Privacy Policy

Last updated 8 October 2026

CloudStash builds software used by our own teams and by people who work with us. This policy explains what happens to personal data when you use it. It covers google-mcp, which connects a Google account to an AI assistant.

The short version

google-mcp runs entirely on your own computer. CloudStash operates no server in the path, and we never receive, store or log your Google data or your credentials.

But your data does leave your machine. google-mcp exists to give an AI assistant access to your Google account, so anything it retrieves — message bodies, calendar events, file contents, documents — is passed to the AI client you are running, which sends it to that client's model provider under their privacy terms, not ours. If you use Claude Code, that is Anthropic. This is the purpose of the software rather than a side effect, and it is the most important thing on this page.

What google-mcp does

google-mcp is a local MCP (Model Context Protocol) server. Your AI client starts it as a process on your own Mac. It has no public listener: the only server it ever opens is a temporary one on 127.0.0.1 that exists while you sign in and does nothing but receive Google's redirect.

What it accesses

You choose the products and the access level when you connect an account, per account. Access is granted by you through Google's own consent screen.

Product Read only Read and write
Gmail gmail.readonly gmail.modify
Calendar calendar.readonly calendar
Drive drive.readonly drive
Docs documents.readonly documents

Every sign-in also requests openid and userinfo.email, used only to confirm which account granted consent. gmail.modify cannot permanently delete mail.

Credentials

Where your data goes

To Google

Requests go directly from your machine to Google's APIs. Google's client libraries add a standard header naming the library version; that header goes to Google only.

To your AI client and its model provider

Results are returned to the AI client that started google-mcp, and that client transmits them to its model provider for processing. CloudStash has no control over, and no visibility into, what that provider does with them. Consult your AI client's privacy policy — that relationship is between you and them.

To your local disk

Saving an attachment or downloading a file writes it to a path you or your assistant chooses. Those files remain on your computer.

Logs

google-mcp writes diagnostic text to standard error only. Your AI client may record that output, and the tool calls and results, in its own logs. Those logs belong to that client, not to CloudStash.

What CloudStash collects

Nothing. google-mcp contains no analytics, telemetry, crash reporting, error reporting or update check. Its only outbound network connections are to Google.

Removing access

Run, on your own machine:

google-mcp remove-account your-address@example.com

This revokes the grant at Google, deletes that account's token from your Keychain, and removes the address from the local list.

Revoking at myaccount.google.com/permissions makes the stored token useless, but does not delete it from your Keychain. Run remove-account as well if you want the credential gone from your machine.

After removal, these remain on your computer:

google-mcp retains no message identifiers, content or cache of its own.

Children

This software is not directed at children and is not offered for public download.

Changes

If this policy changes materially we will update the date at the top of this page.

Contact

Privacy questions: privacy@cloudstashhq.com

CloudStash, Texas, United States.