Mailroom by Jacob Kieser
Privacy
Mailroom runs locally and does not store Gmail data on a hosted Mailroom server.
Last updated August 1, 2026
Google Limited Use
Mailroom's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Data storage
Mailroom has no hosted backend or email database. It does not use ads, analytics, or telemetry, and it does not sell Gmail data.
What it can access
Mailroom can search and read messages, manage labels, create and update drafts, send and forward email, archive, and move messages to Trash. It reads each account address to route results to the correct inbox.
Agent access
When you ask Codex, Claude, or another MCP client to work with an email, the email needed for that request goes to the selected client. Its privacy terms and settings apply. Use Mailroom only with a client, account, and workspace configuration that does not use submitted content to train generalized AI or ML models. For a personal OpenAI account, turn off “Improve the model for everyone.” For a personal Anthropic account, do not opt in to model improvement. Mailroom itself does not use Gmail data for ads, profiling, sale, or AI model training.
Data sharing, transfer, and disclosure
Mailroom does not share, transfer, or disclose Google user data to Jacob Kieser, advertisers, data brokers, analytics providers, information resellers, lenders, or other unrelated third parties.
At your direction, Mailroom transfers only the data needed for a requested user-facing feature: between your Mac and Google; to the MCP or AI client you selected, such as OpenAI Codex or Anthropic Claude Code, so it can perform your request; and to email recipients you explicitly select when you ask Mailroom to send or forward a message. Those providers and recipients receive only the data needed for that action and process it under their own privacy terms. Mailroom never transfers Google user data for advertising, sale, profiling, credit or lending decisions, or training generalized AI or ML models. You are responsible for confirming that your selected client's current data controls preserve that restriction.
Local storage
You create a personal Google OAuth app in your own Google Cloud project. Mailroom moves its downloaded Desktop OAuth file into macOS Keychain and deletes the downloaded copy. Your OAuth tokens also stay in Keychain. Account names and non-secret config stay in a local file readable only by your macOS user. Requested email can still exist in your local agent session while a task runs.
Data protection
Gmail data is sent directly between your Mac and Google over HTTPS. Mailroom processes requested messages and attachments locally and does not write them to a hosted database, analytics service, or application log. OAuth tokens are encrypted at rest by macOS Keychain and protected by its operating-system access controls. Mailroom never returns tokens to the MCP client.
Remote images and tracking resources in email are not loaded. Attachments are size-capped, type-checked, hashed, and never executed. Errors are redacted, and every message, thread, draft, and label identifier is tied to its source account to prevent cross-account access. Gmail changes require an explicit user request and deletion means recoverable Gmail Trash, never permanent deletion.
Retention
Mailroom keeps no independent copy of Gmail content after a request finishes. Content returned to Codex, Claude, or another MCP client may remain in that client's local or hosted task history according to the provider settings you choose. Messages, drafts, labels, and Trash items created in Gmail remain there until you change or remove them in Gmail.
Delete your data
Run ./setup --uninstall to remove the plugin and choose
whether to revoke its tokens, or disconnect one account with
./mailroom auth remove <alias>. You can also revoke
Mailroom from your Google Account security settings. To remove
Gmail content retained in an AI client's task or chat history,
delete the corresponding task or chat using that client's controls.