Privacy Policy

Last updated: July 30, 2026

This Privacy Policy describes how the Gmail MCP Server ("the App"), operated by Nathan Higgs ("we", "us"), accesses and uses data from Google Accounts you explicitly connect to it. Contact: nathan@higgs.pro.

What the App is

The App is a personal-use tool, not a public product. It exposes a set of actions (an "MCP server") that a single authorized operator uses, via an AI assistant, to manage their own Gmail labels/filters and Google Drive files/folders across the Google Accounts they choose to connect. Access to the App's control interface is restricted to that operator by a private credential; it is not offered to the public.

Data we access

When you connect a Google Account via Google Sign-In/OAuth, the App requests permission to:

How we use data

Data obtained through these scopes is used solely to carry out actions the operator directly requests — for example, listing labels, moving/labeling messages, creating a filter, or organizing Drive folders. We do not use this data for advertising, do not build user profiles from it, do not sell or rent it, and do not share it with third parties except as strictly necessary to operate the App's own infrastructure (see "Storage" below). Message and file contents pass through the App only for the duration of each request; the App does not log, retain, or analyze the content of your emails or files.

Limited Use disclosure

The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we store

We store OAuth refresh tokens and short-lived access tokens (issued by Google) for each connected account, in private server-side storage (Vercel Blob, access-controlled and not publicly readable) so the App can act without requiring you to sign in again for every action. We do not store the content of your emails, attachments, or files. Tokens are retained until you disconnect the account (via the App's disconnect_mailbox action) or revoke access directly at myaccount.google.com/permissions.

Revoking access

You can revoke the App's access at any time from your Google Account's Third-party access settings, or by asking the App to disconnect a specific mailbox.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy: nathan@higgs.pro.