Privacy policy

Matthew Workspace MCP. Last updated 13 September 2026.

Scope

This policy covers Matthew Workspace MCP, a private Model Context Protocol server operated by Matthew Cowan on his own computer. The application has exactly one user, Matthew Cowan, and the only Google account it accesses is his own.

What the application accesses

With Matthew Cowan's authorisation, the application can read and write the following data in his own Google account:

How that data is used

Data is retrieved on demand to carry out a task Matthew Cowan has asked for, and returned to the AI assistant session that asked for it. Data is not used for training, profiling, advertising, analytics or any secondary purpose.

Where data goes

The application runs locally and talks directly to Google's APIs. It sends no data to any server operated by the developer, because there is no such server. There is no database, no logging service, no analytics and no telemetry.

Content retrieved from Google is passed to the AI assistant used to perform the requested task, and is therefore handled under that assistant provider's own terms and privacy policy. No other third party receives data from this application.

What is stored, and where

The only data the application stores persistently is the OAuth credential set for the authorised account: access token, refresh token, token endpoint, client identifiers and granted scopes. These are written to a file on the local computer, readable only by the operating-system user account that runs the server.

Mail, calendar, document and file content is not cached or retained by the application after a request completes.

Retention and deletion

Stored credentials persist until they are deleted or revoked. To remove them, delete the credential file on the local machine. To revoke the application's access entirely, remove it at myaccount.google.com/connections, which invalidates the stored tokens immediately.

Limited Use disclosure

Matthew Workspace MCP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Security

Credentials are stored with restrictive file permissions on a single machine under the developer's physical control. No credentials are committed to source control or shared. The client secret is held in a password manager and in a local file outside any synchronised folder.

Children

The application is not directed at children and has no users other than its developer.

Changes

Any change to this policy will be published on this page with an updated date.

Contact

Matthew Cowan, Brisbane, Australia. Email matteowcowan@gmail.com.