Privacy Policy
Last updated: July 30, 2026
This Privacy Policy describes how the Gmail MCP Server ("the App"), operated by Nathan Higgs ("we", "us"), accesses and uses data from Google Accounts you explicitly connect to it. Contact: nathan@higgs.pro.
What the App is
The App is a personal-use tool, not a public product. It exposes a set of actions (an "MCP server") that a single authorized operator uses, via an AI assistant, to manage their own Gmail labels/filters and Google Drive files/folders across the Google Accounts they choose to connect. Access to the App's control interface is restricted to that operator by a private credential; it is not offered to the public.
Data we access
When you connect a Google Account via Google Sign-In/OAuth, the App requests permission to:
- Read, label, and organize your Gmail messages and manage Gmail labels and filters (
gmail.modify,gmail.settings.basic). - View, create, move, rename, and delete files and folders in your Google Drive (
drive). - Read your email address to identify which account is connected (
userinfo.email).
How we use data
Data obtained through these scopes is used solely to carry out actions the operator directly requests — for example, listing labels, moving/labeling messages, creating a filter, or organizing Drive folders. We do not use this data for advertising, do not build user profiles from it, do not sell or rent it, and do not share it with third parties except as strictly necessary to operate the App's own infrastructure (see "Storage" below). Message and file contents pass through the App only for the duration of each request; the App does not log, retain, or analyze the content of your emails or files.
Limited Use disclosure
The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we store
We store OAuth refresh tokens and short-lived access tokens (issued by Google) for each connected account, in private server-side storage (Vercel Blob, access-controlled and not publicly readable) so the App can act without requiring you to sign in again for every action. We do not store the content of your emails, attachments, or files. Tokens are retained until you disconnect the account (via the App's disconnect_mailbox action) or revoke access directly at myaccount.google.com/permissions.
Revoking access
You can revoke the App's access at any time from your Google Account's Third-party access settings, or by asking the App to disconnect a specific mailbox.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy: nathan@higgs.pro.