Privacy policy — the iCustoms connector for Claude
This policy covers the iCustoms connector at
https://mcp.customscloud.co/mcp.
Last updated: 15 September 2026
What this connector is
The iCustoms connector lets you ask Claude about your own UK customs declarations. It connects Claude to the iCustoms account you already have, on your instruction, and only for as long as you allow.
It is read-only. It can look up declarations, their status, and HMRC's responses. It cannot create, change, submit or cancel anything.
Operated by Clear Customs Group Ltd, a company registered in England and Wales (company number 13868707), Unit 1 Concord Road, London W3 0TJ, United Kingdom.
What we store
Two things, and nothing else.
Your iCustoms API credentials
- Stored encrypted, each account sealed with its own key, which is itself protected by a master key held separately from the database.
- Decrypted in memory only for the moment a request is made, then discarded.
- Never shared with Anthropic or Claude. Claude receives a separate access token that works only against this connector, only for your account, and only for reading.
- Never placed in a web address, a log file, or your Claude conversation.
A record of which tools you used
Customs declarations are regulated records, so we keep a log of each request: which account made it, which tool was used, whether it succeeded, when, and a short reference.
That reference includes the declaration identifiers you looked up and the goods descriptions you asked to have classified (up to 120 characters). It does not include declaration contents, HMRC responses, or anything else returned to you.
What we do not store
Your declaration data is never copied. Declarations, HMRC notifications, commodity codes and exchange rates are fetched from iCustoms when you ask, passed to Claude, and not retained here.
We do not store your Claude conversations, and we cannot see them.
Who can see what
Only you can see your own data. Every request to iCustoms is made using your credentials, so this connector can only reach what your own iCustoms account can reach.
That is enforced in three independent places: the connector selects your account from your verified sign-in and accepts no account identifier from the request; each request uses your own credentials; and iCustoms applies its own access controls on top.
What is shared with Anthropic
When you ask Claude a question, the answer this connector returns becomes part of that conversation, and is then handled under Anthropic's terms and privacy policy rather than ours: anthropic.com/legal/privacy.
Anthropic never receives your iCustoms API credentials.
Where it runs
- Hosted in Amazon Web Services, eu-west-2 (London).
- All traffic over HTTPS. Credentials encrypted at rest; the database is encrypted and not reachable from the public internet.
- Sign-in uses OAuth 2.1 with PKCE. Access tokens are short-lived and bound to this connector, so a token issued here cannot be used elsewhere.
- Session tokens are stored only as irreversible hashes.
How long we keep it
Your credentials: until you disconnect. Disconnecting erases them — we no longer hold them in any form.
The tool-use log: 12 months, after which it is deleted. A record of who accessed regulated customs data is itself a compliance requirement, so it is kept for a defined period rather than removed on request.
Backups are retained for 7 days and are encrypted.
Your choices
- Disconnect at any time. Remove the connector in Claude and unlink in iCustoms. Your stored credentials are erased.
- Revoke instead. Regenerating your API keys in iCustoms stops this connector working immediately, without touching Claude.
- Ask what we hold. Contact support@icustoms.ai and we will tell you, or delete what we are able to delete.
Under the UK GDPR you have the right to ask what personal data we hold about you and to receive a copy of it; to have inaccurate data corrected; to ask for data to be erased; to ask us to restrict how we use it; to receive it in a portable form; and to object to our use of it. Where we keep a record for a defined period to meet a compliance obligation, we will tell you so rather than delete it silently. If you are not satisfied with how we have handled a request, you can complain to the Information Commissioner's Office at ico.org.uk.
Changes
We will update this page if what we store changes, and note the date. Material changes will be notified through an email to the address on your iCustoms account, at least 14 days before the change takes effect.
Contact
support@icustoms.ai
Unit 1 Concord Road, London W3 0TJ, United Kingdom