Privacy policy — MyInvestor MCP (MCP App)

Last updated: 2026-06-26

This privacy policy applies to MyInvestor MCP, the official MyInvestor connector for Claude.ai, ChatGPT and other MCP clients. The connector lets you browse MyInvestor’s public mutual fund catalogue from a chat conversation.

The connector is operated by MyInvestor (MyInvestor Banco, S.A.) and supplements — without replacing — the master privacy policy that governs the MyInvestor website and app. Where this document does not cover a matter, the MyInvestor master policy prevails.


Scope

This policy covers two surfaces of the connector: (1) what happens when you invoke one of the connector’s seven tools (search_funds, compare_funds, get_funds, search_portfolios, compare_portfolios, resolve_funds, list_facets) from an MCP host (Claude.ai, ChatGPT or any other compatible client) and the host renders the resulting iframe in the conversation; and (2) the connector’s public website (mcp.myinvestor.es) — the landing page and the policy and support pages — including its analytics cookies (see “Public website cookies” below). It does not cover the rest of MyInvestor’s services (web banking, mobile app, customer area), which are governed by the master policy at https://www.myinvestor.es.

What the connector does

When you invoke a tool, the host forwards the parameters you (or the model) supplied to the connector’s HTTPS /mcp endpoint. The connector queries a read-only snapshot of MyInvestor’s public fund catalogue and returns the results to the host, which renders them inline in the chat.

The data served is the same information MyInvestor publishes on its product web pages. No live calls to MyInvestor’s internal APIs are made during an invocation, and the connector never reads any client information.

What is logged

Each request to /mcp produces a technical log line with request metadata (such as the timestamp, method, tool invoked, duration, and response code), with no query content or personal data.

What is not logged:

Anonymized IP in security events. When a request is rejected because its Origin header is not on the allowlist (origin_denied security event), a truncated/anonymized IP address is recorded for abuse detection: the last octet is zeroed for IPv4 addresses (e.g. 192.168.1.0), and IPv6 addresses are truncated to /48. The full IP address is never stored. The same anonymization applies to the IP recorded for the interaction events described below.

Interaction events. To understand which products are shown and consulted most and how many people proceed to MyInvestor from the connector, we record interaction events with the iframe — a fund or portfolio appearing in the results, viewing its details, and using the MyInvestor button — identified only by the public product identifier (the fund’s ISIN or the portfolio identifier). They use no cookies or client storage and record no personal or account identifier — only which public product was shown or consulted, never who.

Log retention. Beyond the anonymized IP, the request metadata in the table above, and the interaction events described above, the log stores no query content and no personal data.

Cookies and client storage (connector and iframe)

The /mcp endpoint and the iframe rendered inside the chat do not set cookies and do not use client storage (localStorage, sessionStorage, IndexedDB). The interaction events described under “What is logged” likewise use no cookies or storage.

Public website cookies

The public website (mcp.myinvestor.es) — the landing page and the policy and support pages — uses Google Analytics 4 under Google’s Consent Mode v2. Before you accept analytics cookies, Google Analytics is loaded with analytics storage denied and may receive aggregate cookieless page and event measurements. If you accept via the cookie banner, analytics cookies are enabled; if you reject, no analytics cookie is set.

Cookie Type Provider Purpose Expiry
_ga, _ga_<id> Analytics Google Analytics 4 (Google) Measure site usage in aggregate (page views, sessions) to improve it ~24 months
myi_cookie_consent Technical (necessary, consent-exempt) First-party (stored in localStorage) Remember your choice about analytics cookies Persistent

Technical storage is strictly necessary and requires no consent. Analytics cookies are only enabled if you accept them: Google Analytics starts with analytics storage denied by default, and storage is granted only after your acceptance. We use no advertising or personalization cookies.

How to withdraw or change your consent. You can change your choice at any time from the “Cookie settings” link in the footer, which reopens the banner. You can also block or delete cookies from your browser settings (Chrome, Firefox, Safari, Edge or Opera).

For details on the cookies MyInvestor uses across the rest of its services, see MyInvestor’s cookie policy. To exercise your data protection rights you can contact MyInvestor’s Data Protection Officer at dpo@myinvestor.es.

Third parties

The connector itself does not call any third-party API at request time.

Data origin

The catalogue snapshot is derived from MyInvestor. It contains only publicly listed product attributes (name, ISIN, TER, AUM, performance history, etc.) — no client data whatsoever. MyInvestor’s master privacy policy covers any action you take on the rest of their website or app.

The iframe exposes deep links to MyInvestor’s public website for actions beyond the connector’s scope — mainly the fund subscription flow. Clicking one of those links opens the URL in a new browser tab; from that point MyInvestor’s website terms and master policy apply, including authentication and client data processing.

Minors

The connector is intended for adult individual investors. It does not knowingly process data from persons under 18 years of age.

Changes to this policy

If we materially change what is logged or how data flows through the connector, we will update the Last updated date and the corresponding metadata in the connector directory.

Contact

For any questions about this policy or to exercise data protection rights specifically relating to the connector, write to info@gptadvisor.com. For everything else, refer to MyInvestor’s master policy and the contact channels listed there.