Privacy policy

A clear explanation of access, use, storage, and control.

Updated September 5, 2026

About this policy

This policy applies to mcp and its Google service integrations. The capabilities page describes the implemented features and requested permissions. For privacy questions or deletion requests, contact tugan0329@gmail.com.

Data we access

Access begins with your authorization through Google. mcp does not collect your Google password. Depending on the feature you use, the integrations process:

  • Account information: email address, account identifiers, authorization metadata, and OAuth access and refresh tokens.
  • Gmail: message and thread identifiers, headers, senders, recipients, subjects, bodies, labels, drafts, and attachment metadata. Attachment-backed message body parts may be retrieved to read an email.
  • Calendar: calendar metadata and event details returned by Google, including titles, times, descriptions, locations, and attendees.
  • Tasks: task-list identifiers and names; task titles, notes, status, due dates, update information, and links. Task workflows process text, not microphone recordings.

How data is used

Data is used to provide the features you choose: email search and organization, drafting and sending, calendar lookup, and selected task workflows. Calendar access is read-only. Task workflows may move tasks between configured lists, process a selected request, and mark completed work.

The current authorization configuration requests gmail.modify, gmail.send, calendar.readonly, and tasks. The capabilities page explains each scope. The permissions shown by Google describe the access you grant.

Sharing and connected services

Requested results are returned to the MCP client or workflow you connect. A cloud AI client may send prompts, email content, calendar details, task details, and tool results to its provider. Running an integration locally does not mean all processed information remains on the device.

  • Google: provides the authorized account services and OAuth authorization.
  • OpenAI / Codex: processes requests and selected content in the implemented AI-assisted task workflow.
  • Vestaboard: receives selected output when a connected-display workflow is enabled. Requested output may include task-derived text or calendar details and may be visible on the selected display.
  • Message recipients: receive emails when you authorize a send.

Transfers are limited to providing the requested user-facing features and permitted security or legal purposes. Use only clients and providers whose terms and settings support this policy. Review their retention, sharing, and model-training controls before connecting an account. Support correspondence is used to respond to the request.

Storage and protection

OAuth tokens and account metadata are stored in a local account store with owner-only file permissions on supported systems. The integration does not itself encrypt that file; device encryption and backup protection are controlled by the device owner. Google API requests use HTTPS.

The email connector does not keep a separate persistent mailbox database. Clients and task workflows may retain conversation history, task-derived prompts, outputs, state, and execution logs. Those files remain until removed; the current task workflow does not automatically expire them. Connected providers have their own retention controls. Displayed content remains until replaced or cleared.

Support correspondence is retained as needed to resolve the request and meet applicable obligations. Original Google account data remains subject to your Google account settings.

Google API Limited Use

mcp’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API user data and developer policy.

We do not sell Google user data, use it for advertising or credit decisions, or use or transfer it to develop, train, or improve non-personalized or general-purpose AI or machine-learning models. Human access is limited to your explicit agreement for specific data, security needs, legal obligations, or other uses permitted by Google’s policies. Connected services must uphold these restrictions.

Revoke access and delete data

Revoke mcp’s access in Google Account connections. Then remove the account from the local integration. These are separate actions: removing a local account does not revoke Google authorization, and revocation does not erase previously retained copies.

Stop connected workflows before removing their stored credentials or state. Delete retained client history, workflow files, logs, exports, and backups using the relevant controls. Clear displayed content and use provider controls or support channels to request deletion of provider-held copies. Removing integration data does not delete source emails, calendar events, or tasks in Google.

See the deletion guide or contact tugan0329@gmail.com for help.

This website

This informational website does not connect to your Google account or receive OAuth tokens or account content. It has no advertising, analytics scripts, or tracking cookies.

The site is hosted on Google Cloud Run. Google Cloud processes request information such as IP address, requested URL, browser information, status codes, and timestamps to deliver and protect it. The default Cloud Logging bucket is configured for 30-day retention. The static server does not maintain an additional access log. Google Cloud may retain service-security records under its applicable terms.

Changes and new features

New integrations must have an implemented purpose, appropriate permissions, and clear data-use disclosures before activation. New access requires user authorization and any applicable platform review. Existing consent does not authorize unrelated future uses. Material changes to these practices will be disclosed before the changed processing begins.