that require them to protect it. They fall into these categories:

  • cloud hosting, database and authentication providers;
  • AI model providers that process questions and the data needed to answer them;
  • payment processing;
  • transactional email;
  • website hosting, analytics and error monitoring; and
  • optional sign-in providers (Google and Microsoft).

The current providers, what each one does and where it processes data are listed at https://www.mspstuff.io/subprocessors. We will update that list before adding a new sub-processor that handles Customer Data.

6.2 Within the Customer's organization and with people the Customer chooses. Members can share sessions with colleagues, email reports through an allow-listed outbox, and share individual items with Viewers. These are the Customer's choices.

6.3 AI Clients chosen by the Customer. As described in Section 5.2.

6.4 Legal reasons. If we must do so by law, or to protect the rights, safety or security of our customers, the public or MSPStuff. If we receive a legal demand for Customer Data, we will tell the Customer before disclosing, unless the law prohibits it.

6.5 Business transfers. If MSPStuff is involved in a merger, acquisition or sale of assets, information may be transferred as part of that deal, subject to this Privacy Policy.

7. How long we keep information

InformationHow long we keep it
Cached Connected System dataWhile the connection is active. A Customer can purge the cache at any time from the Data tab. Deleted from active systems within 30 days after the connection is removed or the subscription ends.
Chats, memory notes, saved reports, files, dashboards and schedulesUntil the Customer or Member deletes them, or until 30 days after the subscription ends.
Connection credentialsDeleted promptly when the connection is removed or the subscription ends.
Account informationFor the life of the account, then deleted within 30 days after the subscription ends, except as noted below.
Audit log of AI tool callsFor the life of the account, then deleted within 30 days after the subscription ends.
Server logsUp to 90 days.
Database backupsRolling backups that expire on our hosting provider's own cycle. Deleted data can stay in a backup until that backup expires.
Beta applications that do not become customers12 months from the application.
Billing and tax recordsAs long as required by tax and accounting law (generally up to 7 years).
Analytics and error dataAccording to PostHog's and Sentry's own retention settings.

We may keep information longer where needed to resolve a dispute, enforce our agreements or comply with a legal hold.

8. Security

We use technical and organizational measures designed to protect information, including row-level security in our database, encryption in transit, a secrets vault for connection credentials, hashed API keys, mandatory two-factor authentication for password users, invitation-only signup, one active session per user, AI servers with no public internet address, per-Member permissions, and an audit log of every AI tool call. Logs are moved off our servers every 10 minutes to separate storage. More detail is on our security page at https://www.mspstuff.io/security.

No system is completely secure. If we learn of a security incident that affects your personal data, we will notify the Customer and, where the law requires, affected individuals and regulators.

9. Your rights and choices

9.1 Requests about your information. Depending on where you live, you may have the right to ask us to give you access to, correct, delete, export or restrict the use of your personal information, or to object to how we use it. Email us at the address in Section 1. We will respond within 30 days, or sooner where the law requires. We may need to verify your identity first. We will not discriminate against you for making a request.

9.2 If your data came from an MSP's systems. We process that data for the MSP (see Section 2.1). We will pass your request to the MSP and help them respond.

9.3 Customer tools. Customers can purge cached data in the app and can request an export or deletion of account data and saved work by email.

9.4 Marketing emails. You can unsubscribe using the link in any marketing email.

9.5 Complaints. If you are not satisfied with our response, you may have the right to complain to your local data protection authority.

10. Cookies and similar technologies

We use cookies and similar technologies:

  • Essential cookies to sign you in, keep your session secure and remember your settings. The Service does not work without them.
  • Analytics through PostHog, to understand how our website and app are used.

We do not use advertising cookies. You can control cookies through your browser settings. Blocking essential cookies will prevent sign-in.

11. International transfers

We are based in the United States, and our main systems are in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States and in the other countries where our providers operate. Where the law requires, we rely on appropriate safeguards for these transfers, such as standard contractual clauses in our agreements with providers.

12. Children

The Service is for businesses and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy. We will post the new version with a new "Last updated" date. For material changes, we will notify Customer admins by email or in the app before the change takes effect.

14. Contact

AutomatedMSP, LLC (doing business as MSPStuff)1315 Wooten RdNesbit, MS 38651United StatesEmail: bkelly@automatedmsp.com