Privacy Policy

Application: pi-workspace-mcp · Last updated: 1 October 2026

1. Scope

This policy covers pi-workspace-mcp ("the Application"), a private automation client used by a single individual to access that individual's own Google Workspace account. The Application has one user — its owner. It is not distributed, offered, or made available to the public, and it holds credentials for no Google Account other than its owner's.

2. What data the Application accesses

Only with the owner's prior consent, and only for the owner's own Google Account, the Application may access:

3. How data is used

Data is used solely to carry out the owner's own instructions — for example, reading a document the owner asked to summarise, or writing a value the owner asked to record. The Application performs no analytics, no profiling, no advertising, and no automated decision-making. It trains no machine-learning models on Google user data.

4. Data sharing and disclosure

Google Workspace data is not sold, rented, traded, transferred, or disclosed to any third party. There are no analytics providers, advertising partners, data brokers, or other recipients. Google user data is exchanged only between the owner's own computer and Google's APIs.

This disclosure reflects the Limited Use requirements of the Google API Services User Data Policy. Google user data is used only to provide and improve the user-facing features described above, is not transferred to others except as necessary to provide those features or as required by law, and is not used for advertising.

5. Storage and retention

The Application stores no Google user data on any remote or third-party server. It runs entirely on the owner's own computer.

OAuth credentials are stored locally on the owner's computer only, in files readable solely by the owner, at ~/.google_workspace_mcp/credentials/. They consist of an access token, a refresh token, and the associated scope grant. Credentials are retained until the owner revokes access, at which point they cease to function.

6. Data protection

All communication with Google's APIs uses HTTPS. Local credential files are protected by filesystem permissions limiting access to the owner's user account. No Google user data is transmitted to, processed by, or stored on any third-party service.

7. Revoking access

The owner may revoke the Application's access at any time at https://myaccount.google.com/permissions. Revocation takes effect immediately; the locally stored refresh token stops working and can be deleted.

8. Children

The Application is used exclusively by its owner and is not directed at children.

9. Changes to this policy

Any update to this policy will be published at this URL with a revised "Last updated" date.

10. Contact

Questions about this policy or about the Application's handling of data: luarlelima@gmail.com