1. Scope
getclippy.co and Clippy Mc Clipface are operated by GetClippy LLC, a New York limited liability company. In this policy, “we,” “us” and “our” mean GetClippy LLC.
This Privacy Policy applies to getclippy.co, its hosted coupon API, the read-only MCP server at getclippy.co/mcp, and the Clippy Mc Clipface instruction skill (together, the “Service”), including when the Service is used through Muse, Meta's consumer AI assistant, or through another AI assistant. It does not govern a retailer, affiliate network, shopping agent, AI assistant (including Muse itself), browser, or other third-party service.
2. Information processed
Coupon lookups
The Clippy skill sends only a merchant name, or a product name when the user names a product rather than a store, and currency with a lookup; it does not send cart contents, items, prices, subtotals, shipping amounts, or checkout totals. Checkout totals are compared locally by the user's agent. For compatibility, the API still accepts an optional cart subtotal and shipping amount from other clients; if supplied, they are used only to estimate savings for that response. The Service processes lookup values to find and rank applicable offers. The application does not store the raw search text in its analytics database or create a per-user shopping history; aggregate counts record only which catalogue store, if any, a lookup matched, as described below. Hosting and security providers may temporarily process request URLs, IP addresses, user-agent information, timestamps, and similar connection data to deliver and protect the Service.
MCP server and AI assistants such as Muse
When an AI assistant such as Muse (Meta's consumer AI) calls the MCP server at getclippy.co/mcp, the request contains only the tool name and its arguments: a store name and currency for find_coupons, a product name and currency for find_product_coupons, or a currency and number of results for get_deals. It does not include your name, account, chat history, cart contents, prices, or totals, and the Service does not ask the assistant for them. MCP calls are logged only in the aggregate usage counters described below: totals by tool, outcome, and matched catalogue store. They create no per-user records, and the raw search text is not stored. MCP calls also count toward the anonymous adoption estimates described below, which keep only one-way hashes in aggregate sketches and no list of clients. To enforce the MCP server's rate limit, each request also increments a short-lived counter keyed by a one-way keyed hash (HMAC) of the requesting IP address and the current minute; the counter holds only a request count, never the IP address itself, and expires within about two minutes. The assistant provider processes your conversation, including what you ask it to look up, under its own privacy policy (for Muse, the Meta Privacy Policy), not this one.
Aggregate service analytics
For each coupon lookup, the Service records daily and all-time request totals and whether live data was available. It also estimates daily and monthly distinct network clients. To do that, it briefly processes the requesting IP address and user agent in memory, combines them with a secret using HMAC, and sends only rotating pseudonymous values to Redis cardinality counters. The application does not store the raw IP address or user agent in those counters. These figures are approximate because many people may share an agent provider or network address.
For coupon, deal, report, MCP tool-call, and install-link requests, the Service also keeps anonymous adoption counts: estimates of distinct network clients per day, week, and month, and new versus returning clients. To do that, it combines the requesting IP address and a coarse user-agent category (such as “assistant” or “browser”) in memory with a secret key that changes every quarter, and adds only the resulting one-way hash to Redis HyperLogLog sketches. The sketches cannot be turned back into IP addresses, user agents, or per-client records, and the application keeps no list or history of individual clients. Install links (getclippy.co/i) may carry a short campaign tag, such as ?ref=receipt; only aggregate counts per tag are stored.
The Service also keeps aggregate usage counts for all requests: daily and all-time totals by endpoint, response status class (such as success or error), matched store name, and outcome (for example, whether a lookup found any offers, which MCP tool was called, or whether a report was stored). These counts contain no IP address, user agent, hash, or raw search text, and a lookup that matches a store in a sensitive category is counted without the store name. Adoption figures and usage counts are published only as aggregate totals, at /api/stats/adoption and /api/stats/usage.
Website analytics (Google Analytics)
The getclippy.co web pages load Google Analytics 4 (measurement ID G-ZP5HKW057J), a service provided by Google. When you visit a page, the Google Analytics tag sets first-party cookies on getclippy.co (such as _ga and _ga_ZP5HKW057J) that let Google Analytics recognize a returning browser, and it sends Google information about the visit: the page URL and title, the referring page, approximate location derived from your IP address, browser and device characteristics, screen size, language, and interactions such as page views, scrolls, and outbound link clicks. We use the resulting reports to understand how people find and use the website. Google processes this information under its own terms and privacy policy, and may combine it with other information as described there. Google Analytics runs on the website only; it is not part of the hosted coupon API or the instruction skill, and coupon lookups made by an agent are not sent to Google Analytics.
Ad measurement (Meta Pixel)
We may advertise Clippy on Facebook, Instagram, and other Meta services. To measure whether those ads work, the getclippy.co web pages load the Meta Pixel, a small piece of code provided by Meta Platforms, Inc. The pixel sends Meta information about your visit: the page URL, the referring page, your IP address, browser and device information, and a few actions on the page, such as viewing a page or tapping “Copy the Muse prompt.” It can set a first-party cookie on getclippy.co (_fbp), and Meta may read cookies it has already set in your browser. If you use Facebook or Instagram, Meta may match this information to your account. We use the resulting reports to count how many visits and prompt copies came from our ads and to improve which ads we show. We do not send Meta your name, email address, or any coupon lookup, cart, or purchase details, and the pixel is not part of the hosted coupon API or the instruction skill. Meta processes this information under its own terms and the Meta Privacy Policy.
Optional Community mode
If a user affirmatively enables Community mode, an agent may submit a random event ID, offer ID, outcome (“worked,” “rejected,” or “unverified”), eligibility status, an optional yes/no indicator of whether an accepted code lowered the checkout total, and consent confirmation. The report does not include a name, merchant name, cart contents, items, prices, totals, savings amounts, order number, or payment details, and the Service rejects reports that contain other fields. Connection data is processed to rate-limit reports, but the stored report does not contain a raw IP address.
Optional savings receipt
After a checkout comparison confirms that a code lowered the final total, the agent may offer a short savings receipt. It is generated by the agent on the user's side from the totals shown at checkout and is not sent to Clippy. If the user chooses to share it, the share line links to getclippy.co with only a generic tag (?ref=receipt) that contains no amount, store, cart, or personal or unique identifier. The user decides whether and where to post it; the agent does not post or send it. When someone opens that link, the website records the visit, including the tag, through the website analytics described above, and passes the same generic tag to the install link.
Optional savings reports
The Clippy skill does not ask agents to send savings reports, and Community mode never includes savings amounts. The API retains a legacy savings endpoint: with separate affirmative consent after a completed checkout, a client may submit a random event ID, savings amount in integer minor units, currency, consent confirmation, and checkout confirmation. These reports do not contain identity, merchant, order, payment, or cart information. Public savings figures are aggregated by currency and are community-reported, not independently audited.
Optional weekly digest
If you ask your agent for a weekly digest, the agent or its host (not Clippy) stores and runs the schedule under that provider's privacy practices. Each run sends Clippy the selected currency and requested result limit and receives a current, non-personalized catalogue selection. Clippy does not require an email address or maintain a subscriber list for this feature.
Information you send us
If you contact us, we process the information in your message and your contact details to respond, keep appropriate business records, and protect the Service.
3. How information is used
- Return and rank current coupon offers.
- Measure reliability, capacity, and adoption in aggregate.
- Understand website traffic and usage through Google Analytics.
- Measure whether our ads on Meta services bring people to the website, using the Meta Pixel.
- Use recent, opted-in outcomes to lower the ranking of repeatedly rejected eligible offers and to avoid counting accepted codes that did not lower the checkout total as successes.
- Display opted-in, completed-checkout savings totals.
- Prevent abuse, troubleshoot failures, and secure the Service.
- Meet legal obligations and enforce the Service terms.
4. Disclosure to others
We use infrastructure providers, including Vercel for hosting and Upstash for Redis storage, to operate the Service. They process information on our behalf under their applicable terms and privacy practices. We use Google Analytics (provided by Google LLC) to measure website use; when you visit getclippy.co, page-visit information and analytics cookie identifiers described in section 2 are sent to Google, which processes them under its own terms and privacy policy. See how Google uses information from sites that use its services. The page-visit and button-click information described in section 2 is sent to Meta Platforms, Inc., which processes it under the Meta Privacy Policy. We may also disclose information when required by law, to protect rights and safety, or as part of a business transfer.
Coupon feeds come from affiliate programs Clippy has joined, including through the affiliate networks CJ Affiliate, Impact, Awin and Admitad, and from direct brand programs. Clippy fetches those feeds centrally; a coupon lookup does not itself send the shopper’s query to those networks or brands. If a user or agent follows a tracked shopping link, the destination retailer and any affiliate network involved may receive the IP address, browser or device data, referrer, cookie or similar identifiers, and transaction attribution information. Their policies, not this one, govern that processing.
5. Affiliate tracking and privacy signals
We do not sell personal information for money. Tracked links support commission attribution and may involve third-party cookies or similar technologies after the link is opened. Depending on the law that applies to you, this activity may be treated as “sharing” or targeted advertising. You can avoid this third-party tracking by not opening a tracked link and instead navigating to the retailer independently or using a coupon code manually. The Clippy website uses Google Analytics, which sets first-party analytics cookies and sends page-visit information to Google as described in section 2. The Meta Pixel is used to measure our ads and can set the _fbp cookie; depending on the law that applies to you, this may be treated as targeted advertising or “sharing.” You can limit how Meta uses this information for ads in your Facebook or Instagram ad preferences, including the setting for activity information from ad partners, and you can block the pixel with a content or tracker blocker or your browser’s tracking protection, or by blocking or deleting cookies. You can limit Google Analytics by blocking or deleting cookies in your browser, using a content blocker, or installing Google’s Google Analytics opt-out browser add-on; the coupon service and the website work the same either way. The website does not respond differently to browser “Do Not Track” signals. A universal opt-out signal may still be honored by the destination retailer or network under its own policy.
6. Retention
- MCP rate-limit counters expire within about two minutes.
- Daily approximate-client counters expire after about 40 days; monthly counters expire after about 400 days.
- Anonymous adoption sketches expire after about 40 days (daily), 100 days (weekly), and 120 days (monthly), and their hashing key changes every quarter.
- Google Analytics event data is kept for the retention period set in Google Analytics (Google offers periods from 2 to 14 months); aggregated reports may be kept longer. Google Analytics cookies typically expire after up to 2 years unless you delete them sooner.
- The Meta Pixel
_fbpcookie typically expires after about 90 days unless you delete it sooner. Meta keeps the information it receives under its own retention practices. - Aggregate request totals and aggregate savings totals may be kept indefinitely because they are not intended to identify a person.
- Coupon outcomes are used in a seven-day evidence window. Deduplication and rate-limit records expire automatically; provider logs and backups may persist for a limited additional period.
- Individual savings reports and correspondence are kept only as long as reasonably needed for aggregation, fraud prevention, legal compliance, and dispute resolution.
7. Your choices and rights
You can use coupon lookup in Private mode without submitting Community or savings reports. You may withdraw Community-mode consent at any time for future reports. You can also avoid affiliate tracking, limit Google Analytics, and limit or block the Meta Pixel as described above.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or information about disclosure of personal information, and to appeal or complain to a regulator. Because Clippy intentionally avoids account profiles and direct identifiers, we may be unable to locate aggregate or pseudonymous records as belonging to you. To make a request, email clippy@getclippy.co. We may need to verify the request and may retain information when legally permitted or required.
8. Security
We use reasonable administrative and technical safeguards, including server-side credentials, data minimization, validation, rate limits, rotating pseudonymous analytics identifiers, and restricted operator endpoints. No system is perfectly secure, and we cannot guarantee absolute security.
9. Children
The Service is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
10. International use
The Service is operated in the United States and information may be processed there and in other locations where service providers operate. Local privacy rights may still apply.
11. Changes
We may update this policy as the Service or law changes. We will post the revised policy here and update the effective date. If a change materially affects how previously collected information is used, we will provide additional notice when reasonably required.
12. Contact
GetClippy LLC operates the Service. Questions or privacy requests: clippy@getclippy.co.