Skip to content
My GoHighLevel MCP

Security & data handling

What we store

| Data | Why | How | |---|---|---| | Your email, name, password hash | Sign-in | Argon2 password hashing | | GoHighLevel sessions | Calling GoHighLevel as you | Encrypted at rest (Fernet / AES-128 + HMAC); one per person and agency | | Claude connection tokens and personal tokens | Letting Claude call the server | Stored only as SHA-256 hashes | | Activity log | Your audit trail | Arguments stored with message bodies removed and emails/phones masked, plus the GoHighLevel endpoints reached | | Billing records | Payments | Card details stay with Cashfree |

Your GoHighLevel password is never stored: it is used once, to sign in. We do not copy your contacts, conversations or pipelines into our database. Tool results pass through to Claude and are not kept.

What Claude can and cannot do

  • Claude acts with the GoHighLevel login of the person asking, so it can never do more than that person could in GoHighLevel.
  • It can reach only the sub-accounts your organisation has chosen (and paid for). Our server checks this on every call; it is not left to the model.
  • Admins can switch off any tool, or all deletes.
  • Tools that import files or fetch web pages can only use public web addresses — never files on our servers or private networks — and your GoHighLevel session is only ever sent to GoHighLevel's own servers.
  • Every call, including refused ones, is in the activity log.

Isolation

Each organisation is a separate tenant. Every query is filtered by organisation, and each person's GoHighLevel sessions are kept apart: one customer's sessions, sub-accounts and logs are unusable by another — even when two organisations sign in to the same agency. This is covered by automated tests on every build.

People and access

Roles: Owner, Admin and Member. Owners and admins use the panel; members use Claude. Removing someone, or turning them off, revokes their Claude connections straight away. Support staff can open your panel only in a read-only session, and each such view is recorded.

Data rights

  • Export: Download my data under Settings.
  • Delete: delete the organisation under Settings. GoHighLevel sessions and Claude connections are removed immediately; the rest of its data is deleted 30 days later.
  • Questions: see the Privacy Policy and DPA.

Reporting a vulnerability

Email the security contact on our contact page (choose "Security / privacy question"). Please give us a reasonable time to fix before disclosure.