Privacy Policy
Last updated: September 24, 2026
This policy describes the personal, local-use integration called Aside Personal Gmail MCP (the “App”). The App is operated by the owner of the connected Gmail account. Contact: yunmartin@gmail.com.
Information the App accesses
When the owner invokes a tool, the App may access Gmail message and thread content, headers, sender and recipient addresses, subjects, dates, labels, message identifiers, attachment metadata, and attachment content. Google OAuth permissions are limited to Gmail read access and Gmail compose access. The compose permission can manage drafts and send email.
How information is used
The App uses Gmail data only to carry out a tool call requested by the owner: search or read email, retrieve a requested attachment, create an unsent draft, or send a message. The App does not continuously scan the mailbox, run a background inbox monitor, sell Gmail data, or operate a hosted service for other users.
Where information is processed
- Gmail API requests go directly to Google.
- Results returned by the App are provided to Aside. If the owner asks an AI model to analyze email or attachment content, that content may be processed by the AI model provider selected in Aside. The provider's own terms and privacy settings apply.
- The App has no remote application backend and does not send email content to an independent App operator.
Local storage and retention
- OAuth access and refresh tokens are stored locally in a Windows DPAPI-protected file scoped to the current Windows user.
- The OAuth desktop-client configuration is stored in the owner's local Aside directory and should not be shared.
- The App does not intentionally retain message bodies after a tool call. When the owner requests an attachment download, a local copy is saved in the App's attachments folder and remains there until the owner deletes it.
- Drafts and sent messages remain in Gmail and are subject to Google's account settings and retention.
Security and user control
The OAuth callback listens only on the local loopback interface. The App is locked to the owner's Gmail account. The owner can revoke access in Google Account security settings and can delete the local token and downloaded files. The send tools send only when explicitly invoked; the owner should check recipients, content, and attachments before sending.
Changes
This policy may be updated if the App's data handling changes. The latest version will be posted on this page.