1. Scope
mcclipface.com, getclippy.co and McClipFace are operated by GetClippy LLC, a New York limited liability company. In this policy, “we,” “us” and “our” mean GetClippy LLC.
This Privacy Policy applies to mcclipface.com and getclippy.co (the same site at two addresses), its hosted coupon API, the MCP server at mcclipface.com/mcp (also at getclippy.co/mcp), and the McClipFace instruction skill (together, the “Service”), including when the Service is used through Muse, Meta's consumer AI assistant, or through another AI assistant. It does not govern a retailer, affiliate network, shopping agent, AI assistant (including Muse itself), browser, or other third-party service.
2. Information processed
Coupon lookups
The McClipFace install sends only a merchant name, or a product name when the user names a product rather than a store, and currency with a lookup, and, optionally, the address of a product page the shopper picked; it does not send cart contents, items, prices, subtotals, shipping amounts, or checkout totals. Lookups send the store or product name and currency, and, optionally, the address of a product page the shopper picked, in every mode, Private mode included; Private mode stops reports, not lookups. Checkout totals are compared locally by the user's AI assistant. At the start of the first shopping task each week, and whenever a McClipFace response shows a newer version, the McClipFace install may also ask mcclipface.com/api/version for the current version of its instructions; that request sends no lookup or user data, and the Service stores nothing from it. Older clients may still send a cart subtotal or shipping amount; the API ignores and does not store them, and the MCP connector rejects them. The Service processes lookup values to find and rank applicable offers. The application does not store the raw search text in its analytics database or create a per-user shopping history; aggregate counts record only which catalogue store, if any, a lookup matched, as described below. Hosting and security providers may temporarily process request URLs, IP addresses, user-agent information, timestamps, and similar connection data to deliver and protect the Service.
To enforce the direct API’s lookup limit (30 lookups per hour per connection, or 600 for known AI assistant fetchers, on /api/coupons, /api/deals and /api/shop/proof), each lookup also increments a short-lived counter keyed by a one-way keyed hash (HMAC) of the requesting IP address and the current hour; the counter holds only a lookup count, never the IP address itself, and expires within about one hour. The user agent is checked only to pick which limit applies and is not stored. Lookups through the MCP server don’t count toward this limit. Each request turned away by the limit adds one to a daily total that holds no IP address, hash or other caller data.
MCP server and AI assistants such as Muse
When an AI assistant such as Muse (Meta's consumer AI) calls the MCP server at mcclipface.com/mcp or getclippy.co/mcp, the request contains only the tool name and its arguments: a store name and currency (and, optionally, the address of a product page the shopper picked) for find_coupons, a product name and currency for find_product_coupons, a currency, a number of results, and optionally a store or brand filter and a yes/no setting for sensitive categories, for get_deals, or, for report_coupon_result, the store name, the code that was tried, the outcome, and optionally an eligibility status and the offer ID. The connector accepts no amounts: a saved amount or any other extra field is rejected. It does not include your name, account, chat history, cart contents, prices, or totals, and the Service does not ask the assistant for them. Lookup calls are logged only in the aggregate usage counters described below: totals by tool, outcome, and matched catalogue store. They create no per-user records, and the raw search text is not stored. A report_coupon_result call also stores one anonymous coupon result report or broken-link report, described below. MCP calls also count toward the anonymous adoption estimates described below, which keep only one-way hashes in aggregate sketches and no list of clients. To enforce the MCP server's rate limit, each request also increments a short-lived counter keyed by a one-way keyed hash (HMAC) of the requesting IP address and the current minute; the counter holds only a request count, never the IP address itself, and expires within about two minutes. The assistant provider processes your conversation, including what you ask it to look up, under its own privacy policy (for Muse, the Meta Privacy Policy), not this one.
find_coupons can also optionally receive the address of a product page on the matched store’s own website that the shopper picked (POST /api/deeplink accepts the same). When an assistant sends McClipFace a product page address to build a shopping link, in the POST body to /api/deeplink or as the find_coupons target_url argument, McClipFace uses it only to build that one link on our server and send it straight back. Any query string or fragment is removed from the product address before use. The address isn’t logged, stored, cached or counted, and McClipFace never opens it or sends it anywhere. If the shopper follows the shopping link, the network and the store receive that page address as the link’s destination, like any affiliate link.
Aggregate service analytics
For each coupon lookup, the Service records daily and all-time request totals and whether live data was available. It also estimates daily and monthly distinct network clients. To do that, it briefly processes the requesting IP address and user agent in memory, combines them with a secret using HMAC, and sends only rotating pseudonymous values to Redis cardinality counters. The application does not store the raw IP address or user agent in those counters. These figures are approximate because many people may share an AI assistant provider or network address.
For coupon, deal, report, MCP tool-call, and install-link requests, the Service also keeps anonymous adoption counts: estimates of distinct network clients per day, week, and month, and new versus returning clients. To do that, it combines the requesting IP address and a coarse user-agent category (such as “assistant” or “browser”) in memory with a secret key that changes every quarter, and adds only the resulting one-way hash to Redis HyperLogLog sketches. The sketches cannot be turned back into IP addresses, user agents, or per-client records, and the application keeps no list or history of individual clients. Install links (getclippy.co/i and mcclipface.com/i) may carry a short campaign tag, such as ?ref=bio; only aggregate counts per tag are stored.
The Service also keeps aggregate usage counts for all requests: daily and all-time totals by endpoint, response status class (such as success or error), matched store name, and outcome (for example, whether a lookup found any offers, which MCP tool was called, or whether a report was stored). These counts contain no IP address, user agent, hash, or raw search text, and a lookup that matches a store in a sensitive category is counted without the store name. Adoption figures and usage counts are published only as aggregate totals, at /api/stats/adoption and /api/stats/usage.
McClipFace keeps anonymous daily usage counts. To estimate how many distinct callers we get, your IP address and user agent are combined with a random value that changes every day and is deleted after about 2 days, and only the resulting one-way hash goes into a counter. We never store IP addresses or user agents, and we keep only daily totals, for about 400 days. These counts cover downloads of the McClipFace install files (SKILL.md, install.md and the install zip), and counting them does not change what those downloads contain.
Website analytics (Google Analytics)
The mcclipface.com and getclippy.co web pages load Google Analytics 4 (measurement ID G-ZP5HKW057J), a service provided by Google. When you visit a page, the Google Analytics tag sets first-party cookies on the site you visit, mcclipface.com or getclippy.co (such as _ga and _ga_ZP5HKW057J) that let Google Analytics recognize a returning browser, and it sends Google information about the visit: the page URL and title, the referring page, approximate location derived from your IP address, browser and device characteristics, screen size, language, and interactions such as page views, scrolls, and outbound link clicks. We use the resulting reports to understand how people find and use the website. Google processes this information under its own terms and privacy policy, and may combine it with other information as described there. Google Analytics, the Meta Pixel and OpenAI's ads measurement pixel run on the website only; none of them is part of the hosted coupon API, the MCP server (/mcp and /mcp/read) or the McClipFace install instructions, and McClipFace never sends coupon lookups made by an AI assistant to Google, Meta or OpenAI.
Ad measurement (Meta Pixel)
We may advertise McClipFace on Facebook, Instagram, and other Meta services. To measure whether those ads work, the mcclipface.com and getclippy.co web pages load the Meta Pixel, a small piece of code provided by Meta Platforms, Inc. The pixel sends Meta information about your visit: the page URL, the referring page, your IP address, browser and device information, and a few actions on the page, such as viewing a page or tapping “Copy the Muse prompt.” It can set first-party cookies on mcclipface.com or getclippy.co (_fbp, and _fbc when you arrive from a Meta ad), and Meta may read cookies it has already set in your browser. When you copy a setup prompt or link, our server also sends Meta a record of that copy (the event, a random event ID, the time, the page URL and which button was used) with your IP address, browser user agent, and Meta’s cookie identifiers (_fbp, _fbc) or the ad click ID from the link you arrived through, so Meta can match it to an ad. Our server passes these along without storing or logging them. Nothing is sent from our server for our own test traffic, requests with no user agent or one that names a known bot, requests from other sites, or preview builds. We keep that ad click ID and when you arrived in your browser for up to 90 days. If you use Facebook or Instagram, Meta may match this information to your account. We use the resulting reports to count how many visits and prompt copies came from our ads and to improve which ads we show. We do not send Meta your name, email address, or any coupon lookup, cart, or purchase details. Meta processes this information under its own terms and the Meta Privacy Policy. The website also uses OpenAI's ads measurement pixel to measure whether our ads in ChatGPT bring people to the site, which sends OpenAI page views and clicks or copies of the links that add McClipFace to your AI.
Coupon result reports and Community mode
With Community mode on, after an AI assistant tries a code at checkout, it reports the result anonymously. Each stored report contains only: a random report ID; the offer ID, which points back to the store and code; the store’s website (or the store name in lowercase if there is no website); the code exactly as it was served; the outcome (“worked” or “rejected”, or “unverified” in a report sent to the direct API); an eligibility status (whether the code’s stated requirements were met, or unknown); a consent flag; a source tag showing where the report came from (for example, mcp); a yes/no for whether the checkout total went down (only when a client of the HTTP report endpoint sends this yes/no; the MCP connector never accepts it, and no amount is ever stored with a report); and the time the report was stored. With Community mode on, the AI assistant reports every result, worked or failed, without asking each time. If Community mode was chosen under McClipFace instructions older than version 1.4.0, or the AI assistant can’t tell which version, it stops sending reports and asks the Community or Private question again at the start of the next session; it sends reports again only after the user says yes, and anyone who doesn’t answer stays in Private mode. With Community mode off (Private mode, or before the user chooses), the AI assistant sends no reports at all, not even for codes that worked. Assistants using the McClipFace connector in Meta’s Muse may still report codes that worked when Community mode is off; reports contain the same limited fields described above. If a host or workspace setting does not allow reports, the AI assistant sends none. No IP address, user agent, account, name, cart contents, items, prices, totals, savings amount, order number, or payment details are stored with a report, and the Service rejects reports that contain other fields. Like any web request, each report reaches the Service with connection metadata such as the IP address and user agent. Connection data is processed to rate-limit lookups and reports, to count at most one report per network address (as a one-way hash) per store and code in any 24 hours, and to count how many different callers report a broken link (described below); a repeat report is stored but not counted again. The stored report does not contain a raw IP address. Codes with more worked than failed reports in the last 14 days are shown as confirmed by shopper reports (the verified field), which is not a guarantee that a code will work.
With Community mode on, an AI assistant that opens an offer’s link and finds that it ends on an error page or never reaches the store can report the link as broken. A broken-link report is not a coupon result report and never counts for or against the code. For each reported offer, the Service keeps only the offer’s details (the offer ID, the store’s website, the code, the offer’s link, the store’s web addresses and the affiliate network), the times of the reports, a report count, whether the offer is flagged or hidden, and the results of any link check. An offer is hidden once 2 different callers report it within 72 hours, or right away if the link checker finds the link dead. To tell callers apart, the Service keeps a separate record for 72 hours that holds only a one-way hash made from the hashed network address and the offer ID, the same approach used to count a coupon result report once per caller. No IP address, user agent, account, name, cart contents, prices or totals are stored with a broken-link report. Flag, hide, restore, link check and expiry steps are also written to our internal change log with the offer’s details and a report count, never anything about who reported; link check entries also record the final host and HTTP status. To check whether offer links still work, the Service’s link checker sends HEAD requests (or, for a site that doesn’t accept them, a GET whose page it doesn’t read) with the user agent McClipFace-LinkCheck/1.0 (+https://mcclipface.com); it contacts the offer’s tracked link and each redirect it leads to, not the user, and sends no user data.
Optional savings reports
The McClipFace install does not ask AI assistants to send savings reports, and Community mode never includes savings amounts. The API retains a legacy savings endpoint: with separate affirmative consent after a completed checkout, a client may submit a random event ID, savings amount in integer minor units, currency, consent confirmation, and checkout confirmation. These reports do not contain identity, merchant, order, payment, or cart information. Public savings figures are aggregated by currency and are community-reported, not independently audited.
Optional weekly digest
If you ask your AI assistant for a weekly digest, the AI assistant or its host (not McClipFace) stores and runs the schedule under that provider's privacy practices. Each run sends McClipFace the selected currency and requested result limit, and optionally a store or brand filter and whether to include sensitive categories, and receives a current catalogue selection. McClipFace does not require an email address or maintain a subscriber list for this feature.
Information you send us
If you contact us, we process the information in your message and your contact details to respond, keep appropriate business records, and protect the Service.
3. How information is used
- Return and rank current coupon offers.
- Measure reliability, capacity, and adoption in aggregate.
- Understand website traffic and usage through Google Analytics.
- Measure whether our ads on Meta services bring people to the website, using the Meta Pixel.
- Measure whether our ads in ChatGPT bring people to the website, using OpenAI's ads measurement pixel.
- Use recent, opted-in outcomes to lower the ranking of repeatedly rejected eligible offers and to avoid counting accepted codes that did not lower the checkout total as successes.
- Hide offers whose links are reported or found broken.
- Display opted-in, completed-checkout savings totals.
- Prevent abuse, troubleshoot failures, and secure the Service.
- Meet legal obligations and enforce the Service terms.
4. Disclosure to others
We use infrastructure providers, including Vercel for hosting and Upstash for Redis storage, to operate the Service. They process information on our behalf under their applicable terms and privacy practices. We use Google Analytics (provided by Google LLC) to measure website use; when you visit mcclipface.com or getclippy.co, page-visit information and analytics cookie identifiers described in section 2 are sent to Google, which processes them under its own terms and privacy policy. See how Google uses information from sites that use its services. The page-visit and button-click information described in section 2 is sent to Meta Platforms, Inc., from your browser by the Meta Pixel and, when you copy a setup prompt or link, also from our server; Meta processes it under the Meta Privacy Policy. The page view and button click information described in section 2 for OpenAI's pixel is sent to OpenAI OpCo, LLC, which processes it under the OpenAI Privacy Policy. We may also disclose information when required by law, to protect rights and safety, or as part of a business transfer.
Coupon feeds come from affiliate programs McClipFace has joined, including through the affiliate networks CJ Affiliate, Impact, Awin and Admitad, and from direct brand programs. Some coupon codes and shopping links come from a licensed coupon data partner, and those links may earn McClipFace a commission. McClipFace fetches those feeds centrally; a coupon lookup does not itself send the shopper’s query to those networks or brands. Affiliate networks and our coupon data partner send us reports of clicks and commissions earned per store and day, which we keep to run the business; we do not receive or store order numbers, items, purchase amounts, or anything that identifies the shopper. If a user or an AI assistant follows a tracked shopping link, the destination retailer, any affiliate network involved and our coupon data partner, whose link handles the click, may receive the IP address, browser or device data, referrer, cookie or similar identifiers, and transaction attribution information. Their policies, not this one, govern that processing.
5. Affiliate tracking and privacy signals
We do not sell personal information for money. Tracked links support commission attribution and may involve third-party cookies or similar technologies after the link is opened. Depending on the law that applies to you, this activity may be treated as “sharing” or targeted advertising. You can avoid this third-party tracking by not opening a tracked link and instead navigating to the retailer independently or using a coupon code manually. The McClipFace website uses Google Analytics, which sets first-party analytics cookies and sends page-visit information to Google as described in section 2. The Meta Pixel is used to measure our ads and can set the _fbp and _fbc cookies, and the site keeps the ad click ID from a Meta ad link and when you arrived in your browser’s local storage for up to 90 days; depending on the law that applies to you, this may be treated as targeted advertising or “sharing.” You can limit how Meta uses this information for ads in your Facebook or Instagram ad preferences, including the setting for activity information from ad partners, and you can block the pixel with a content or tracker blocker or your browser’s tracking protection, or by blocking or deleting cookies. OpenAI's ads measurement pixel is used to measure our ads in ChatGPT and can set the __oppref and __obref cookies; depending on the law that applies to you, this may be treated as targeted advertising or sharing. If you use ChatGPT, you can turn off ads personalization and clear ads data under Settings, then Ad Controls, and you can block the pixel with a content or tracker blocker or your browser's tracking protection, or by blocking or deleting cookies. You can limit Google Analytics by blocking or deleting cookies in your browser, using a content blocker, or installing Google’s Google Analytics opt-out browser add-on; the coupon service and the website work the same either way. The website does not respond differently to browser “Do Not Track” signals. A universal opt-out signal may still be honored by the destination retailer or network under its own policy.
6. Retention
- MCP rate-limit counters expire within about two minutes.
- Lookup rate-limit counters, keyed by a one-way keyed hash of the IP address and the current hour, expire within about one hour. Daily totals of requests turned away by the limit hold no caller data and are kept for about 400 days.
- Daily approximate-client counters expire after about 40 days; monthly counters expire after about 400 days. These monthly aggregate counts hold only pseudonymous HyperLogLog values, not a per-person record.
- Daily install-file download counts are kept for about 400 days, and the random daily value used to hash callers for them is deleted after about 2 days.
- Per-day aggregate usage counts (by endpoint, status class, matched store and outcome, with no IP address, user agent, hash or search text) are kept for about 400 days.
- Anonymous adoption sketches expire after about 40 days (daily), 100 days (weekly), and 120 days (monthly), and their hashing key changes every quarter.
- Google Analytics event data is kept for the retention period set in Google Analytics (Google offers periods from 2 to 14 months); aggregated reports may be kept longer. Google Analytics cookies typically expire after up to 2 years unless you delete them sooner.
- The Meta Pixel
_fbpcookie typically expires after about 90 days unless you delete it sooner. Meta keeps the information it receives under its own retention practices. - Meta Conversions API (setup prompt and link copies): daily outcome counts are kept for 90 days, and running totals of outcomes may be kept indefinitely; neither holds caller data. Rate-limit counters, keyed by a one-way keyed hash of the IP address, expire within 2 minutes (per-minute counters) and 2 days (per-day counters). A one-way hash of each event ID, used to stop duplicates, is kept for 48 hours, and a daily count of all events is kept for 2 days. No IP address, user agent or Meta identifier (
_fbp,_fbcor ad click ID) is stored. The ad click ID and arrival time in your browser’s local storage are kept for up to 90 days. - OpenAI's ads measurement pixel cookies typically expire after about 30 days (
__oppref) and 365 days (__obref) unless you delete them sooner. - Aggregate request totals and aggregate savings totals may be kept indefinitely because they are not intended to identify a person.
- Individual coupon result reports are deleted once they are older than 90 days; the cleanup runs whenever a new report is stored.
- Daily worked and failed counts per store and code are dropped after 14 days, and the counter itself expires 15 days after the last report. Coupon outcomes are used in a seven-day evidence window per offer and a 14-day window per store and code.
- Report rate-limit records, keyed by a one-way keyed hash of the IP address, expire after 1 hour. Duplicate-check records that allow one counted report per caller per store and code expire after 24 hours, and the record that stops the same report ID from being stored twice expires after 90 days. Provider logs and backups may persist for a limited additional period.
- Broken-link reports: the record that tells callers apart (a one-way hash made from the hashed network address and the offer ID) expires after 72 hours. Broken-link rate-limit records, keyed by a one-way keyed hash of the IP address, expire after 1 hour, and the record that stops the same report ID from being stored twice expires after 90 days. A flagged offer’s record (its details, report times and link check results) is deleted at the daily cleanup once 72 hours pass without another report. A hidden offer’s record is deleted when the offer comes back: when a link check finds the link working, or at the daily cleanup 7 days after the last report or failed check. Change log entries for broken-link steps hold no caller data and are kept until we remove them.
- Individual savings reports (a random event ID, amount, currency, and the consent and checkout confirmations) are not deleted automatically and are kept until we remove them. The record that stops the same savings event ID from being stored twice expires after one year. Savings rate-limit records, keyed by a one-way keyed hash of the IP address, expire after 1 hour. Savings totals by currency may be kept indefinitely.
- Install-link counts by day, source, coarse user-agent category and campaign tag may be kept indefinitely.
- Correspondence is kept only as long as reasonably needed for fraud prevention, legal compliance, and dispute resolution.
7. Your choices and rights
You can use coupon lookup in Private mode, in which the AI assistant sends no coupon result reports (the McClipFace connector in Meta’s Muse is the one exception, described under coupon result reports). Lookups work the same in both modes and still send the store or product name and currency, and, optionally, the address of a product page the shopper picked. You can turn Community mode off at any time, and no further reports are sent. You can also avoid affiliate tracking, limit Google Analytics, and limit or block the Meta Pixel and OpenAI's ads measurement pixel as described above.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or information about disclosure of personal information, and to appeal or complain to a regulator. Because McClipFace intentionally avoids account profiles and direct identifiers, we may be unable to locate aggregate or pseudonymous records as belonging to you. To make a request, email clippy@getclippy.co. We may need to verify the request and may retain information when legally permitted or required.
8. Security
We use reasonable administrative and technical safeguards, including server-side credentials, data minimization, validation, rate limits, rotating pseudonymous analytics identifiers, and restricted operator endpoints. No system is perfectly secure, and we cannot guarantee absolute security.
9. Children
The Service is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
10. International use
The Service is operated in the United States and information may be processed there and in other locations where service providers operate. Local privacy rights may still apply.
11. Changes
We may update this policy as the Service or law changes. We will post the revised policy here and update the effective date. If a change materially affects how previously collected information is used, we will provide additional notice when reasonably required.
12. Contact
GetClippy LLC operates the Service. Questions or privacy requests: clippy@getclippy.co.