TurboForms AI Connector — Privacy Policy Addendum
This addendum supplements Unvired’s main Privacy Policy and applies specifically to the TurboForms Model Context Protocol (MCP) connector and MCP App (“the Connector”), which allow AI assistants such as Claude to create, read, and modify digital forms on your Unvired Digital Enterprise Platform (UMP) instance.
Last updated: July 28, 2026
1. What the Connector Does
The Connector allows a user to interact with an AI assistant (such as Anthropic’s Claude) to:
- Upload PDF documents and convert them into digital TurboForms
- Create, view, update, and finalize form definitions on your configured UMP instance (development, sandbox, or production, as selected by you or your administrator)
- Retrieve form structure, components, validation rules, and embedded images for display
- Visualize a form’s current state through an interactive MCP App interface
The Connector acts on your instructions and only takes actions you or your AI assistant session initiate. It does not act autonomously or outside of an active session.
2. What Data Flows Through the Connector
Depending on which tools are used in a session, the Connector may transmit the following between the AI assistant and your UMP instance:
- Source documents you upload — PDFs or other files provided for conversion into a digital form
- Form content — field names, labels, validation rules, conditional logic, layout structure, and any embedded images or figures
- Configuration and routing information — the UMP instance URL/landscape (dev, sandbox, or production) you or your administrator have configured, and an authentication token or API key used to authorize requests
- Session metadata — form session identifiers, component keys, and status information needed to resume or verify a build in progress
The Connector does not request or require end-user personal data (such as end-customers’ names, health information, or financial details) beyond what may incidentally appear in the content of a document you choose to upload for conversion. You are responsible for ensuring you have the right to upload any such document.
3. Role of the AI Assistant Provider
When you use the Connector through an AI assistant such as Claude, the content described in Section 2 is also processed by that assistant’s provider (for example, Anthropic) in order to generate responses and execute the requested actions. That processing is governed by the AI provider’s own privacy policy and terms — for Claude, see Anthropic’s Privacy Policy and Commercial Terms. Unvired does not control, and is not responsible for, how the AI provider retains, trains on, or otherwise handles data during that processing; please review the AI provider’s own disclosures for specifics on retention and model training.
4. Authentication & Credential Handling
- Authentication tokens or API keys configured for the Connector are used solely to authorize requests to your specified UMP instance.
- Tokens are not stored by Unvired outside of the configuration you provide, and are not embedded in request URLs.
- If you use the desktop (local) version of the Connector, credentials are stored using your operating system’s secure credential store where supported by the host application.
- If you use a hosted/remote version of the Connector, credentials are held only for the duration and purpose of routing your request to the correct UMP landscape, as described in our main Privacy Policy’s data retention section.
5. Data Retention
Form content and documents processed through the Connector are retained on your UMP instance in accordance with your organization’s existing data retention configuration and agreement with Unvired, as described in the main Privacy Policy. The Connector itself does not create a separate, longer-lived copy of your data; it reads from and writes to your UMP instance directly (or, for the hosted gateway variant, routes requests to it without independent storage).
6. Cross-Border Considerations
Where the Connector routes requests to a UMP instance hosted in a different region than the AI assistant’s processing infrastructure, data may transit or be processed in additional countries beyond those disclosed in the main Privacy Policy’s cross-border section. [Confirm and list any additional transit jurisdictions once the hosted gateway architecture is finalized.]
7. Your Choices
- You control which UMP landscape (dev/sandbox/production) the Connector points to.
- You can revoke or rotate the Connector’s authentication token at any time through your UMP administration settings, which immediately stops the Connector’s access.
- Uninstalling or disconnecting the Connector stops all data flow through it; it does not delete data already stored on your UMP instance.
8. Contact
Questions about this addendum can be directed to the same contacts listed in our main Privacy Policy: legal@unvired.com





