Poke MCP

Overview

Poke MCP is a private, owner-operated integration hub. It connects the owner’s services to authenticated AI clients through the Model Context Protocol (MCP). It does not offer public account registration.

Google data accessed

When authorized by the owner, Poke MCP may access:

  • Google Drive: file and folder metadata, file contents and exports, and the ability to create folders, create or upload files, and delete a source file only in an explicitly requested workflow.
  • Gmail: read-only message search, message metadata and body content, and attachments. Poke MCP cannot send, modify, or delete Gmail messages.

How Google data is used

Google data is used only to complete a specific operation requested through an authenticated MCP client, such as finding a file, reading an email, exporting a document, uploading a backup, or processing an attachment. Results are returned to the authorized client that initiated the request.

Poke MCP does not use Google user data for advertising, profiling, credit decisions, or training generalized AI models.

Storage and retention

The Google OAuth refresh credential is stored as a protected server-side environment secret. Short-lived access tokens may be cached in application memory until they expire. Poke MCP does not maintain a separate database of Google Drive files or Gmail messages. Files intentionally created or uploaded by a requested operation remain in the owner’s Google Drive under the owner’s control.

Operational logs may contain a tool name, request identifier, timing, and success or failure status. The hub is designed not to log OAuth credentials or Google file, email, or attachment contents.

Sharing and disclosure

Google data is not sold. It is not shared with advertisers or data brokers. Data is transmitted only to Google APIs, the Poke MCP server, and the authenticated MCP client selected by the owner to fulfill the requested operation. Infrastructure providers may process encrypted traffic and operational data solely to host and secure the service.

Owner controls

The owner can disable individual tools in the hub, revoke Poke MCP from the Google Account permissions page, or request deletion of the stored authorization credential using the developer contact shown on the OAuth consent screen. Revocation prevents future Google API access.

Security

Poke MCP uses authenticated MCP access, HTTPS, server-side secret storage, scoped Google authorization, and short-lived access tokens. No internet service can guarantee absolute security, but access is deliberately limited to the private use case described here.

Google API Services User Data Policy

Poke MCP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes and contact

This policy may be updated when the service or its Google access changes. The current version and update date will remain available at this URL. Privacy questions can be sent to the developer contact listed on the Google OAuth consent screen.