Privacy Policy
Workspace Conduit AI · Last updated March 25, 2026
What this service does
Workspace Conduit AI is an MCP (Model Context Protocol) server that lets AI assistants like Claude read and write your Google Docs, Sheets, and Slides on your behalf. It acts as a bridge between your MCP client and Google's APIs.
Data we access
When you authorize Workspace Conduit AI, we request access to:
- Google Docs — read and write your documents
- Google Sheets — read and write your spreadsheets
- Google Slides — read and write your presentations
- Google Drive (read-only) — search files and retrieve metadata
- Email address — to identify your account
We only access your Google data when your MCP client makes a specific tool call. We do not scan, index, or analyze your files in the background.
Data we store
- OAuth tokens — your Google access and refresh tokens are encrypted with AES-256-GCM and stored in a secure Redis database. These are used to authenticate API calls on your behalf.
- Session tokens — a random session identifier that maps your MCP client to your Google account. Expires after 30 days.
- Email address — used as your account identifier.
Data we do NOT store
- We do not store the content of your documents, spreadsheets, or presentations.
- We do not store your Google password.
- We do not log API request or response bodies.
- We do not share any data with third parties.
- We do not use your data for training AI models.
Data security
- OAuth tokens are encrypted at rest using AES-256-GCM.
- All connections use HTTPS/TLS.
- Session tokens are cryptographically random (256-bit).
- Per-user rate limiting prevents abuse.
- CSRF protection on the OAuth flow.
Data retention
Session tokens and OAuth tokens expire after 30 days. After expiration, they are automatically deleted from our database. You can revoke access at any time through your Google Account permissions.
Your rights
- Revoke access — remove Workspace Conduit AI from your Google Account at any time via Google Account permissions.
- Data deletion — revoking access automatically invalidates stored tokens. Contact us to request immediate deletion.
Third-party services
Workspace Conduit AI uses the following third-party services to operate:
- Google APIs — to access your Docs, Sheets, Slides, and Drive
- Vercel — hosting and serverless compute
- Upstash Redis — encrypted token storage
Contact
For privacy questions or data deletion requests, contact us.