Privacy Policy

Casey MCP — last updated 14 September 2026

Scope

Casey MCP is a personal-use application with a single user: its author, Casey Bruns. It is not offered to other people and has no other users. This policy describes how the application accesses, uses, stores and shares Google user data, as required by the Google API Services User Data Policy.

What data the application accesses

When the author signs in with his Google Account and grants consent, the application can access, on that account only:

It accesses this data only when the author issues an instruction that requires it. The application performs no background synchronisation, no scheduled scanning, and no bulk export.

How the data is used

Data is retrieved solely to carry out the specific operation the author has asked for — for example retrieving a document he has asked to read, or adding an event he has asked to create. It is not used for advertising, profiling, analytics, model training by the application, or any purpose unrelated to the request at hand.

Where the data goes

The application runs entirely as local processes on the author's own computer. It operates no server, no database and no hosted infrastructure, and it transmits no data to the author or to any party other than as described here.

The author should be clear about one consequence of how the application is used: because its purpose is to make his Google data available to an AI assistant running on his computer, content retrieved from Google in response to his instructions is passed to that assistant, and therefore to the provider of the AI model the assistant uses, under that provider's own terms and privacy policy. This is the intended function of the application rather than an incidental disclosure. No data is shared with anyone else.

What is stored, and where

The only data the application retains is authentication material: the OAuth refresh and access tokens issued by Google. These are written to files in the author's own home directory on his own computer, readable only by his user account. No Google user content — no file contents, no message bodies, no calendar entries — is written to durable storage by the application; such content exists only in memory for the duration of the request that fetched it.

Retention and deletion

Stored tokens persist until they are deleted or revoked. The author may revoke the application's access at any time from the Google Account permissions page at myaccount.google.com/permissions, and may delete the stored tokens by removing the credential files from his computer. Revoking access immediately ends the application's ability to reach any Google data.

Limited Use disclosure

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes

If this policy changes, the revised version will be published at this address with an updated date above.

Contact

Questions about this policy may be sent to cbruns65@gmail.com.