All legal documents

AI Assistant Connector, what it can and cannot see

What an AI assistant can read through our connector, and what it can never reach.

Last updated 24 September 2026

1. Why this page exists

Gaplessly publishes a Model Context Protocol (MCP) connector at gaplessly.com/api/mcp. An AI assistant that a person has connected it to can use it to answer questions like "what time can I get a table on Friday?" about businesses that take bookings through Gaplessly. This page describes that one surface. For how we handle account and booking data generally, the Privacy Policy is the right document; this page covers only what the connector can reach.

It is separate from the Privacy Policy for the same reason our Meta data deletion page is: a directory reviewing a connector for listing asks for a statement scoped to the integration, and a section buried in a longer policy does not answer that question.

2. What the connector can read

Exactly what any member of the public can already see on a business's own booking page, and nothing else. There is no login, no API key and no credential of any kind on this surface, so there is nothing it could authenticate as in order to see more.

  • A business's public booking profile: its name, the kind of business it is, its public address and phone number if it has published them, and what it offers.
  • Free times, for a service or a party size, on days you ask about.
  • The current date and time at the business, so an assistant does not answer Friday when the venue is already on Saturday.

It cannot read bookings. Not yours, not anyone's. There is no tool that looks a booking up, and the connector has no way to reach one: a booking is only ever readable through the private link sent to the person who made it, and that link is never given to an assistant.

3. What we receive from the assistant

A business identifier, a date, and either a service or a party size. That is the whole of it. We do not receive your name, your email address, your phone number, your conversation, or anything else you said to the assistant, because no tool on this connector accepts those fields. An assistant that asked you for them in order to book through us has misunderstood what it is connected to.

Each request reaches us from the assistant's own servers, so the network address we see belongs to the assistant platform rather than to you. We use it only to rate limit the connector, and we do not attempt to identify a person from it.

4. How a booking is actually made

By you, on the business's booking page, not by the assistant. When you choose a time, the connector hands the assistant a short-lived link to that business's booking page, opened at that time. You open it, you enter your own details, and you confirm. The assistant never sees what you type there.

This is deliberate and it is the main protection on this surface. An assistant cannot commit you to a booking, cannot enter contact details on your behalf, and cannot pay for anything: no payment details are ever collected through the connector, and the link's destination is the same page any other visitor would use.

5. What we keep

Nothing about the conversation. A connector request that only searches for times writes nothing to our database beyond the ordinary rate-limit counter, which holds a network address and a count for a few minutes and is then overwritten.

If you go on to make a booking through the link, that booking is stored exactly as a booking made directly on the page would be, under the business you booked with, and the Privacy Policy's retention section governs it. We additionally record that it originated from the connector rather than from the website, so a business can see how people are reaching them. That record is the word "mcp" on the booking row and contains nothing about you or about the assistant you used.

6. Who the business is, and who we are

The same two roles the Privacy Policy describes apply here. The business you book with is responsible for the booking and for your relationship with them; Gaplessly provides the software. A business appears on this connector because it takes bookings through Gaplessly, on the same public terms as its own booking page.

7. Questions, and changes

Reach us at the address in the Privacy Policy's contact section. If this connector starts doing anything beyond what is described here, such as accepting a guest's contact details or reading an existing booking, we will change this page before that ships rather than after.

Last updated 24 September 2026.