Effective October 6, 2026 · Operated by Tampa Web Technologies Inc
This policy covers the AEO Ultimate connector for Claude: the hosted connector at mcp.aeoultimate.app and the account at app.aeoultimate.app that holds your sites’ connection keys. The connector lets Claude, Anthropic’s AI assistant, read the answer engine optimization (AEO) data of your WordPress sites and Shopify stores and, only where you allow it, make changes you approve.
It adds to, and does not replace, the privacy policy of the TWT AEO Ultimate WordPress plugin and the privacy policy of the AEO Ultimate Shopify app, which covers what the app stores for a Shopify store, including its change history. What Claude does with the answers it receives is covered by Anthropic’s privacy policy.
The short version
- We pass Claude’s requests to your sites and the answers back. We do not store the answers, and we never see your conversations with Claude.
- We store your account, the list of sites you add, and each site’s connection key, encrypted.
- Passwords, sign-in tokens and codes are stored only as one-way hashes, so they cannot be read back, even by us.
- Your sites and stores keep their own rules: on WordPress the connector works only for site administrators; on Shopify it needs the app’s Mid or Pro plan and a key the store owner creates. Changes are off until you switch them on, and every change is previewed first and can be reverted on the site or in the app.
- Claude never receives Shopify order or customer data: the connector cannot read it.
- We never sell your data, use it for advertising, or use it to train any AI model.
1. What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Account: your name or business name, email address, and password (stored only as a scrypt hash) | You, when you create an account at app.aeoultimate.app | To sign you in, including when you connect Claude |
| Your sites: each site’s or store’s address, label and platform (WordPress or Shopify), and the client or business it belongs to | You | So Claude can tell your sites apart and reach the right one |
| Connection keys: the WordPress Application Password each site created for Claude, or the connection key a Shopify store created in the AEO Ultimate app, encrypted (AES-256-GCM) | You paste it from TWT AEO → Settings → MCPs on a WordPress site, or from AEO Ultimate → Settings → Use with Claude in a Shopify admin | To sign in to that site’s connector for you. It is decrypted only for the moment a request is made |
| Connection health: the site name it reports (for a Shopify store, the store’s .myshopify.com address), whether it allows changes, when it last answered, and the last error | Your site, when the key is checked and when Claude uses it | To show you which sites are working and why one is not |
| Claude connection records: the name and return address Claude registers, and sign-in codes and tokens (stored only as hashes) | Claude, when you connect it and sign in | To let Claude act for your account until you disconnect it or the tokens expire (access tokens after 1 hour, renewal tokens after 60 days of no use; each renewal replaces the old token) |
| Plan status: your Claude plan, trial dates and site limit | Our records | To apply the free one-site limit, the 14-day trial and the multi-site plan |
| Server logs: IP address, time, address requested and response code | Every request to our servers | Security, abuse prevention (including rate limits) and troubleshooting |
2. What passes through but is not stored
When Claude uses a tool, we receive its request (for example which site, which page or product, and for a change, the new text) and pass it to your site, or for a Shopify store to the AEO Ultimate Shopify app; the answer (for example AI citation results, AI crawler visits, Google indexing status, schema findings, catalog gaps, product details or page scores) comes back through us to Claude. We do not store requests or answers. Your sites and the Shopify app never send API keys, plugin or app settings, visitor IP addresses, the full text of AI answers, or Shopify order or customer data through the connector.
We do not receive or read your Claude conversations, chat history, memory or files. Claude sends only what a tool needs.
3. How we use it
- To run the connector: sign you in, check each site’s key, and pass Claude’s requests to the right site.
- To apply your plan, and to tell our team when a multi-site trial starts so we can follow up.
- To keep the service secure and running, and to fix problems you report.
People on our team do not look at your sites’ data except to resolve a support request you raise, with your permission, or where the law requires it.
4. Who else receives data
- Anthropic. The answers your sites give are delivered to the Claude app you connected, under Anthropic’s privacy policy.
- Your own sites. Claude’s requests go to the WordPress sites you added, signed in with their connection keys.
- The AEO Ultimate Shopify app. For a Shopify store, requests go to the app at store.aeoultimate.app, which we also operate (hosted on Vercel), signed in with that store’s connection key. The app answers only for the store the key belongs to.
- Hosting. The service runs on a server we operate, rented from Liquid Web, L.L.C. in the United States.
We share nothing else, and we sell nothing.
5. How long we keep it
| When | What happens |
|---|---|
| You remove a site’s connection key, or the site | The encrypted key is deleted right away. |
| You disconnect Claude | Its tokens expire on their own: access tokens after 1 hour, renewal tokens after 60 days unused. They are stored only as hashes. To cut off access at once, remove the site’s connection key here, or turn the connector off (or revoke its key) on the site or in the Shopify app. |
| You ask us to delete your account | Your account, sites, keys and connection records are deleted within 30 days. |
| Server logs | Kept for about 14 days, then deleted as logs rotate. |
| Backups | Deleted data leaves our backups within 14 days as older backups expire. |
6. Security
All traffic is encrypted (HTTPS). Claude signs in through OAuth 2.1 with PKCE, and a renewal token used twice ends the whole sign-in. Connection keys are encrypted and passwords, tokens and codes are hashed. The database cannot be reached from the internet, each account’s data is kept apart, and the service will not call private or internal network addresses. On each site and store, the connector is off until its owner turns it on, changes need a separate switch, and every change is previewed, confirmed and logged with a one-click revert. No system is perfectly secure, but we work to protect your data and limit who can reach it.
7. Your rights
You can remove sites and connection keys at any time at app.aeoultimate.app, turn the connector off on any WordPress site under TWT AEO → Settings → MCPs and revoke its Application Password in your WordPress profile, and turn the connector off or revoke its key in a Shopify store under AEO Ultimate → Settings → Use with Claude. Depending on where you are, laws such as the GDPR or the CCPA/CPRA may give you further rights to access, correct, export or delete your data. For any request, including deleting your account, email david@tampawebtech.com.
8. Children
The service is for businesses and site owners. It is not directed to children under 16, and we do not knowingly collect their data.
9. Changes
If this policy changes, we will update the date at the top and, for significant changes, tell you by email or in the dashboard.
10. Contact
Tampa Web Technologies Inc
8005 Tierra Verde Dr, Tampa, FL 33617
david@tampawebtech.com