Read-only AI assistant connector: does it fit the Developer Terms, and does it work for HIPAA sellers and free-plan Bookings reads?

Hi,

We’re Cotter Systems, and we run a hosted, read-only connector that lets business owners ask their own AI assistant (Claude or ChatGPT) questions about their business, answered from the systems they already use.. It’s built and running with practice-management, accounting and spreadsheet systems, at the sandbox and early-pilot stage. We’d like to add Square Appointments, starting with independent medical spas, and want to check three things before we build:

  1. Developer Terms. The terms say a developer may not “create a service that functions substantially the same as the Developer Tools or any Square service,” and Square offers its own MCP server. Ours differs in two ways. It answers across Square and a seller’s other systems, for example Square bookings alongside QuickBooks. It also works out things Square doesn’t, such as which clients are overdue for their usual treatment. It requests read scopes only. Does an integration like this fit the terms?

  2. HIPAA-covered sellers. Some of these sellers are healthcare providers, and we’ll sign a business associate agreement with each of them. Does anything in Square’s terms or HIPAA program limit a developer reading Square Appointments data for such a seller? Or is there a separate agreement we’d need with Square?

  3. Free-plan reads. The Bookings API guide says that on the free Appointments plan, “all the API calls… with seller-level readable permissions succeed.” The Appointments pricing page lists “Bookings API” as not included on Free. Can you confirm that APPOINTMENTS_ALL_READ, CUSTOMERS_READ and ORDERS_READ work for a seller on the free plan?

We don’t use seller data to train AI models, and we’d store seller content only with the seller’s express consent.

Thanks,
Safi Abdul, Founder, Cotter Systems

On the Developer Terms and HIPAA questions, we can’t provide legal advice or pre-approve an integration through the Developer Forums. You’ll want to review the Square Developer Terms and Square HIPAA BAA with your counsel. The relevant areas to pay close attention to are seller consent/OAuth, requesting only the scopes you need, clearly explaining what data your service accesses and stores, deleting data if authorization is revoked, and not using Square Content or seller data to train or improve an AI system.

For sellers on the Free Appointments plan, APPOINTMENTS_ALL_READ is expected to work. A paid Appointments Plus or Premium plan is required for seller-level writes, such as creating, updating, or canceling seller-level bookings with APPOINTMENTS_ALL_WRITE.

CUSTOMERS_READ and ORDERS_READ are separate API permissions and aren’t tied to the Appointments subscription plan, assuming the seller authorizes those scopes and the relevant data exists.