Privacy policy
A clear explanation of access, use, storage, and control.
Updated September 5, 2026
About this policy
This policy applies to mcp and its Google service integrations. The capabilities page describes the implemented features and requested permissions. For privacy questions or deletion requests, contact tugan0329@gmail.com.
Data we access
Access begins with your authorization through Google. mcp does not collect your Google password. Depending on the feature you use, the integrations process:
- Account information: email address, account identifiers, authorization metadata, and OAuth access and refresh tokens.
- Gmail: message and thread identifiers, headers, senders, recipients, subjects, bodies, labels, drafts, and attachment metadata. Attachment-backed message body parts may be retrieved to read an email.
- Calendar: calendar metadata and event details returned by Google, including titles, times, descriptions, locations, and attendees.
- Tasks: task-list identifiers and names; task titles, notes, status, due dates, update information, and links. Task workflows process text, not microphone recordings.
How data is used
Data is used to provide the features you choose: email search and organization, drafting and sending, calendar lookup, and selected task workflows. Calendar access is read-only. Task workflows may move tasks between configured lists, process a selected request, and mark completed work.
The current authorization configuration requests gmail.modify, gmail.send, calendar.readonly, and tasks. The capabilities page explains each scope. The permissions shown by Google describe the access you grant.
Storage and protection
OAuth tokens and account metadata are stored in a local account store with owner-only file permissions on supported systems. The integration does not itself encrypt that file; device encryption and backup protection are controlled by the device owner. Google API requests use HTTPS.
The email connector does not keep a separate persistent mailbox database. Clients and task workflows may retain conversation history, task-derived prompts, outputs, state, and execution logs. Those files remain until removed; the current task workflow does not automatically expire them. Connected providers have their own retention controls. Displayed content remains until replaced or cleared.
Support correspondence is retained as needed to resolve the request and meet applicable obligations. Original Google account data remains subject to your Google account settings.
Google API Limited Use
mcp’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API user data and developer policy.
We do not sell Google user data, use it for advertising or credit decisions, or use or transfer it to develop, train, or improve non-personalized or general-purpose AI or machine-learning models. Human access is limited to your explicit agreement for specific data, security needs, legal obligations, or other uses permitted by Google’s policies. Connected services must uphold these restrictions.
Revoke access and delete data
Revoke mcp’s access in Google Account connections. Then remove the account from the local integration. These are separate actions: removing a local account does not revoke Google authorization, and revocation does not erase previously retained copies.
Stop connected workflows before removing their stored credentials or state. Delete retained client history, workflow files, logs, exports, and backups using the relevant controls. Clear displayed content and use provider controls or support channels to request deletion of provider-held copies. Removing integration data does not delete source emails, calendar events, or tasks in Google.
See the deletion guide or contact tugan0329@gmail.com for help.
This website
This informational website does not connect to your Google account or receive OAuth tokens or account content. It has no advertising, analytics scripts, or tracking cookies.
The site is hosted on Google Cloud Run. Google Cloud processes request information such as IP address, requested URL, browser information, status codes, and timestamps to deliver and protect it. The default Cloud Logging bucket is configured for 30-day retention. The static server does not maintain an additional access log. Google Cloud may retain service-security records under its applicable terms.
Changes and new features
New integrations must have an implemented purpose, appropriate permissions, and clear data-use disclosures before activation. New access requires user authorization and any applicable platform review. Existing consent does not authorize unrelated future uses. Material changes to these practices will be disclosed before the changed processing begins.
