The first question everyone asks is "so the AI will see everything?" The short answer is no.
Here is exactly what it sees, what it never sees, and who sets the boundary.
By default - only what is already public
For most businesses MCP reads only the public content of your site - exactly what any
visitor sees anyway: services, prices if they are published, common questions, hours. Not
code, not the database, not passwords, not closed areas. And this is not a promise you can
forget to keep - it is simply the boundary of how the work is built: there is no
connection to your systems, because none is needed.
What AI never sees
Personal customer data, orders, records, anything sitting in your closed systems - stays
closed. Unless you deliberately open a controlled channel to it, it has no way to get
there. In short: what is open to everyone gets read; what isn't, doesn't.
And when closed data is genuinely needed
There are cases - usually a business with a custom task - where the AI does need to reach
closed data to answer for real. Even then privacy is built in: least privilege (it sees
only what the task needs), personal data anonymised before it reaches an external model,
and every access logged. The solution is built to meet your field's requirements - GDPR,
medical, governmental.
You set the boundary
You define what the AI may read and what it may do. We don't open more than we agreed, and
it stays under your control. If something isn't needed for the task, it simply isn't
opened in the first place - not a box you have to remember to switch off, but part of the
design.
Why this is actually an advantage
Think about the alternative: with no orderly source, AI gathers scraps about you from all
over the web - old copies, listings, guesses. One clean, controlled source isn't only more
accurate - it is also more transparent about what is exposed and what isn't. Real privacy
isn't "nobody knows anything", it is you knowing exactly what is open and holding the key.
The right question isn't "will the AI see", but "who decides what it sees". With MCP -
you do.
Have sensitive data or a non-standard task? We'll explain exactly what gets opened, what is hidden and what is logged - for your case.
Talk about the task