Last updated 18 September 2026.
google-multi-mcp is a single-user tool. The only person whose Google data it accesses is its owner, for Google accounts the owner has connected by signing in and granting consent themselves.
With the owner's consent, and only when the owner's Claude assistant calls a tool: Gmail messages, threads, labels and drafts; Google Calendar calendars, events and free/busy data; Google Drive file metadata and file contents. It can be run in a read-only mode that exposes no tools which send, share, create, change or delete anything.
Data is fetched from Google on demand and returned to the owner's Claude session, which is operated by Anthropic under the owner's own Anthropic account, to answer the owner's request. It is not used for advertising, profiling, training models or any purpose other than the owner's request.
The server does not store email, calendar or Drive content. It stores only what it needs to reach Google on the owner's behalf: the OAuth refresh token and address for each connected account, and hashes of the access credentials it issues to the owner's Claude clients. These live in files readable only by the server's user on the owner's machine.
Google user data is not sold, and is not transferred to anyone except as described under "How it is used". The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Access can be withdrawn at any time at myaccount.google.com/permissions. Removing an account from the server deletes its stored refresh token.