Connecting an AI assistant to your dispensary data is a big step, and it is smart to ask questions before you do. The short answer: the Flowhub MCP server was built with layered protections so your AI assistant can only see and do what you can, every change requires your approval, and customer personal information stays locked down.
Here is exactly how each layer works.
Your Permissions Are the AI's Permissions
The AI assistant signs in as you, using your Flowhub login. That means it inherits your exact role permissions, nothing more.
If your account cannot create deals, the AI cannot create deals.
If you only have read access to reports, the AI can only read reports.
If a teammate connects their own account, their AI is limited by their permissions, not yours.
💡 For owners and admins: review your team's Flowhub permissions before rolling out AI tools. Each person's assistant will only ever have the access their own login has.
No Direct Database Access, Ever
Connecting AI to Flowhub does not give it open access to your database. The MCP server exposes a fixed, approved set of tools (the same ones listed in View Available MCP Actions) and every action passes through the same validation and compliance guardrails as the Flowhub app itself.
Think of it as a new way of using the Flowhub interface, not a back door around it. If an action would not be valid in the app, it is not valid through the MCP either.
You Approve Every Change
Before the AI makes any change to your live data, like a deal, a price update, or an inventory move, it stops and asks for your confirmation. You will see a summary of exactly what is about to happen, and nothing is applied until you approve it.
A few things to know:
Reads never change anything. Questions about your sales, inventory, or customers are retrieval only.
Writes always pause for approval. Review the summary card before you confirm, especially for bulk changes.
Changes can be corrected. If something is approved by mistake, you can ask the assistant to reverse the change.
🔒 Keep approvals on. Do not set write or bulk tools to "always allow" in your assistant's settings. See the Flowhub MCP Setup Guide for our recommended tool settings.
Customer PII Is Locked Down
The Flowhub MCP server is designed to keep personal identifying information (PII) out of AI conversations. It works with summaries of your business data, including sales trends, inventory levels, and category performance, not individual customer identities.
If a request would expose personal customer details, the assistant will decline. You may occasionally see it respond with something like "sorry, I can't do that" — that is the PII safeguard working as intended, and it applies to every plan, free or paid.
Every Action Is Logged Under Your Name
Actions taken through the MCP server generate the same activity records as actions taken in the Flowhub app. Changes to products, inventory, pricing, and deals appear in your activity feed with your name attached — the same traceability you already rely on.
If you ever need to review what happened and when, the full history is there, whether the change was made by hand or through your assistant.
Your Data and the AI Provider
Here is the part that depends on the choices you make outside of Flowhub. When you chat with an AI assistant, your prompts and the data it retrieves are processed by the AI provider you chose — Anthropic (Claude), OpenAI (ChatGPT), or Google (Gemini) — under that provider's terms.
What to check before connecting:
Free and entry-level consumer plans may use your conversations to improve the provider's models, depending on the provider and your settings. Review the data controls before connecting business data.
Paid, team, and enterprise plans generally offer stronger commitments that your data will not be used for model training. Check the terms for your specific plan.
Multi-store and enterprise operators should consider a business or enterprise AI plan, where admins can manage data-sharing settings across the whole organization.
💡 The upgrade usually pays for itself. Beyond the privacy controls, higher-tier plans include the more capable models that produce reliable analysis of your retail data. The time savings alone typically outweigh the subscription cost.
Frequently Asked Questions
Do I have to pay more for my data to be secure?
Not with Flowhub — the permission, approval, PII, and logging protections above apply to every connection. Paying more applies to your AI provider's plan, where higher tiers offer stronger data-sharing and training controls.
Does the AI assistant see my Flowhub password?
No. The connection uses OAuth, a standard secure sign-in. The assistant never sees your password, and you can disconnect at any time from your assistant's settings.
Can the AI make changes without me knowing?
No. Write actions require your approval before they are applied, and every change is logged in your activity feed under your name. Keep approval settings on (do not use "always allow" for writes) to maintain this protection.
If I'm on a free AI plan, will it leak my customer data?
The PII safeguards are enforced by the Flowhub MCP server itself, so they apply regardless of your AI plan. The free-plan consideration is about your business conversation data potentially being used for model training — review your provider's settings.
What if the AI gets something wrong?
Modern frontier models are far more reliable than earlier AI, but no model is perfect. That is exactly why approvals exist: review each change before confirming, start with read-only questions while you build trust, and use a capable model — smaller, faster models are more likely to make mistakes with retail data.
Can I revoke access?
Yes, any time. Disconnect the Flowhub connector from your AI assistant's settings, and the connection is severed immediately. You can also ask your Flowhub admin to adjust your permissions, which takes effect on the AI's access right away.
Still have questions about privacy or security? Reach out to our support team at help@flowhub.com anytime.
