RevSheet

Privacy Policy

Last updated: 10 June 2026

This Privacy Policy describes how RevSheet (“we”, “us”) handles information in connection with the Multi-Gmail MCP Server (the “Service”), a remote Model Context Protocol server that lets an AI assistant (such as Claude) read your Gmail and prepare draft replies on your behalf, across one or more of your own Google accounts.

What we access

When you connect a Google account, you grant the Service access to your Gmail via the https://www.googleapis.com/auth/gmail.modify scope and your basic profile (email address) via OpenID Connect. This allows the Service to:

The Service can never send email. The gmail.send scope is never requested and no send endpoint is ever called — every draft is reviewed and sent by you, manually, from within Gmail.

How we use Google user data

Gmail content and profile data are accessed only to provide the features you invoke through your AI assistant (reading, searching, triaging, and drafting). Message content is retrieved on demand to fulfil a request and returned to your assistant; we do not use it for any other purpose.

Limited Use disclosure

The Service’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

Data storage and retention

We minimise stored data. We do not retain the bodies, subjects, or attachments of your email messages — these are fetched transiently to answer a request and are not persisted by the Service. To keep additional accounts connected, we store an encrypted Google OAuth refresh token (encrypted at rest) keyed to your account identifier; this is deleted when you unlink an account or revoke access. Operational logs are scrubbed of OAuth credentials and message content.

Sharing

We do not sell your data and do not share Google user data with third parties, except with infrastructure providers strictly necessary to operate the Service (e.g. hosting), and as required by law. Your data is, by design, returned to the AI assistant you chose to connect; that assistant’s provider processes it under its own terms.

Revoking access

You may disconnect at any time using the unlink_account tool, or by removing the Service from your Google Account permissions. Revoking access invalidates the stored token and ends our ability to access your mailbox.

Contact

Questions or data requests: privacy@revsheet.com.au.


RevSheet — privacy@revsheet.com.au · Home · Privacy · Terms