MCP server

Privacy and redaction

What a tool result contains, what is held back by default, and what is recorded when an assistant asks for more.

Whatever a tool returns goes into your assistant's context, and from there to the model provider that assistant uses. That is outside Oleon. So the server returns what answers most questions, which is when something happened, which way it went and whether it worked, and holds back what most questions do not need.

What is redacted by default

DataWhat the assistant receives
Message text, captions, previews and snippets[redacted] (42 chars), with the length kept
Phone numbers and WhatsApp IDsThe last four digits, as •••4821
Email addressesThe first letter and the domain, as j•••••@example.com
Links to attachments and mediaRemoved entirely

The length stays because it still answers useful questions, such as whether a customer sent a one-word reply or three paragraphs, without revealing the words. Attachment links are removed rather than masked because a working link is a credential: anyone holding it could download the file.

Everything else, such as timestamps, directions, delivery status, failure reasons, labels, assignees and order totals, is returned as it is.

Asking for message text

Two tools accept include_message_text:

When an assistant sets it to true, that one call returns the words themselves. Phone numbers and email addresses stay masked, and attachment links stay removed.

The result says which case applies in its _meta block, so neither you nor the assistant has to guess:

JSON
{
  "data": { "…": "…" },
  "_meta": { "message_text": "included and audited" }
}

Assistants are told to ask for message text only when a question cannot be answered without it. You can also tell yours directly, for example: "Don't read message text unless I ask."

What is recorded

These events are written to Oleon's audit log under the MCP category, with the person, the time and the details:

EventRecorded detail
A tool call that includes message textThe tool, the project and the arguments it was called with
A Bot Studio draft created with create_flow_versionThe project, the flow type, the instance and the version number
A connection approved through OAuthThe app that asked, by the name it registered
A connector token created or revokedThe token's name

Reads that do not include message text are not written to the audit log individually.

What Oleon does not do

  • The MCP server does not send your data to a model. It has no model of its own; your assistant brings one.
  • Tool results are not cached or stored. Each call reads your workspace as it is at that moment.
  • Using the MCP server does not draw on your Oleon Support allowance. The model usage belongs to your assistant's provider.

The rest of it

This page covers what the MCP server does with your data. What Oleon Workspace as a whole collects, who it is handed to and how long it is kept is in the privacy policy, and how the product is built and operated is on the security page.