When connecting Retino to an AI assistant, you can choose whether it can access only standard operational data or also sensitive customer data.
Info: Retino MCP provides read-only access. The AI assistant cannot create, change or delete anything in Retino.
What data the AI assistant can see
Standard read access is included with every connection. Sensitive data is optional, and we recommend allowing it only when you actually need it.
Access level | What the AI assistant can see | What it is useful for |
Standard data | Statuses and dates of cases, orders and shipments, items, amounts, carriers, refunds and aggregate statistics | Operations overviews and comparisons of periods, carriers or return reasons |
Sensitive data | Customer name, email address and phone number, addresses, case and order codes, tracking numbers, customer messages and internal notes | Resolving a specific customer, order or case and summarizing communication |
Sensitive access does not add any new functions. It only provides more detail in results the AI assistant can already retrieve.
Note: MCP cannot access stored sign-in details, integration tokens, refund bank accounts, attachments or free-text custom fields. With sensitive access, however, it can read messages and internal notes, including any information people entered into them manually.
How access works
You sign in and authorize the connection directly in Retino, so the AI assistant never receives your password.
Each connection:
applies only to the selected e-shop and user;
follows the products active for that e-shop;
can be revoked in Retino at any time;
stops working if the user loses the required access to the e-shop.
The AI assistant stores the connection according to its own security rules.
Where the data may remain stored
Data retrieved from Retino may appear in the conversation and its history. Any further storage and processing is governed by the terms of the selected AI service. Connect Retino only to assistants that are approved for working with customer data and that you trust.
How to use MCP safely
Use your own AI account. Do not connect Retino to someone else's or a shared account.
Start with standard data. Allow sensitive data only when you need it for a specific task.
Do not share customer data publicly. Check the contents before sending a link, screenshot or report.
Protect your device. Do not authorize the connection on a public or unfamiliar computer. Enable two-factor authentication in Retino and the AI service if available.
Check the Redirect URL. Authorize access only after starting the connection yourself.
127.0.0.1orlocalhostmay be valid for an application installed on your computer.Review active connections. Disconnect AI assistants you no longer use.
Consider team changes. Revoke access when a colleague leaves, a device is lost or you suspect the wrong account was used.
How to revoke access
Open Settings → MCP in Retino.
Find the connection by AI assistant and user.
Revoke access and confirm the action.
Once revoked, the AI assistant can no longer retrieve new data through that connection. Earlier answers may remain in the AI service's history and must be deleted there if necessary.
The owner of the e-shop account can manage all of the e-shop's MCP connections. Other users can manage only their own connections.
The highlighted Revoke access option disconnects only the selected connection. Revoke all disconnects every active MCP connection for the e-shop.
If you have not connected Retino yet, connect an AI assistant to Retino. For inspiration, see what you can do with the AI connection.

