MCP Wave
Privacy Policy

Privacy Policy

Effective 1 July 2026 · Last updated 1 July 2026

MCP Wave ("MCP Wave", "we", "us") provides hosted Model Context Protocol (MCP) connectors that let an AI assistant you choose work with services you already use, such as Gmail. This policy explains what data we access, how we use it, how long we keep it, and how you can remove it.

If you do not agree with this policy, do not connect the service.

1. Who we are

MCP Wave. Contact: support@mcpwave.com. You may use this address for any privacy question, data access request, or deletion request.

2. What the service does

You connect a Google account to MCP Wave through Google's standard OAuth consent screen. Once connected, an AI assistant that you have authorized (for example, a Model Context Protocol client such as Claude) can ask our service to perform Gmail actions on your behalf — searching and reading mail, drafting replies, sending approved mail, applying labels, archiving, trashing, and managing Gmail filters and send-as addresses.

Every action is taken because you asked your assistant to take it. We do not act on your mailbox on our own initiative.

3. Google user data we access

We request the narrowest Google OAuth scopes that support the features described on our home page:

https://www.googleapis.com/auth/gmail.modify
Read, compose, send, and organize messages, threads, drafts, and labels in your Gmail account.
https://www.googleapis.com/auth/gmail.settings.basic
Read and manage Gmail filters and send-as (alias) addresses.
openid, email
Your Google account identifier and email address, used only to identify which mailbox a connection belongs to.

Through these scopes we may handle the content of your email messages (including subject, body, attachments metadata, and recipients), your labels and filters, and your account's email address.

4. How we use it

We do not:

5. Disclosure to your AI assistant

This is important to understand: the purpose of the service is to make your data available to an AI assistant that you choose and authorize. When you ask that assistant to read or search your mail, the relevant message content is transmitted to that assistant's operator so it can answer you.

That operator's own privacy policy and data handling then apply to the content it receives. MCP Wave is not responsible for how a third-party AI provider handles data once you have directed it to be sent there. Only data responsive to your request is sent; we do not bulk-export your mailbox.

6. Limited Use disclosure

MCP Wave's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and consistent with those requirements:

7. Storage, security, and location

No system is perfectly secure. If you believe your account or data has been compromised, contact support@mcpwave.com.

8. What we retain

Authorization tokens
Kept while your connection is active, so the service can act on your instruction. Deleted when you disconnect or revoke access.
Connection settings
Which mailboxes you linked and which recipients you approved for sending. Deleted when you disconnect that mailbox.
Email content
Not stored. Fetched to answer a request and passed to your assistant, not persisted by us.
Operational logs
Short-lived diagnostic logs that record that a request occurred and whether it succeeded. They do not contain message bodies or authorization tokens.

9. Deleting your data / revoking access

You can end our access at any time, in any of these ways:

Revoking access immediately invalidates our stored authorization. We delete the associated tokens and connection settings. Deletion requests sent by email are actioned within 30 days.

10. Children

The service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

11. Changes

We may update this policy. Material changes will be reflected in the "Last updated" date above, and where appropriate we will notify connected users. Continued use after a change means you accept the updated policy.

12. Contact

support@mcpwave.com