Privacy Policy

How Cowork Hub Gmail MCP collects, uses, and protects your information.

Effective 26 May 2026

1. Who we are

Cowork Hub Gmail MCP ("the Service") is operated by Future Workshops Limited, a company registered in England & Wales (the "data controller", "we", "us"). Our registered address is on file with Companies House under company number 05642908.

Questions, data-rights requests, or complaints about this policy: privacy@futureworkshops.com.

2. What this policy covers

The Service is a Model Context Protocol (MCP) server that lets a user connect their Gmail account to an MCP client of their choice (for example, Claude). When the user invokes a Gmail-related tool in their MCP client, the Service relays the request to Google's Gmail API and returns the result to the client.

This policy describes what we do with the personal data the Service processes on your behalf. It does not describe what happens to your Gmail data once it leaves the Service and reaches your chosen MCP client — that is governed by the privacy policy of the MCP client provider. See Section 5 ("Sub-processors and onward transfers") for our role and theirs.

3. What we collect

Category Examples Lawful basis (UK GDPR Art. 6)
Account identity Your Cowork Hub user id, email address, name, and the names of the Cowork Hub accounts you belong to. Contract (Art. 6(1)(b))
Gmail connection metadata The Google email you connected and an encrypted OAuth access token and refresh token issued by Google. Tokens are stored encrypted at rest using Active Record Encryption. Contract (Art. 6(1)(b))
Gmail content (transient) Thread bodies, headers, labels, drafts — fetched from Google's Gmail API on demand and relayed to your MCP client. We do not store Gmail content in our database. Contract (Art. 6(1)(b))
Server logs Request method, path, status code, response time, IP address, and user agent. Logs are kept on rolling Heroku log drains for a maximum of 7 days. Logs do not contain Gmail content. Legitimate interest in security and abuse prevention (Art. 6(1)(f))
Essential session cookie A single encrypted Rails session cookie used to keep you signed in. No analytics, advertising, or tracking cookies. Strictly necessary (PECR exemption)

4. How we use Gmail data — Google API Services User Data Policy ("Limited Use")

The Service's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Use for user-facing features only. We use Gmail data exclusively to power the Gmail tools the user invokes through their connected MCP client (for example, listing threads, reading a message, applying labels, creating drafts).
  • No advertising. We do not use Gmail data for advertising purposes, ad personalisation, or any form of profiling for marketing.
  • No human review. No Future Workshops employee or contractor reads your Gmail content, except (a) with your explicit consent during user-requested support, (b) when required to investigate a specific security incident or comply with applicable law, or (c) in aggregated, anonymised form that cannot identify individual users.
  • No model training. We do not use Gmail data to develop, train, or improve general-purpose AI models or to build features that are not user-facing in the Service.
  • No transfer except as needed to provide the user-facing feature. We transfer Gmail data only to the MCP client you have explicitly connected (so that the connector can do its job) and to Google (so that we can call the Gmail API on your behalf). See Section 5.

5. Sub-processors and onward transfers

The Service relies on the following sub-processors to operate:

Sub-processor Purpose Location
Cowork Hub (Future Workshops Limited) Identity provider (SSO). Receives your sign-in. UK / EU
Google LLC Gmail OAuth + Gmail API. Source of your Gmail data. USA / global
Salesforce (Heroku) Application hosting, database, log aggregation. EU (eu region)

MCP clients (e.g. Anthropic's Claude). When you connect an MCP client to the Service, that client receives Gmail data in response to the tool calls it makes — that is the point of the Service. The MCP client is not a sub-processor of ours; you have an independent relationship with the client provider, and what the provider does with the data is governed by their own privacy policy and terms. We recommend reading the relevant client provider's policy before connecting.

International transfers. Where data is transferred outside the UK, we rely on the UK International Data Transfer Addendum and EU Standard Contractual Clauses with Google and Salesforce, plus the UK and EU adequacy decisions where applicable.

6. Retention

  • Account identity: retained for as long as you have an active Cowork Hub account.
  • Gmail OAuth tokens: retained until you disconnect the Gmail account in the Service, revoke access at myaccount.google.com/permissions, or your Cowork Hub account is closed.
  • Gmail content: not retained. Fetched on demand, returned to your MCP client, then discarded from server memory.
  • Server logs: 7 days, rolling.
  • Backups: automated database backups are retained for up to 30 days.

You can disconnect a Gmail account at any time from the Connections page; that revokes our access and deletes the stored OAuth tokens immediately.

7. Your rights

Under UK GDPR you have the right to: access the personal data we hold about you; have it corrected if it's inaccurate; have it deleted; restrict or object to its processing; receive a portable copy; and withdraw any consent you've given.

To exercise any of these rights, email privacy@futureworkshops.com. We respond within one month.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we have handled your data unlawfully.

8. Security

All traffic to the Service is encrypted in transit (TLS 1.2+). OAuth access tokens and refresh tokens are encrypted at rest in our database. Production access is restricted to a small number of named Future Workshops engineers under multi-factor authentication and audit logging. We follow the OWASP ASVS guidelines as a baseline and run automated vulnerability scans on every deployment.

No system is perfectly secure. If you believe you have found a security issue, please report it privately to privacy@futureworkshops.com.

9. Children

The Service is not directed at children under 16 and we do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please email privacy@futureworkshops.com and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app and the "Effective" date at the top will be updated. Your continued use of the Service after a change means you accept the revised policy.