Privacy policy
Last updated:
Personal Google MCP is a private integration operated by Igor Klun under the klun.pro brand for the owner's personal Google account. This policy covers that integration and these public information pages. It does not provide other visitors with access to the account or cover unrelated services. Privacy contact: igor.klun@gmail.com.
How Google access works
The owner signs in directly with Google and chooses permissions on Google's authorization screen. The integration uses Google's APIs and OAuth authorization; it does not ask for or store the owner's Google password. Access depends on the permissions actually granted, API availability and the feature requested. Permission alone does not authorize a tool to act on its own.
Data accessed and why
Depending on the requested task and granted permissions, Personal Google MCP may retrieve and process:
- Account identity: name, email address, profile information and account identifier, to connect the correct account and reject other accounts.
- Email: message headers, senders, recipients, subjects, bodies, attachments, threads, drafts, labels and supported mailbox settings, to find, read and summarize email and support requested mail tasks.
- Calendars and tasks: calendar names, events, attendees, meeting details, task lists, task text, due dates and completion state, to answer scheduling and task questions.
- Drive and documents: file names, identifiers, metadata, content, permissions and sharing information, plus Docs text, Sheets cells and Slides content, to find and work with the owner's documents.
- Forms: form structure, questions and responses, to inspect forms and their submitted answers.
- Contacts and Chat: contact names, email addresses, phone numbers and other saved contact fields; accessible Chat spaces, membership and messages, to look up people and requested conversations.
- Apps Script: project metadata, source files, deployments and execution information, to inspect the owner's scripts and requested automation.
Results are used to carry out the owner's requested workspace task and produce its response. Features that change data, send messages or share content require separate owner authorization and applicable safeguards. Personal cloud writes are currently disabled. This policy does not activate them or start background synchronization.
Sharing and human access
Data passes between Google, the owner's private server and the assistant client selected by the owner. Only content relevant to an authorized task may be supplied to that client. A requested sharing or export action may also send selected content to the destination the owner identifies, when that action is enabled and authorized. These public pages never display account contents or authorization credentials.
Google provides the account and APIs. If the owner requests AI assistance, the configured AI service may receive relevant excerpts, attachments, prompts and generated responses needed for that task. When the owner uses OpenAI's Codex or ChatGPT, that recipient is OpenAI. Other assistant clients use the provider selected in their configuration. Review the selected provider's privacy and retention settings before authorizing a transfer. OAuth tokens and client secrets must not be included in AI prompts.
Human access to specific Google content requires the owner's affirmative agreement, except where necessary to investigate security issues or meet legal obligations. There is no routine third-party human review of account contents. Disclosures for security or legal requirements must be limited to what is necessary.
Limited Use and AI restrictions
Personal Google MCP complies with the Limited Use requirements of the Google API Services User Data Policy and the Google Workspace user data and developer policy. These restrictions also apply to information derived from Google data.
Google Workspace API data is not used to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models. Google data must not be sent to an AI provider for those purposes. Any AI processing must be limited to the owner's requested feature, with provider terms and settings that exclude such training.
Google data is not sold, supplied to data brokers or information resellers, used for advertising or retargeting, used for credit scoring or lending, or assembled into databases for unrelated purposes. It is not transferred for purposes outside the requested features and the limited security or legal circumstances described here.
Storage and protection
OAuth tokens and client credentials are kept on the owner's server under restricted file permissions, separately from public web content. The Google tool endpoint is private; the public website exposes no account-data API. Account checks bind access to the authorized owner. HTTPS protects connections to this website and Google. Backups containing authorization material are encrypted, and restoring them is restricted to the operator.
The personal integration does not automatically mirror the Gmail mailbox. Retrieved content is processed for the request; assistant conversations, generated responses and files explicitly saved by the owner can retain that content in the selected client or destination. Their storage and deletion controls belong to that service or destination.
Retention
Authorization material remains stored until the operator replaces or removes it. Revoking permission at Google invalidates access but does not automatically erase local credential files. Saved exports and responses remain until removed from their destination or expired by its retention controls. Assistant providers may keep conversation or processing records under their own published terms and the owner's settings.
Operational logs retain bounded, rotating records for troubleshooting and security. Public web records may include time, IP address, path and response status. Tool audit records identify operations and outcomes without recording OAuth tokens, complete tool arguments or message and file content. Encrypted snapshots follow the server's backup-retention schedule and cleanup process; deleting a live file does not immediately erase its older snapshots. The operator can provide the current schedule on request.
Revoke access or request deletion
- To stop Google access, open Google Account third-party connections, select this integration and remove its access. Further API access stops when Google's revocation takes effect.
- To remove locally stored authorization material or saved integration data, email igor.klun@gmail.com and identify the account and data concerned. Do not send passwords or OAuth tokens. The operator verifies the request, disables affected access and removes the identified active local copies.
- Remove saved assistant conversations, exports or responses through the relevant client's or destination's controls. Contact its provider for records governed by that provider's retention obligations.
Removing local integration data does not delete the original messages, files, contacts or events at Google. Those remain under the owner's Google-account controls. Backup copies expire through scheduled retention and cleanup rather than immediate individual removal; restored copies must not reactivate revoked access or undo an accepted deletion request.
Website cookies
These public pages set no application cookies and include no analytics scripts, tracking pixels, advertisements or third-party assets. The separate authenticated workspace may use cookies for its login session.
Policy updates
The date above identifies the current policy. Before introducing a new category or purpose of Google-data use or a materially different sharing practice, the operator must update this page, notify the owner through the assistant or direct contact, and obtain consent before that new use begins. The homepage links to this policy at https://klun.pro/privacy.