Use AI Agents With Your Own Database — Without Uploading Your Customer Data

The question we keep hearing
"We like the agents, but we do not want to upload our customer data." It is a fair position. Your customer list, order history and pricing are yours, and copying them into another system is one more place they can leak from.
You do not have to. A ThinnestAI agent can use data it never stores.
How it works: actions
An action is an HTTPS endpoint of yours that the agent may call mid-conversation, with arguments it fills from what the customer said. "Where is my order 10432?" becomes a call to GET https://api.yourapp.com/orders/10432, and the agent answers from what your API returns.
- It works on every channel — website chat, WhatsApp, Telegram and phone calls.
- Your API decides what to return. Return the order's status, not the whole history.
- Your credentials are stored encrypted and never shown again.
- A new action is off until you test it and switch it on.
What stays where — precisely
| Where it lives | |
|---|---|
| Your customer list, orders, stock, CSVs | Your database. The agent asks for one answer at a time. |
| The conversation itself | Passes through ThinnestAI and the AI model while the agent answers. ThinnestAI stores the conversation history — the agent re-reads it to continue a conversation — in India. |
| What each action was called with | Kept by ThinnestAI as an audit trail of what the agent asked your system. |
| Leads, escalations, call results | Sent to your systems by signed webhook as they happen. |
We are careful with this wording, and you should be with yours: the conversation is not "never stored". The records you look things up in stay in your database.
Get what happens back into your systems
Webhooks send each event to your endpoint, signed so you can verify it came from us: a lead captured, a conversation escalated or resolved, a call finished, and a call's results — summary, the details it collected, the full transcript and a recording link. Write them into your own tables and your database becomes the system of record for everything the agent did.
Build it in one session
With the ThinnestAI MCP server connected to Claude Code or Cursor, one conversation does the whole thing: the assistant writes the endpoint in your app, creates the action, tests it against your real API, asks you before switching it on, sets up the webhook receiver with signature checks, and test-chats the agent to prove it answers from your data.
Rules for the endpoints
- https only. Addresses inside private networks are refused.
- Answer within 10 seconds — someone on the phone is waiting.
- Treat every argument as untrusted. It came from a stranger's message: parameterised queries, and never let an argument choose a table or a URL.