How Personal Mail MCP handles data. In force as of 27 August 2026.
Personal Mail MCP ("the application") is a locally installed, single-user tool. This policy describes how it handles the data of the individual who installs and runs it (the "operator"). The application has no other users.
With the operator's explicit Google authorization, the application accesses the operator's own Gmail data, specifically:
It accesses only the Google Account that the operator has personally authorized. It never accesses any other person's account.
Data is retrieved from Google's API, passed to an AI assistant running under the operator's control for the sole purpose of answering the operator's own questions or drafting the operator's own replies, and then discarded. The application maintains no database and no message archive.
The only data written to persistent storage is authentication material, held in a directory on the operator's own computer with owner-only file permissions:
Attachments are written to disk only when the operator explicitly asks for one to be downloaded. Nothing else is retained.
The application transmits data to no one. It makes network requests only to
Google's own API endpoints at googleapis.com, using the operator's
credentials, to serve the operator's own requests. There is no analytics, no
telemetry, no error reporting service, no advertising, and no third-party
recipient of any kind. No data is sold, rented, or disclosed.
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the operator with the functionality described above, is never transferred to others, is never used for advertising, and is never used to train generalized AI or machine learning models.
Message data is not retained past the request that fetched it. Stored credentials persist until the operator deletes them. The operator may revoke the application's access at any time at myaccount.google.com/permissions, which immediately and permanently invalidates all stored tokens. Deleting the application's configuration directory removes every trace of stored credentials.
Credentials are stored with owner-only file permissions. Because the application runs on the operator's own machine, its security is bounded by the security of that machine and the operator's account on it.
The application is not directed at children and is not made available to the public.
Any change to this policy will be published on this page with an updated date.
Questions about this policy may be sent to gmailMCP@bsq.info.