Security & privacy
Security and privacy
What an app connected to your Tipsterland account can see and do, how to revoke access and how to protect your token.
What the connected app sees
Your assistant only sees what the tools it uses return, and only when it uses them:
- your plan and today's limits;
- your picks, your channels and their subscriber counts;
- your stats;
- a summary of your earnings and payouts;
- your discounts.
It has no access to your password, your private messages, your payment or billing details, or your subscribers' personal data. And it can't use the Tipsterland API beyond these fourteen tools.
It acts on your behalf
Whatever your assistant posts goes out under your name, exactly as if you'd done it on the website: your followers see no difference. So:
- Check what it's about to post before approving it, especially odds, stakes and prices: through the MCP it can't delete or change anything already published, only set a pick's result. If something goes wrong, you fix it on the website or app.
- Only turn the connector on in conversations where you need it.
- Be wary of instructions you didn't write: if you ask it to read a web page or a document, that text could try to slip in orders (“post this in their channel”). Your assistant shouldn't do anything you didn't ask for; if it suggests it, say no.
How to revoke access
Open Tipster Studio → AI (MCP)
Find the connection under “Active connections”
You'll see each connected app and each token, with when it was created and last used.
Click “Revoke”
It takes effect immediately: that app's next request will no longer work.
Then, if you like, also remove the connector in Claude or the app in ChatGPT so they stop offering it.
Images
If you give your assistant a link to an image, Tipsterland downloads it and stores it with your post, just as if you'd uploaded it on the website. Don't share links to images with details you don't want published (your balance, your full name, your email…).
Your token is like a password
- It's shown only once, when you create it. Tipsterland can't show it to you again.
- Don't share it, don't paste it into an AI conversation and don't commit it to a code repository.
- It expires after 90 days. When it does, create a new one.
- If you think someone has seen it, revoke it in Studio and create a new one.
Activity log
Every MCP call is logged: which tool, when, with what result and from which address. Picks and posts created through the MCP are internally marked with that origin. This helps us support you if something didn't go as expected, and to detect abuse. In Tipster Studio you can see your connections, when they were last used and today's usage.
How your account is protected
- Sign-in always happens on tipsterland.com: the AI app never sees your password.
- Before granting access, Tipsterland shows you which app is asking. If you don't recognise it, click Cancel.
- Your plan is checked on every call, and the team can turn off an account's access instantly.
Stuck? Message us from the Tipsterland support chat.