Last updated: June 30, 2026
gmail-mcp-oauth ("the service") is an OAuth-authenticated Model Context Protocol (MCP) server that connects to the Google Gmail API on your behalf. It is operated by Welch Commerce Systems, a DBA of Welch Products LLC ("Welch Commerce Systems," "we," "us," or "our"). This privacy policy explains what Google user data the service accesses, and how it uses, stores, shares, retains, and deletes that data.
This policy applies to the instance of gmail-mcp-oauth that Welch Commerce Systems operates and has registered with Google for OAuth access. gmail-mcp-oauth is also open-source software; if you deploy your own instance from the source code, you are the operator and data controller of that deployment and this policy does not apply to it.
With the OAuth scopes you approve on Google's consent screen, the service accesses the Gmail API to:
The service requests only the scopes needed for the Gmail features you use. You see and approve every scope on Google's consent screen before any access is granted, and you can decline.
We use the Google user data the service accesses solely to provide the Gmail features you invoke through your connected MCP client. The service acts only in response to your requests, or to requests from a client you have connected and authorized. We do not use your Google user data for any purpose other than providing these user-facing features.
We do not sell your Google user data, and we do not share it with third parties for their own purposes. Your data flows only to:
We do not transfer your Google user data to advertising platforms, data brokers, or information resellers.
gmail-mcp-oauth's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data to serve advertising; we do not transfer or sell it to third parties for advertising or other unrelated purposes; we do not use it to train generalized or non-personalized artificial-intelligence or machine-learning models; and we allow humans to read your data only with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
The service encrypts refresh tokens at rest, supports encryption-key rotation, authenticates every request, gates account access behind an explicit allowlist, and runs in a hardened, non-root container. Decrypted tokens exist only transiently in memory at the moment of an API call.
The service is intended for business and developer use and is not directed to children. We do not knowingly collect data from children.
If we change this privacy policy, we will post the updated version at this same URL and revise the "Last updated" date above. Material changes will be reflected here before they take effect.
For questions about this privacy policy or the service's handling of your data, contact Welch Commerce Systems at [email protected].