mail-mcp

Privacy Policy

Last updated 1 September 2026.

Who this covers

mail-mcp is private software built and operated by Lorenz Ueing, Lucerne, Switzerland. It is used solely by him to access his own email accounts. It is not offered to the public, has no other users, and there is no account registration or sign-up of any kind.

This policy exists because Google requires every application using its authorization APIs to publish one. The application described here processes only the operator's own data.

What the application does

mail-mcp connects to email accounts belonging to the operator and allows him to search, read, organise and send his own mail through an AI assistant interface. Google accounts are connected through Google's standard OAuth consent flow. A Proton Mail account is connected locally through Proton Mail Bridge, which decrypts mail on the operator's own machine. Each account is authorised separately, and authorisation can be withdrawn at any time.

Data accessed

From Google the application requests only gmail.modify and gmail.send. It does not request permanent-deletion access, and it does not access Google Drive, Calendar, Contacts, or any other Google service.

How data is handled

Sharing and disclosure

No data accessed by this application is sold, rented, published, or shared with any third party. There is no advertising, no analytics, and no profiling.

When the operator uses the application through an AI assistant, the content he chooses to act on is transmitted to that assistant's provider in order to produce a response, under that provider's own terms. No other transmission of message content occurs.

Google user data and Limited Use

Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Retention and deletion

No message content is retained by the application. Stored tokens are deleted when the operator removes an account from the configuration, or when he revokes access — for Google accounts at myaccount.google.com/permissions, which immediately ends the application's access to that account.

Contact

Questions about this policy: lu@m2a.ch.