Skip to main content
Guide

Curve MCP: Reconciled Campaign Data in Any AI Client

Curve MCP gives AI clients each campaign's platform spend beside your own tracked conversions and cost per conversion, by completed week, de-identified, read-only and logged.

11 min read

Curve MCP is the read-only MCP server from Curve that gives an AI client reconciled campaign numbers: each Google Ads and Meta campaign's platform-reported spend, clicks and impressions beside the conversions Curve's server-side tracking attributed, with cost per conversion, for completed weeks. It works with any client that can connect to an MCP server, including Claude, ChatGPT and Cursor. Every answer is built to be de-identified: counts are rounded, small groups are withheld, and questions about a person come back as a dashboard link. A signed BAA comes with every plan and covers Curve, not your AI vendor.

What the server answers

The server exposes three tools, and each does one job. Your AI client decides when to call them. The tools decide what can come back.

  • A performance tool returns organization-level figures for one fixed window: visitors, sessions, goal completions, funnel steps, and a row per campaign with spend, clicks, impressions, conversions and cost per conversion.
  • A self-description tool tells the assistant what the connector can and cannot return, which windows exist and how figures are rounded, so it can state its limits instead of guessing at them.
  • An open-in-dashboard tool handles everything else. It returns a one-time link that opens the in-product analyst with the question drafted. The link needs a login, expires quickly and carries no data.

Windows are fixed choices: last week, or the last 4, 13 or 52 completed weeks. Each answer carries totals for the window plus one row per week inside it, with the exact dates covered. There are no custom date ranges and the current week is never included, so figures can run up to a week behind the dashboard. The reasoning is in why Curve MCP answers in weeks, not rows.

What "reconciled" means here

A campaign tracked server-side has three conversion numbers: sent (what your tracking delivered), accepted (what the platform took in), and matched to a campaign (by the platform or by your own tracking). Curve MCP reconciles your server-side campaigns by putting the conversions Curve's server-side tracking recorded beside the platform's own spend, clicks and impressions for the same campaign and weeks.

Each row carries cost per conversion by completed week, and one link opens the full sent, accepted and matched view inside Curve. Cost comes from the platform, outcomes come from a count no platform graded, and cost per conversion uses the same ruler for Google Ads and Meta. Conversions are counted as people on a fixed last-touch model, so a person who converts twice in the window counts once.

See comparing what your tracking sent with what Google credited for how those legs work.

Questions it answers well

  • "Which campaigns drove the most conversions over the last 13 weeks, and what did each one cost per conversion?" The core budget question, answered from your own count.
  • "Show our Google Ads and Meta campaigns week by week for the last 4 weeks. Where did cost per conversion jump, and did clicks move with it?" Separates a traffic change from a conversion change, for campaigns busy enough to clear the small-group rule every week.
  • "How many campaign rows came back withheld over the last 13 weeks, and why?" You get a rounded tally and the rule behind it, not names, so a short list reads as privacy working, not broken tracking.
  • "Where do people drop off in the new-patient funnel over the last 52 weeks?" Funnel steps come back in order, as people counts.
  • "Show cost per conversion for Google Ads and Meta side by side for the last 52 weeks." Each campaign row carries its platform. Withheld campaigns drop out of both sides, so compare only what cleared the rule.

What it will not return

  • Anything about a person: names, email addresses, phone numbers, single visits, form answers or journeys.
  • Revenue or ROAS.
  • Breakdowns by channel, device, region or page.
  • Strings a visitor can set, such as UTM values, page paths and referrers.
  • Write actions of any kind.

Where the numbers get thin

A campaign row appears only when its conversion count clears the small-group rule. A campaign that spent money and converted a handful of people, or nobody, is withheld whole, spend included, and shows up only as one more in the withheld-rows tally. The connector cannot answer "which campaign is burning budget with nothing to show": that campaign is absent, not zero, so ask it in the dashboard. The same rule applies to every weekly row, so week-by-week campaign trends work only for campaigns that convert plenty of people every week.

Tagging decides the conversion count. A conversion is credited to the campaign in the visitor's last utm_campaign value within 30 days, and it counts only when that value equals the platform's campaign name or ID (case aside). A click that carries only a click ID and no utm_campaign, or a value that names an ad instead of the campaign, counts toward no campaign here. The campaign ID is the safest value, because a name can drift or arrive encoded.

The dashboard's campaign report matches more clicks than that, using other signals, so for the same weeks the connector's conversions can come in lower and its cost per conversion higher. When the two disagree, fix the tagging before moving budget.

Which AI clients can use it

Curve MCP works with anything that can connect to an MCP server: Claude (desktop, web and Claude Code), ChatGPT, Cursor and any other MCP-capable client or agent. Because MCP is an open standard, there is no separate integration per assistant: every client sees the same three tools and gets the same shaped answers.

For any MCP server, data travels a little differently depending on the client. A hosted client calls the server from the vendor's cloud, while a local client calls it from your machine. Either way, every tool result reaches the model vendor on the next turn. That is why every Curve MCP answer is shaped the same way whichever client asks, and why the vendor question stays yours:

  • The tracking BAA stops at the tracking platform. The AI vendor you connect is your choice, under your own agreement with that vendor.
  • Vendor coverage is narrow. Among Claude's apps, only Enterprise plans can enable HIPAA readiness, and Anthropic's own documentation disagrees on whether Claude Code is covered.
  • Prompts are a separate leak. Whatever a user types into an assistant reaches the vendor no matter which connectors are attached.

The connector adds nothing patient-level to what the AI app already holds. What your team types is a separate matter, and no connector controls it.

How Curve shapes every answer

Every call runs the same fixed sequence, and a failure at any step ends it without data.

  1. Check who is asking. The token must be valid, unexpired and bound to one organization, the organization must meet the connector's traffic minimum, and the user must have access switched on.
  2. Accept fixed choices only. The performance tool takes one input, a window from a closed list, with no filter, no date field and no free text, so an assistant cannot narrow a figure down to one person. The dashboard-link tool is the one exception. It accepts the question to draft and, optionally, the email or phone of the person asked about, so the assistant can hand them over without typing them into the question. Neither ever comes back in an answer, and the email or phone is stored only as a keyed hash.
  3. Query under a narrow role. The service reads through its own database identity, granted only the tables its queries need. It is refused form submissions and their contact details, form answers and session recordings, and it will not start if any of those ever becomes readable.
  4. Shape the numbers. People are counted once across the whole window, not once per visit. Small groups are withheld, every released count is rounded, spend is rounded, and cost per conversion is calculated from the rounded figures.
  5. Close the subtraction gap. Where one number could be subtracted from another to reveal a small group, the smaller number is withheld too.
  6. Show approved names only. A goal, funnel or campaign name appears only if the organization approved it. Otherwise the row reads "(label hidden)" and its numbers still count.
  7. Run a final guard. The full response is checked for anything shaped like an email, phone number, ID, date or name. On a hit, or if the guard cannot run, the answer is blocked. It fails closed.
  8. Log, then answer. Every call is recorded before anything is returned. If the record cannot be written, no data goes out.

Two choices carry most of the weight. The server releases values that were built to be safe; it does not scrub unsafe ones afterward, which is why the guard blocks rather than cleans. And because no visitor-set string is ever returned, a planted campaign tag or referrer cannot smuggle an instruction into your assistant through this connector.

The small-group mechanics, including why subtraction matters, are in how small-group rules work for de-identified MCP answers. The uncomfortable part is that de-identification costs detail, and the weekly rows pay first.

How access is scoped and logged

The server is read-only. It offers tools only, and none of them writes, so an assistant cannot change a campaign, a goal or a setting through it.

  • Off by default. Access is a per-user switch that starts off. Only the clinic's primary user can turn MCP on for the organization.
  • Scoped tokens that expire. A token is bound to one person and one organization, never spans organizations, and expires. Issuing one needs a confirmation code, and admins are notified. A leaked token exposes one organization's rounded aggregates at most.
  • Every call logged. The record holds who asked, which tool ran and what left. Calls that returned data are kept for years, so if anyone later asks what an assistant saw, there is a copy to check.

For a compliance officer, that turns approval into something checkable: a fixed output, a named set of tools and a log of every answer. The compliance officer checklist for approving an MCP connector covers what to ask of any server, this one included.

Who it is for

The connector is for healthcare organizations that track with Curve and want their marketing team asking campaign questions in an AI assistant without opening a path to patient data. That runs from an independent practice with a few campaigns to a national organization with dozens. One gate comes first: an organization needs steady site traffic, week after week, before the connector can be switched on, because rounding and withholding only protect people when there are enough of them. A very small practice may not clear it, and the dashboard answers its questions instead.

  • Independent practices. Lean on the 13- and 52-week windows. At low volume, weekly rows withhold more than they show, and the longer windows are where the numbers are dense enough to read.
  • Multi-location groups and national organizations. Expect organization-level figures. There is no location or region breakdown, so location questions go to the dashboard.
  • Marketing directors. The weekly cost-per-conversion check, asked the same way every Monday, is the job it does best.
  • Compliance officers. A server with fixed output and a full call log can be reviewed as a system, instead of reviewing every prompt the team writes.

It does not replace the dashboard. Person-level work, revenue and anything that needs a breakdown stays inside the product, where Curve Analyst works with the detail the connector withholds. The split is covered in Curve MCP and Curve Analyst: when to use which.

Frequently asked questions

Does the connector reconcile server-side campaigns?

Yes. It puts each campaign's platform-reported spend, clicks and impressions next to the conversions Curve's server-side tracking recorded, with cost per conversion by completed week, and one link opens the full sent, accepted and matched view inside Curve.

Does an MCP server make an AI assistant HIPAA compliant?

No, and no MCP server can. This one controls what leaves: rounded, organization-level weekly figures with small groups withheld and no identifiers. Whether your AI app and its vendor fit your HIPAA program is a separate decision, and the BAA you sign for tracking does not extend to that vendor.

Can an assistant change campaigns or budgets through it?

No. There are no write tools. That is a real difference from some ad-platform servers: Meta's, TikTok's and Amazon's MCP servers can create or change campaigns, while Google's official Google Ads server is read-only.

Who can switch the connector on?

Only the organization's primary user can turn MCP on for the organization, and each person's access is then a separate switch that starts off. A token belongs to one person and one organization, needs a confirmation code to issue, notifies admins when it is issued, and expires. Every call it makes is logged.

What happens when someone asks about a specific patient?

The assistant gets a link, not an answer. The link opens the in-product analyst with the question drafted, needs a login, works once and expires quickly. The connector returns nothing about the person, though anything the user typed into the prompt has already reached the AI vendor.

Does it work with ChatGPT?

Yes. Curve MCP works with ChatGPT, Claude (desktop, web and Claude Code), Cursor and any other client or agent that can connect to an MCP server. Every client gets the same tools and the same de-identified answers.

Which ad platforms do the campaign rows cover?

Google Ads and Meta campaigns with spend or clicks in the window, at campaign level. Spend, clicks and impressions are each platform's own figures. Conversions are your tracking's count.

Where to start

  1. Write down the five questions you ask every Monday. If they are about campaigns, weeks and cost per conversion, the connector answers them. If they are about people, revenue or pages, they belong in the dashboard.
  2. Settle the AI vendor question first. Pick the client your team will use and confirm what your agreement with that vendor covers, because no connector settles it for you.
  3. See it on real data. Book a Curve MCP demo to watch it answer campaign questions in Claude or ChatGPT, with withheld rows, hidden labels and the dashboard link in view. Bring your compliance officer.
  4. Not tracking with Curve yet? Run the free compliance scanner to see what your current tags send before anything else gets connected.

Reviewed September 2026. Product details reflect the connector's current ruleset. Anthropic, OpenAI, Google, Meta, TikTok and Amazon details were checked against official documentation on September 24, 2026.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit