Privacy policy

gmail-mcp-personal · last updated 24 September 2026

This policy describes how the private application gmail-mcp-personal (“the tool”) handles information. The tool is used by one individual, for that individual's own mailboxes.

1. Whose data is accessed

Only the mailboxes of the tool's operator. The tool is authorised by the operator through Google's OAuth consent flow, and it can only reach accounts the operator has personally signed in to and granted access to. It never accesses anyone else's account.

2. What is accessed

Access is requested through the Gmail API, using the gmail.readonly, gmail.modify, gmail.send and gmail.compose scopes.

3. Where the data goes

Nowhere except the operator's own computer. Messages and attachments that the operator chooses to export are written to local storage on that device. The tool does not transmit mail content to any third-party service, server, or analytics platform.

4. Sharing

None. No information obtained through the tool is sold, rented, published, or shared with any third party.

5. Storage and retention

Exported copies remain on the operator's device for as long as the operator keeps them, and can be deleted at any time by deleting the files. OAuth access tokens are stored locally on the same device.

6. Revoking access and deleting data

The operator can revoke the tool's access at any time at myaccount.google.com/permissions. Revoking access immediately stops all further access. Locally exported data can be deleted by removing the files from the device.

7. Security

Credentials are held locally on the operator's device and are not shared. Authentication is handled entirely by Google; the tool never sees or stores the operator's Google password.

8. Changes

Any future change to this policy will be published on this page, with the “last updated” date above amended.

9. Contact

hangtongma@gmail.com