When you connect an AI agent to CloudBees Unify using MCP, your data is handled according to CloudBees' standard privacy and security practices.
Privacy principles
CloudBees Unify MCP follows the same privacy and data handling practices as other CloudBees Unify features.
For complete information, refer to:
What is visible to CloudBees
When you use MCP, the following is visible to CloudBees:
-
Tool calls: Which CloudBees Unify operations your AI agent requests (for example, "list components" or "get build logs").
-
Tool parameters: The specific resources you’re accessing (component names, workflow IDs, etc.).
-
Your user account: All actions are attributed to your authenticated user account.
CloudBees does NOT see:
-
Your AI conversations: The questions you ask your AI agent stay between you and your AI service (Claude, Gemini, etc.).
-
Your prompts or context: Only the tool call contents (tool names and parameters) are sent to CloudBees, not the surrounding conversation. However, tool parameters may contain text from your conversation if your AI agent includes it in a tool call.
What is visible to your AI service
Your AI service (Anthropic for Claude, Google for Gemini) handles your conversations according to their privacy policies:
-
Claude (Anthropic): Anthropic Privacy Policy
-
Gemini (Google): Gemini Apps Privacy Notice
CloudBees Unify only receives tool call contents, not your surrounding conversation.
Audit and compliance
All MCP activity is logged for audit and compliance purposes.
Contact CloudBees Support for:
-
Audit inquiries or security investigations.
-
Compliance reporting requirements.
-
Questions about data retention policies.
Best practices
To protect your privacy:
-
Use dedicated accounts: Create service accounts for your AI agent to use rather than personal accounts.
-
Apply least privilege: Only grant the minimum roles needed for AI operations.
-
Understand your AI service’s policy: Know how your AI service (Claude, Gemini) handles conversation data.
Refer to Secure your MCP connection for more security guidance.