GmailMCP

Effective October 5, 2026

Privacy policy

GmailMCP is a privately operated, personal-use integration for its owner's Gmail account, supporting FIN-001 Personal Finance and GMAIL-001 email organization. The Google authorization screen may identify the application as FIN-001 Personal Finance. This website provides public information only; it does not offer mailbox access or public registration.

Data accessed and why

With the owner's Google authorization, the integration can read the account email address, message identifiers, headers, senders and recipients, subjects, bodies, labels, threads, and attachments. It uses selected messages to find receipts, statements, and payment notifications, preserve source evidence, support personal finance review, and prepare email classifications and label proposals.

The current GmailMCP connection is read-only. Mailbox label changes require a separate permission grant and approval. Sending mail, creating calendar events, and reminders are not enabled by that grant; future features require updated disclosures and any necessary consent before use.

Storage and security

GmailMCP keeps authorization credentials in the owner's macOS Keychain. Selected messages, original message content, attachments, processing records, and audit evidence may be stored in a local database on the owner's device. Google API requests use HTTPS. The local evidence database is not separately encrypted by GmailMCP; its protection depends on device access controls, disk encryption, and the owner's backup configuration.

Connected tools and sharing

Selected content and derived results may be passed to the owner's configured FIN-001 or GMAIL-001 tools to carry out the requested workflow. If the owner enables AI-assisted processing, those tools may send selected email content to the chosen AI provider. GmailMCP itself does not call an AI model. Such processing must be limited to the requested feature and the owner's consent; provider retention depends on the provider and account settings. This policy does not claim that every connected tool processes data only on-device.

Google-derived data must not be sold, used for advertising, supplied to data brokers, used to determine creditworthiness, or used to train general-purpose AI models. Transfers are limited to providing the disclosed features with consent, security needs, or legal requirements. Access by another person requires specific owner authorization unless necessary for security or legal compliance.

Use and transfer of information received from Google APIs are subject to the Google API Services User Data Policy, including its Limited Use requirements.

Retention, deletion, and revocation

Local evidence is retained until the owner removes it; GmailMCP currently has no automatic retention schedule. Audit evidence is append-only during normal operation. Removing a complete local archive and its backups is an owner-managed task, and copies in connected tools must be removed separately.

The owner can stop future access in Google Account connections and remove the saved GmailMCP Keychain credential. Revocation does not automatically delete previously downloaded messages, attachments, derived records, or backups. Local deletion does not delete the original Gmail messages.

This public website

These static pages contain no mailbox data, sign-in form, advertising, or site-authored analytics. The hosting provider may process standard request information such as IP addresses and browser details to deliver and secure the website.

Contact and changes

For privacy questions or deletion assistance, contact the application owner using the support email shown on the Google consent screen. Material changes to Google-data use require updated disclosures and renewed consent where applicable.