Privacy policy

This is a single-operator, self-hosted deployment. It is used only by Frank Dekervel, for Google accounts he owns.

What is accessed

When an account is authorised, the service receives an OAuth token that lets it call Google Workspace APIs (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script) as that account, and only in response to requests made by the authorised user through a connected MCP client.

What is stored

OAuth refresh tokens are stored on the operator's own server so sessions survive restarts. Message, file and calendar content is passed through in response to a request; it is not retained by this service.

What is shared

Nothing is sent to any third party. Data flows only between Google's APIs, this server, and the MCP client the authorised user has connected. There is no analytics, telemetry, advertising or sale of data.

Deleting your data

Revoking access at myaccount.google.com/permissions immediately invalidates the stored token. Stored tokens can also be deleted on request.

Contact: kervel@gmail.com