Privacy policy
For the inboxfewer instance operated by Timo Derstappen · last updated 2026-10-09
Who operates this
This inboxfewer instance is run privately by Timo Derstappen, Germany, for his own Google accounts. It is not a commercial service and has no other users. Questions: teemow@gmail.com.
What inboxfewer does
inboxfewer is a Model Context Protocol server. You sign in with Google and connect an AI assistant to it; the assistant can then call tools that read and change data in your Google account, for example to archive newsletters, find a document linked from a mail or create a calendar event. Nothing happens in your account unless you, through your assistant, ask for it.
Google data it accesses
When you sign in, Google asks you to grant the following access. Each scope is used only to carry out the tool calls you make.
- Gmail: read, label, archive, send and manage mail and filters.
- Google Drive and Docs: read documents linked from mail, manage files.
- Google Calendar: read and manage events.
- Google Meet: read spaces and recordings, manage space settings.
- Google Tasks: read and manage tasks.
- Google Contacts and directory: read contacts to resolve names and addresses.
- Account e-mail address: identify which account a session belongs to.
How the data is handled
- Processing. Mail, documents and events are fetched from Google when a tool runs, handed to the assistant that made the call, and discarded. inboxfewer keeps no copy of your mail or files.
- Tokens. The OAuth access and refresh tokens Google issues are stored encrypted (AES-256-GCM) in a key-value store on the operator's own Kubernetes cluster at home in Germany, so that your session stays signed in. They are deleted when you sign out or revoke access.
- Your assistant. Whatever a tool returns is sent to the AI assistant you connected. That assistant's provider and its own privacy terms govern that data from there on; inboxfewer does not choose or control the assistant.
- Logs and metrics. Operational logs record tool names, timings and errors, and a hashed account identifier for security auditing. They never contain mail bodies, subjects, attachments or file contents.
- No sharing. Google user data is not sold, not shared with third parties, not used for advertising, and not used to train machine-learning models. No human reads it except the account holder through their own assistant.
Limited use
inboxfewer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your control
You can revoke inboxfewer's access at any time in your Google account under Third-party apps & services. Revoking invalidates the stored tokens; signing out of your assistant removes them from the server. To have anything else removed, write to teemow@gmail.com.
Changes
Changes to this policy are published on this page with a new date. The source of this page and of inboxfewer itself is public on GitHub.