Privacy Policy
Last updated: July 30, 2026
This Privacy Policy describes how the Gmail MCP Server ("the App"), operated by Nathan Higgs ("we", "us"), accesses and uses data from Google Accounts you explicitly connect to it. Contact: nathan@higgs.pro.
What the App is
The App is a personal-use tool, not a public product. It exposes a set of actions (an "MCP server") that a single authorized operator uses, via an AI assistant, to manage their own mail folders, filing rules, and cloud files across the accounts they choose to connect. It supports both Google accounts (Gmail and Google Drive) and Microsoft 365 accounts (Outlook and OneDrive). Access to the App's control interface is restricted to that operator by a private credential; it is not offered to the public.
Data we access — Google accounts
When you connect a Google Account via Google Sign-In/OAuth, the App requests permission to:
- Read, label, and organize your Gmail messages and manage Gmail labels and filters (
gmail.modify,gmail.settings.basic). - View, create, move, rename, and delete files and folders in your Google Drive (
drive). - Read your email address to identify which account is connected (
userinfo.email).
Data we access — Microsoft 365 accounts
When you connect a Microsoft 365 account, the App requests permission to:
- Read and organize your Outlook mail folders and move messages between them (
Mail.ReadWrite). - Read and manage your inbox rules, which auto-file incoming mail (
MailboxSettings.ReadWrite). - View, create, move, rename, and delete files and folders in your own OneDrive (
Files.ReadWrite). This does not extend to SharePoint sites or files shared with you by others. - Read and manage your Microsoft To Do task lists and tasks, including their due dates and notes (
Tasks.ReadWrite). - Read your name and email address to identify which account is connected (
User.Read).
How we use data
Data obtained through these scopes is used solely to carry out actions the operator directly requests — for example, listing folders or labels, searching for and reading specific messages, moving messages, creating a filing rule, or organizing cloud folders. We do not use this data for advertising, do not build user profiles from it, do not sell or rent it, do not use it to train AI models, and do not share it with third parties except as strictly necessary to operate the App's own infrastructure (see "Storage" below).
When the operator asks to read or summarize a message, its content is retrieved from Google or Microsoft, returned to the operator's own AI assistant for that single request, and then discarded. The App does not log, store, index, or retain the content of your emails, attachments, or files at any point.
Limited Use disclosure
The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we store
We store OAuth refresh tokens and short-lived access tokens (issued by Google or by Microsoft) for each connected account, in private server-side storage (Vercel Blob, access-controlled and not publicly readable) so the App can act without requiring you to sign in again for every action. Each account's tokens are held in a separate object. We do not store the content of your emails, attachments, or files. Tokens are retained until you disconnect the account (via the App's disconnect_mailbox ordisconnect_outlook_mailbox action) or revoke access directly with your provider.
Revoking access
You can revoke the App's access at any time — for Google accounts from myaccount.google.com/permissions, and for Microsoft 365 accounts from myapps.microsoft.com or via your tenant administrator — or by asking the App to disconnect a specific mailbox.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy: nathan@higgs.pro.