Skip to main content
Guide

Curve MCP and Curve Analyst: When to Use Which

Use Curve MCP for rounded weekly campaign numbers in your own AI client, and Curve Analyst in the app for people, revenue, breakdowns and this week's data.

11 min read

Use Curve MCP when you want rounded, aggregate campaign numbers for completed weeks inside your own AI client, and use Curve Analyst when the question needs detail: one person, revenue, a channel or page breakdown, or anything from this week. Both run on Curve, the HIPAA-compliant tracking and analytics platform with a signed BAA on every plan. The real split is where the answer lands: Analyst answers inside the app, under that BAA, while MCP answers go to an AI vendor you chose, so they carry only rounded weekly totals and hand anything deeper to Analyst through a one-time link.

The difference is where the answer goes

Analyst is the chat built into the dashboard. Your question goes to the data and the answer comes back to your screen, all inside the boundary your BAA covers. It reads the same detail your dashboard shows, because you are already logged in with access to it.

MCP (Model Context Protocol) works the other way round. You connect it to an AI client your team already uses, and every answer it returns becomes part of a conversation held by that AI vendor. The vendor is your pick, not a Curve subprocessor, and the BAA that covers your tracking data does not reach it.

That one fact explains every limit below. MCP releases only figures built to be safe outside the boundary. Analyst can go further because its answers never cross it.

MCP and Analyst side by side

The same question can get an exact answer in one and a withheld figure in the other:

  • Where you ask: MCP works in any client that can connect to an MCP server: Claude (desktop, web and Claude Code), ChatGPT, Cursor and other MCP-capable clients or agents. Analyst lives in the chat tab of the dashboard.
  • Time: MCP covers completed weeks only: last week or the last 4, 13 or 52 weeks, as totals plus a week-by-week series. The current week never appears, so its figures can trail the dashboard by up to a week. Analyst works with date ranges, daily trends and live visitor counts.
  • Detail: MCP returns organization-level visitors, sessions, goal completions and funnel steps, plus each campaign's platform-reported spend, clicks and impressions next to the conversions Curve's server-side tracking recorded, with cost per conversion. Analyst adds breakdowns by channel, UTM, landing page, device and geography. It also reads organic search from Google Search Console and CRM outcomes where HubSpot or WhatConverts is connected.
  • Money: MCP gives spend and cost per conversion, never revenue or ROAS. Analyst reports revenue, ROAS and CPA by platform, campaign and ad group.
  • Attribution: MCP reports last-touch conversions from your own tracking. Analyst can compare first touch, last touch, U-shaped and assisted models.
  • Precision: MCP rounds every count and spend figure, computes cost per conversion from the rounded numbers, and withholds small groups. Analyst shows the figures your dashboard shows.
  • Names: MCP shows a goal, funnel or campaign name only if your organization approved it; otherwise the name reads "(label hidden)". Analyst uses your real names.
  • People: MCP never returns a person, a visit or a session. Analyst can, where your organization has turned those features on.

Neither one changes anything. MCP has no write tools at all, and Analyst cannot edit goals, funnels, event mappings or connectors.

When MCP is the right tool

MCP earns its place when campaign numbers are one input among several and the work already happens in an AI client. Typical cases:

  • The Monday check. "Show last week's spend, conversions and cost per conversion by campaign, and flag anything that moved sharply against the prior four weeks." Asked over the last 13 weeks, one call returns the window total and every completed week inside it, so last week and the four before it arrive together.
  • Drafting the weekly update. The numbers land in the same session as your notes, budget plan and last memo, so the assistant drafts the summary with no spreadsheet export.
  • Long trends. Which campaigns got more expensive per conversion over 13 or 52 completed weeks.
  • Cross-tool comparisons. MCP already reconciles your server-side campaigns, putting each one's platform-reported spend, clicks and impressions next to the conversions your tracking recorded. Put that next to a pacing sheet or a budget plan and ask the assistant to explain what moved. When you want the full sent, accepted and matched view, MCP opens it inside Curve with one link.

The uncomfortable part: small accounts see a lot of withheld figures. A campaign that books a handful of consults a week will often come back withheld for any single week, because a count that small could point at real patients. The 13-week total usually survives when single weeks do not. The reasoning is laid out in why MCP answers in weeks, not rows.

One caution on cross-tool work. MCP's answers are built to be safe on their own, but they cannot make a session safe that also holds contact records from a CRM connector. Keep patient-level connectors out of the conversations where you pull campaign numbers.

When Analyst is the right tool

Go to Analyst when the question needs more resolution than a rounded weekly total, or when the answer would identify someone:

  • This week. "Did bookings pick up after Tuesday's landing page change?" MCP cannot see the current week. Analyst reads daily trends and can tell you how many visitors are on the site right now.
  • Breakdowns and revenue. Which channel, which landing page, mobile or desktop, which state, and the revenue and ROAS an owner actually asks about. MCP carries none of these.
  • Sent versus credited. When Google's conversion count drops, Analyst shows what your tracking sent next to what the platform credited, and says which figure it is quoting. For Meta, the sent figure is platform-level only, because Meta uploads carry no campaign identifier. Comparing what your tracking sent with what Google credited explains which gaps are normal.
  • One person. Where your organization has turned on person lookup, Analyst can show one person's tracked journey (ad clicks, visits, forms and conversions) from an exact email address, and each lookup is access-logged. Where session replay is on, it can find and summarize recorded sessions.

Analyst has limits of its own. It is locked to one organization, taken from your login, and it answers from what your tracking holds: website activity, campaign reporting and CRM outcomes from connected tools, not a health record.

How a question moves from MCP to Analyst

When your AI client asks something MCP will not answer (a named patient, an email or phone number, a single session, revenue, any breakdown), MCP can hand it over through its "open in Curve" tool instead of refusing, and the question continues inside the app.

  1. Your assistant calls the tool. Nothing is looked up at this point. The reply is the same whether or not the person exists in your data, so the AI vendor cannot even learn that a patient is there.
  2. You get a link, never data. The link carries no identifiers and no figures. It needs your login, works once, works only for the person who asked, and expires within minutes.
  3. A confirmation page waits for a click. A page titled "Open this in Curve Analyst?" does nothing until you click its open button, so a link that a chat client previews, or that you open by mistake, is not used up.
  4. The question lands as an unsent draft. Analyst opens with the question in the composer under a banner that names the client, for example: "Drafted by an external AI tool (Claude Code). Read it before you send it; nothing is sent until you do."
  5. The answer stays in the app. Nothing flows back to the AI client. The handoff runs one way.

The unsent draft is deliberate. The question was written by an outside model, which can be steered by text planted in the data it reads, such as an ad comment or a search term. Read the draft before you send it into an assistant that sees full detail. The wider risk is covered in prompt injection in ad data.

What the handoff cannot protect

The handoff guards what leaves the app. It cannot guard what you type. If you paste a patient's email address into your AI client and ask what happened to them, MCP returns only a link, but the address is already in that vendor's conversation history.

On its own side, Curve masks contact details in the drafted question, keeps only a keyed hash of any address the assistant passes along, and wipes both the moment the link is opened, so you name the person again inside Analyst. None of that reaches the copy your AI client already holds.

So ask person-level questions in Analyst from the start, and treat the handoff as the safety net for conversations that drift there. The reverse also holds: do not paste a person-level Analyst answer back into your AI client. That is the same disclosure as trying to paste a patient funnel into ChatGPT.

How a team uses both

The pattern that works is a rhythm rather than a rule: MCP for the weekly overview, Analyst for the follow-ups.

Set access for the handoff, not just the connector

On the User Access page, the AI access card gives each person two separate switches: one for Analyst and one for External AI tools. The external switch is off by default, and only the primary user can turn MCP on for the organization.

Two things must be true for a handoff to land: Analyst is turned on for the organization, and the person's own Analyst switch is on. Miss either and the link stops at a message saying which one is missing, instead of a drafted question.

The handoff is also a separate permission on each access token, off by default, so a token issued without it cannot create links.

Look at label approval too. Any campaign name your organization approves can appear in MCP answers, which means it reaches the AI vendor. Approve neutral names such as "Brand Search" and leave anything naming a condition or treatment as "(label hidden)".

A weekly rhythm that works

  1. Monday, in the AI client. The marketing lead asks for last week against the prior four, by campaign, and drafts the update.
  2. Flags. The assistant points at two campaigns: one whose cost per conversion jumped, and one whose conversions came back withheld.
  3. Follow-up, in Analyst. Both go through the handoff. The lead checks the daily trend, the landing page breakdown, and whether Google credited what was sent.
  4. Back to the memo. The lead writes the conclusion in by hand: "Campaign B lost mobile conversions after the form change on the 12th." Conclusions travel. Rows do not, and neither does a figure MCP withheld: typing "Campaign C had 3 conversions" into the memo puts back exactly the small number the rounding kept out.

Agencies and compliance officers

Agency (partner) users cannot hold Curve MCP access in a client's organization: a partner admin can revoke access or switch MCP off but cannot turn it on, and every connection is bound to one organization, so MCP is never a cross-client view. Agency staff do their drill-downs in Analyst inside the client's account, which keeps that data out of the agency's own AI subscription. The PHI-safe agency reporting workflow covers the weekly report side.

For a compliance officer, both surfaces leave a trail. Analyst conversations are logged and scoped to the organization. Every MCP call is logged, no data is returned if the log entry cannot be written, and those records are kept (calls that returned data for years). The primary user sees a read-only activity view (calls per member per day, tools and outcomes, never arguments or answers); full records are opened only by a named Curve administrator, for example for a breach assessment.

Frequently asked questions

Can Curve MCP tell me about a specific patient?

No. MCP never returns a person, an email address, a phone number or a single visit. Ask about one and your assistant gets a one-time link that opens the question in Analyst behind your login. Analyst answers only if your organization has person lookup turned on and you have access to it.

Why don't MCP figures match the dashboard?

Four reasons, all deliberate. MCP skips the current week, and it rounds counts and spend while withholding small groups. It counts distinct people across the whole window rather than visits, and its campaign conversions are last-touch, which may differ from the model your dashboard view uses. For the exact figure, open it in Analyst.

Is Curve Analyst covered by our BAA?

Yes. Analyst is a read layer over data already collected under the signed BAA included on every plan, and its answers stay inside the app. What the BAA cannot follow is anything you copy out of Analyst into another tool; once pasted elsewhere, that tool's terms govern it.

Does the AI client I connect to MCP need its own BAA?

Curve's BAA does not extend to it, because the AI vendor is your choice rather than a subprocessor. MCP's answers are rounded weekly aggregates with no names, contact details or visits, but that does not govern what you type into the client or what other connectors add to the session. Decide that under your own policy.

Check each vendor's terms separately. For Claude Code, as one example, Anthropic's own documents disagree: its BAA article covers Claude Code only with zero data retention enabled, while its API data-retention page says Claude Code is not covered under HIPAA readiness. Get the answer in writing from Anthropic before anyone puts patient data in that session.

Which AI clients work with MCP?

Any client that can connect to an MCP server works: Claude (desktop, web and Claude Code), ChatGPT, Cursor and other MCP-capable clients or agents. A hosted connector calls the server from the vendor's infrastructure, while a local client starts the call on your machine, but in both cases the model runs at the AI vendor, so every answer reaches that vendor.

Does a small clinic need both?

Not always. If your campaigns are small and your team works in the dashboard, Analyst covers most questions and MCP will return many withheld weeks.

Where to start

Pick by where the work already happens: MCP first if weekly reporting lives in an AI client, Analyst first if it lives in the dashboard. Either way, anyone with MCP access needs Analyst too, because every handoff lands there.

To see MCP answer a week of your own campaigns and hand a follow-up to Analyst, book a Curve demo. For a field-by-field view of what the connector returns, read the MCP overview. Analyst's campaign reporting side is covered on the marketing performance page.

Reviewed September 2026. Covers what MCP returns and how the handoff works today.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit