Google data stays inside an owner-directed tool flow.

Hawkx Workspace MCP is an owner-operated, self-hosted integration. It connects authorized MCP clients to Gmail, Google Calendar, Google Drive, Google Sheets, and Google Docs. The application is not offered as a multi-tenant service.

Google data we access

The application requests separate grants for five services. Depending on the tool the owner invokes, it may access:

  • Gmail: messages, threads, labels, drafts, attachments, and the ability to compose or send mail.
  • Calendar: calendar lists, events, recurring event information, and free or busy availability.
  • Drive: file and folder metadata, file content, exports, and files created or opened through the application.
  • Sheets: spreadsheet metadata, ranges, formulas, values, and sheet structure.
  • Docs: document metadata, tabs, structured content, revisions, and user-requested edits.

Each service uses its own Google OAuth grant. Credentials are not shared between services.

How Google data is used

Google user data is used only to perform the operation the owner requests through an authorized MCP client, return the result of that operation, maintain the requested Google resource, and protect the service from unauthorized access or replay.

The application does not use Google user data for advertising, credit decisions, surveillance, user profiling, or training a general-purpose model. It does not sell Google user data.

Storage and retention

OAuth credentials are stored in owner-controlled infrastructure with owner-only file permissions. Access tokens are refreshed from separate refresh tokens for each service. Google credentials are never returned to MCP clients.

Google content is not copied into a general application database. A file, attachment, export, spreadsheet, or document may be written to an owner-controlled managed path only when the owner explicitly invokes a download, export, create, or update operation. Operational audit records contain request metadata and outcomes rather than raw credentials or full Google content.

Credentials are retained until the owner revokes the grant, deletes the credential file, or decommissions the service. Managed files and audit records remain until the owner deletes them under the retention rules of the owner-controlled environment.

Sharing and disclosure

The application does not sell, rent, or disclose Google user data for advertising. Data is exchanged with Google APIs to perform requested operations and is returned to the specific MCP client that initiated the request.

The selected MCP client or AI provider may process the returned result under its own terms and privacy policy. The owner chooses and authorizes that client. Google OAuth credentials, authorization codes, and refresh tokens are not disclosed to the MCP client or AI provider.

Data may be disclosed when required by law or when necessary to investigate abuse or protect the security of the owner-controlled service. No other human access is permitted without the owner's explicit direction.

Your controls and deletion

The owner can stop using any service independently, revoke the application's access in Google Account security settings, revoke downstream MCP clients, delete a service credential file, and delete managed downloads or audit records.

Revoking Google access prevents future API access but does not automatically remove files that the owner previously downloaded or created. Those files can be deleted from the owner-controlled environment. Deletion or access questions can be sent to hawkxdev@gmail.com.

Security

The application separates the five services by process, OAuth state, Google credential, scope set, audit target, and MCP resource. Credential files use restrictive permissions, refresh operations are locked, writes are not retried after an uncertain outcome, and raw provider responses are not exposed as a public mapping surface.

No method of storage or transmission is perfectly secure. Security incidents affecting Google user data will be investigated and handled according to applicable law and the owner-controlled incident process.

Google API Limited Use

Hawkx Workspace MCP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes to this policy

This policy may be updated when the application's data practices or legal requirements change. The effective date at the top of the page identifies the current version. Material changes will be published before they take effect.

Contact

Hawkx Workspace MCP is operated by Sergey Sokolkin. Privacy and deletion requests: hawkxdev@gmail.com.