Scope
This policy applies only to Mail CLI and GA4 MCP Server. Both are private, locally operated tools for authorized account owners. It does not govern the separate products and websites in the C&E Venture Partners portfolio.
Google user data accessed
Mail CLI
At the user's direction, Mail CLI may access Gmail account identifiers, messages and their headers, labels, attachments, threads, and drafts. It may apply permitted mailbox changes such as labeling, archiving, marking read or unread, moving messages to or from Trash, and creating or updating drafts. It does not expose an email-send action.
GA4 MCP Server
At the user's direction, GA4 MCP Server may access Google Analytics property identifiers and aggregate reporting data, including traffic, page, source, engagement, event, and date-range metrics. It requests read-only access and does not alter Analytics properties.
How data is used
Google user data is used only to authenticate the authorized user, carry out the specific mailbox or analytics operation the user requests, display the requested result, maintain security, and troubleshoot the tool.
C&E Venture Partners does not sell Google user data, use it for advertising, build marketing profiles from it, determine creditworthiness, or use it to train generalized AI models.
Storage and retention
- The tools run on the authorized user's device; C&E Venture Partners does not operate a hosted database that receives mailbox contents or Analytics reports.
- OAuth client information and access or refresh tokens are stored locally with restrictive file permissions. Mail CLI separates credentials by account; GA4 MCP Server stores its token in its local project directory.
- Mail CLI writes only the mailbox changes the user requests back to Gmail. GA4 MCP Server does not persist report responses in its own database.
- Command output may remain in the user's terminal, local files, or AI-client history if the user or their chosen client retains it.
- Local OAuth tokens remain until the user deletes them or revokes access through their Google Account.
Sharing and transfer
The tools communicate with Google APIs to provide their features. When a user invokes a tool through an AI assistant or other MCP client, the requested result is passed to that client on the user's behalf; the selected client's own privacy and retention terms apply. C&E Venture Partners does not otherwise disclose Google user data except when required by law.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Security
We use least-privilege OAuth scopes, local credential isolation, restrictive file permissions, and application-level command allowlists. No method of storage or transmission is completely secure, but these controls are designed to reduce unauthorized access and accidental use.
Your choices
You may stop using either tool, delete its local token, and revoke its access from your Google Account connections. You can manage Gmail content and Analytics access directly in the relevant Google product.
Changes
We may update this policy when the tools, scopes, or data practices change. The updated date above will identify the latest version.
Contact
C&E Venture Partners, LLC
Franklin, Massachusetts, United States
hello@ceventurepartners.com