Privacy Policy
MCP Wave ("MCP Wave", "we", "us") provides hosted Model Context Protocol (MCP) connectors that let an AI assistant you choose work with services you already use, such as Gmail. This policy explains what data we access, how we use it, how long we keep it, and how you can remove it.
If you do not agree with this policy, do not connect the service.
1. Who we are
MCP Wave. Contact: support@mcpwave.com. You may use this address for any privacy question, data access request, or deletion request.
2. What the service does
You connect a Google account to MCP Wave through Google's standard OAuth consent screen. Once connected, an AI assistant that you have authorized (for example, a Model Context Protocol client such as Claude) can ask our service to perform Gmail actions on your behalf — searching and reading mail, drafting replies, sending approved mail, applying labels, archiving, trashing, and managing Gmail filters and send-as addresses.
Every action is taken because you asked your assistant to take it. We do not act on your mailbox on our own initiative.
3. Google user data we access
We request the narrowest Google OAuth scopes that support the features described on our home page:
Through these scopes we may handle the content of your email messages (including subject, body, attachments metadata, and recipients), your labels and filters, and your account's email address.
4. How we use it
- Only to perform the actions you request through your AI assistant.
- To return the results of those actions to the AI assistant you connected — see section 5.
- To maintain your connection (refreshing authorization, and remembering which mailboxes you linked and which recipients you approved for sending).
- To investigate security incidents and abuse, and to comply with law.
We do not:
- Sell, rent, or trade your data.
- Use it for advertising or for building marketing profiles.
- Use it to train, retrain, or improve generative AI or machine learning models.
- Read your mail ourselves, except in the narrow cases described in section 6.
5. Disclosure to your AI assistant
This is important to understand: the purpose of the service is to make your data available to an AI assistant that you choose and authorize. When you ask that assistant to read or search your mail, the relevant message content is transmitted to that assistant's operator so it can answer you.
That operator's own privacy policy and data handling then apply to the content it receives. MCP Wave is not responsible for how a third-party AI provider handles data once you have directed it to be sent there. Only data responsive to your request is sent; we do not bulk-export your mailbox.
6. Limited Use disclosure
MCP Wave's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and consistent with those requirements:
- We limit use of Google user data to providing or improving the user-facing features that are prominently described in the application's user interface.
- We do not transfer Google user data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with the user's explicit prior consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless: (a) we have your explicit consent for specific messages; (b) it is necessary for security purposes such as investigating abuse; (c) it is required to comply with applicable law; or (d) the data has been aggregated and de-identified for internal operations.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or ML models.
7. Storage, security, and location
- Your Google refresh token is encrypted at rest with AES-256-GCM under a key held in a managed secret store, separate from the database.
- Access tokens we issue to your AI client are stored only as irreversible hashes.
- All network traffic is encrypted in transit with TLS.
- The service runs on Google Cloud Platform in the United States
(
us-central1), using Cloud Run and Firestore. - Each connection is isolated to the account that authorized it; one user's connection cannot reach another user's mailbox.
- Message content is processed to fulfill your request and is not retained in our database afterward.
No system is perfectly secure. If you believe your account or data has been compromised, contact support@mcpwave.com.
8. What we retain
9. Deleting your data / revoking access
You can end our access at any time, in any of these ways:
- Disconnect the connector in your AI assistant.
- Remove a mailbox from the MCP Wave setup screen shown when you connect.
- Revoke MCP Wave at myaccount.google.com/permissions.
- Email support@mcpwave.com and ask us to delete your data.
Revoking access immediately invalidates our stored authorization. We delete the associated tokens and connection settings. Deletion requests sent by email are actioned within 30 days.
10. Children
The service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
11. Changes
We may update this policy. Material changes will be reflected in the "Last updated" date above, and where appropriate we will notify connected users. Continued use after a change means you accept the updated policy.