Privacy Policy
Summary. Google Tasks MCP runs on your own computer. It accesses only your Google Tasks, and only after you authorize it. It stores your Google authorization token in a file on your computer. It does not send your tasks or your token to peqdo.com or to any server run by the developer. It has no analytics, no advertising, and it does not sell or share your data. Task content you ask Claude about is shown to Claude in your Claude Desktop conversation (see section 6).
1. Who we are
This Privacy Policy applies to Google Tasks MCP (the "app"). The app is a local Model Context Protocol (MCP) server that lets you manage your Google Tasks from Claude Desktop. It is built on the open-source google-tasks-mcp project (MIT License) and uses a Google OAuth client registered under the name "Google Tasks MCP".
Developer contact: goushanchao@gmail.com. In this policy, "we" and "the developer" mean the person who maintains this app and this website.
Google Tasks MCP is not made, endorsed or reviewed by Google or by Anthropic.
2. Data the app accesses
The developer does not collect any personal data through the app. The app has no user accounts, sends no telemetry and no crash reports, and contains no analytics or advertising code. On your computer, the app handles the following data:
| Data | Why | Where it is kept |
|---|---|---|
| Your Google Tasks data: task list names and IDs, and task titles, notes, due dates, completion status, links, parent/subtask relationships and position | To carry out the request you made in Claude Desktop | Held only in the app's memory while it handles your request. The app does not save it to disk. |
| Google OAuth tokens: a refresh token, an access token, its expiry time, the granted scope, the token type, and the time it was obtained | To call the Google Tasks API on your behalf without asking you to sign in every time | A file on your computer (see section 5) |
The OAuth client configuration file (gcp-oauth.keys.json), which identifies the app to Google. It contains no data about you. |
Required by Google's authorization flow | A file on your computer |
The app does not receive or store your Google password. It does not request your name, email address, profile, contacts, or access to any Google service other than Google Tasks.
3. How Google Tasks data is accessed, processed and used
- The app requests a single Google permission (OAuth scope):
https://www.googleapis.com/auth/tasks, which allows it to view and manage your Google Tasks. If you run it in read-only mode, it requests onlyhttps://www.googleapis.com/auth/tasks.readonly. - The app accesses your Google Tasks only when Claude Desktop calls one of its tools as part of a request you made, for example listing tasks, searching your tasks, creating a task or marking one complete.
- Requests go directly from your computer to Google's API at
https://tasks.googleapis.comover HTTPS. Your task data never passes through any server run by the developer. - Your Google Tasks data is used only to provide the features you ask for: showing, searching, creating, changing, moving, completing and deleting your tasks and task lists.
- Your data is not used for advertising, profiling, analytics or any other purpose. The developer does not use it to develop, improve or train any AI or machine-learning model.
- Changes, such as creating, editing, moving or deleting a task, are made only when you ask for them through Claude Desktop. Deleting a task or a list in Google Tasks is permanent.
4. Google authorization (OAuth) and token handling
- You authorize the app on Google's own consent page, which opens in your web browser. You can see the requested permission there before you agree.
- The app uses Google's recommended flow for installed apps. The sign-in result is returned only to a temporary listener on your own computer (
http://127.0.0.1), protected with PKCE and a randomstatevalue. This listener closes after authorization or after 5 minutes. - After authorization, the app saves the tokens to a file on your computer, and Google may refresh the access token periodically. The app is designed never to print or log tokens.
- Tokens are sent only to Google: to the Google Tasks API with each request, and to Google's OAuth service when the access token is refreshed. They are never sent to the developer.
5. Where data is stored: local computer, not a remote server
Everything the app stores is stored locally on your computer:
- Windows:
%APPDATA%\google-tasks-mcp\tokens.json - macOS and Linux:
~/.config/google-tasks-mcp/tokens.json(or under$XDG_CONFIG_HOMEif set) - The location can be changed with the
GTASKS_TOKEN_PATHenvironment variable.
The token file is plain JSON. It is not encrypted by the app. It is protected by your operating system's user-account file permissions: on macOS and Linux the app sets the file so only your user account can read it, and on Windows it sits in your personal user profile folder. Anyone who can sign in as your user account on that computer could read it.
The developer does not operate a backend for this app. Your tasks and tokens are not stored on peqdo.com or on any other server run by the developer. Your tasks remain stored by Google in your Google account, as always.
The app writes short status and error messages to its standard error output. Claude Desktop may save these in its own log files on your computer. The app does not include tokens in these messages.
6. Sharing with third parties
The developer does not sell, rent, trade or share your data with anyone. Because of how the app works, data does flow to the following parties:
- Google: the app sends your requests and tokens to Google's APIs in order to read or change your Google Tasks. Google's handling of your data is governed by the Google Privacy Policy.
- Claude Desktop and Anthropic: the app returns the results of each request (for example, the titles, notes and due dates of the tasks you asked about) to Claude Desktop, so that Claude can answer you. This is the user-facing feature you are asking for. Claude Desktop sends conversation content, including these results, to Anthropic to generate Claude's replies. That processing happens in your Claude account, is under your control, and is governed by Anthropic's terms and privacy policy, not by the developer. The developer receives none of this data.
We will not disclose Google user data to anyone else, except where required by law. Since the developer does not hold any of your Google user data, there is nothing for the developer to disclose.
7. Google API Services User Data Policy (Limited Use)
Google Tasks MCP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide and improve the user-facing features described on our home page and in this policy.
- Google user data is transferred to others only as needed to provide these features at your direction (to Claude Desktop, as described in section 6), to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.
- Google user data is not used or transferred for serving advertisements, including retargeting, personalized or interest-based advertising.
- Google user data is not sold, and it is not used to determine creditworthiness or for lending purposes.
- No human reads your Google user data, except with your affirmative agreement for specific messages, when needed for security purposes, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations. Since the developer never receives your data, the developer does not read it.
- Google user data is not used to develop, improve or train generalized AI or machine-learning models.
8. Data retention and deletion
- Task data: the app keeps task data only in memory while it handles a request, and it is gone when the app process stops. Your tasks themselves stay in your Google account until you delete them in Google Tasks.
- Tokens: the token file is kept on your computer until you delete it. To remove it, delete the
tokens.jsonfile at the location in section 5, or delete the wholegoogle-tasks-mcpfolder. Deleting the file does not by itself revoke Google's authorization, so also follow section 9. - Claude conversations: task content that appeared in a Claude Desktop conversation is kept according to your Claude settings. You can delete those conversations in Claude.
- Data held by the developer: none. If you email us, we keep the correspondence only as long as needed to answer you, and we will delete it on request.
9. How to revoke Google access
You can withdraw the app's access to your Google account at any time:
- Go to your Google Account's Third-party apps & services page (
https://myaccount.google.com/connections). - Select Google Tasks MCP.
- Choose Delete all connections (or "Remove access").
After you revoke access, the stored token stops working immediately, and the app can no longer read or change your tasks. You can then delete the local token file (section 8) and remove the app from your Claude Desktop configuration.
10. Security
- All communication with Google uses HTTPS (TLS).
- Authorization uses Google's OAuth 2.0 flow for installed apps, with PKCE, a random
statecheck, and a callback that listens only on your own computer (127.0.0.1). - The app requests only the Google Tasks permission it needs. You can choose the read-only permission instead.
- The app does not run a public server, and it does not send your data to the developer. As a result, there is no central store of user data that could be breached.
- Tokens are stored in your user profile with operating-system file permissions, and the app does not include them in its output or logs. Keep your computer and user account secure, because anyone with access to your user account could read the token file.
- The app's source code is public, so anyone can inspect how it handles data.
No method of storage or transmission is completely secure. If you believe your token has been exposed, revoke access as described in section 9 and authorize again.
11. This website (peqdo.com)
This website is a static information page. It uses no cookies, no analytics, no advertising and no third-party scripts, fonts or trackers. Like most web servers, the server that hosts it automatically records basic request logs (IP address, date and time, requested page, browser user-agent). These logs are used only to operate and secure the site. They are not combined with app data, and they are deleted automatically on a rolling basis within 30 days.
12. Children
The app is not directed to children and is intended for people who are old enough to have their own Google account and Claude account under the applicable terms.
13. Changes to this policy
If the way the app handles data changes, we will update this page and its "Last updated" date before the change takes effect. If a change would use your data in a way you have not agreed to, we will ask for your consent first.
14. Contact
For privacy questions, requests or concerns, email goushanchao@gmail.com. We aim to reply within 30 days.
隐私政策(中文版)
摘要:Google Tasks MCP 在你自己的电脑上运行,仅在你授权后访问你的 Google Tasks,并把 Google 授权令牌保存在你电脑上的文件里。它不会把你的任务或令牌发送到 peqdo.com 或开发者的任何服务器。没有数据分析,没有广告,也不出售或共享你的数据。你在 Claude 中询问的任务内容会出现在 Claude Desktop 的对话中(见第 6 条)。
1. 我们是谁
本政策适用于 Google Tasks MCP(以下简称“本应用”)。本应用是一个本地运行的 MCP(Model Context Protocol)服务,让你可以在 Claude Desktop 中管理自己的 Google Tasks。它基于开源项目 google-tasks-mcp(MIT 许可证),并使用一个以“Google Tasks MCP”名称注册的 Google OAuth 客户端。开发者联系邮箱:goushanchao@gmail.com。本应用并非由 Google 或 Anthropic 开发,也未获得其认可或审核。
2. 本应用处理哪些数据
开发者不通过本应用收集任何个人数据。本应用没有用户账号,不发送遥测或崩溃报告,也不包含任何数据分析或广告代码。在你的电脑上,本应用会处理以下数据:
- Google Tasks 数据:清单名称和 ID,以及任务的标题、备注、截止日期、完成状态、链接、父子任务关系和排序位置。这些数据仅在处理请求时保存在内存中,不会写入磁盘。
- Google OAuth 令牌:刷新令牌、访问令牌、过期时间、已授权范围、令牌类型和获取时间,保存在你电脑上的文件中(见第 5 条)。
- OAuth 客户端配置文件(
gcp-oauth.keys.json):用于向 Google 标识本应用,不包含你的个人数据。
本应用不会接收或保存你的 Google 密码,也不会请求你的姓名、邮箱、个人资料、联系人,或 Google Tasks 以外任何 Google 服务的访问权限。
3. Google Tasks 数据如何访问、处理和使用
- 本应用只申请一个 Google 权限:
https://www.googleapis.com/auth/tasks(查看和管理你的 Google Tasks)。在只读模式下,只申请https://www.googleapis.com/auth/tasks.readonly。 - 只有当 Claude Desktop 为完成你提出的请求而调用本应用的功能时,本应用才会访问你的 Google Tasks。
- 请求通过 HTTPS 从你的电脑直接发送到 Google API(
https://tasks.googleapis.com),不经过开发者的任何服务器。 - 数据仅用于实现你要求的功能:查看、搜索、创建、修改、移动、完成和删除任务及清单。不用于广告、用户画像、数据分析或任何其他用途,开发者也不会用它来开发、改进或训练任何 AI 或机器学习模型。
- 创建、修改、移动、删除等操作只会在你通过 Claude Desktop 提出要求时执行。在 Google Tasks 中删除的任务或清单无法恢复。
4. OAuth 授权及令牌处理
- 你在浏览器中打开的 Google 官方授权页面上完成授权,并可以在同意前看到所申请的权限。
- 本应用使用 Google 为桌面应用推荐的授权流程:授权结果只回传到你电脑上的一个临时本地监听地址(
http://127.0.0.1),并使用 PKCE 和随机state校验进行保护。授权完成或超过 5 分钟后,该监听即关闭。 - 令牌只会发送给 Google(随每次请求发送到 Google Tasks API,或在刷新访问令牌时发送到 Google OAuth 服务),绝不会发送给开发者。本应用的设计是从不打印或记录令牌。
5. 数据存储位置:本地电脑,而非远程服务器
- Windows:
%APPDATA%\google-tasks-mcp\tokens.json - macOS / Linux:
~/.config/google-tasks-mcp/tokens.json(如设置了$XDG_CONFIG_HOME,则位于其下) - 可以通过环境变量
GTASKS_TOKEN_PATH修改存储位置。
令牌文件是未经本应用加密的 JSON 文件,依靠操作系统的用户账户文件权限来保护:在 macOS/Linux 上,本应用会把文件权限设为仅当前用户可读;在 Windows 上,文件位于你个人的用户配置目录中。能够以你的用户身份登录这台电脑的人,都可以读取该文件。
开发者没有为本应用运行任何后端服务器。你的任务和令牌不会存储在 peqdo.com 或开发者的任何其他服务器上。你的任务仍然像往常一样由 Google 存储在你的 Google 账号中。本应用会向标准错误输出写入简短的状态和错误信息,Claude Desktop 可能会把这些信息保存在你电脑上的日志文件中,其中不包含令牌。
6. 与第三方共享
开发者不会出售、出租、交易或共享你的数据。由于本应用的工作方式,数据会流向以下两方:
- Google:本应用把请求和令牌发送给 Google API,以读取或修改你的 Google Tasks,适用 Google 隐私政策。
- Claude Desktop 与 Anthropic:本应用把每次请求的结果(例如你询问的任务的标题、备注和截止日期)返回给 Claude Desktop,以便 Claude 回答你,这正是你所请求的功能。Claude Desktop 会把对话内容(包括这些结果)发送给 Anthropic 以生成回复。这一处理发生在你自己的 Claude 账号中,由你控制,适用 Anthropic 的条款和隐私政策,而非由开发者处理。开发者不会收到其中任何数据。
7. Google API 服务用户数据政策(有限使用)
Google Tasks MCP 对从 Google API 获取的信息的使用,以及向其他应用的传输,将遵守 Google API Services User Data Policy,包括其中的有限使用(Limited Use)要求,具体为:
- Google 用户数据仅用于提供和改进本页及首页所述的面向用户的功能。
- 仅在按你的指示提供上述功能(如第 6 条所述传给 Claude Desktop)、遵守适用法律,或在合并、收购、资产出售且事先通知用户的情况下,才会转移数据。
- 不将 Google 用户数据用于或转移用于投放广告,包括再营销、个性化广告或基于兴趣的广告。
- 不出售 Google 用户数据,也不将其用于判断信用或借贷目的。
- 除非获得你对特定内容的明确同意、出于安全需要、为遵守法律,或数据已汇总并匿名化用于内部运营,否则不会有人阅读你的 Google 用户数据。由于开发者从不接收你的数据,开发者也不会阅读这些数据。
- 不使用 Google 用户数据来开发、改进或训练通用 AI 或机器学习模型。
8. 保存期限与删除方式
- 任务数据:仅在处理请求时保存在内存中,程序退出后即消失。你的任务本身会保留在你的 Google 账号中,直到你在 Google Tasks 中删除它们。
- 令牌:保存在你的电脑上,直到你删除为止。删除第 5 条所述的
tokens.json文件,或整个google-tasks-mcp文件夹即可。仅删除文件并不会撤销 Google 授权,请同时按第 9 条操作。 - Claude 对话:出现在 Claude Desktop 对话中的任务内容,按照你的 Claude 设置保存,你可以在 Claude 中删除这些对话。
- 开发者持有的数据:无。如果你给我们发邮件,我们只在答复所需的期限内保留往来邮件,并可应你的要求删除。
9. 如何撤销 Google 授权
- 打开 Google 账号的第三方应用和服务页面(
https://myaccount.google.com/connections)。 - 选择 Google Tasks MCP。
- 点击“删除所有关联”(或“移除访问权限”)。
撤销后,已保存的令牌会立即失效,本应用将无法再读取或修改你的任务。之后你可以删除本地令牌文件,并从 Claude Desktop 的配置中移除本应用。
10. 数据安全
- 与 Google 的所有通信均使用 HTTPS(TLS)。
- 授权使用 Google OAuth 2.0 桌面应用流程,配合 PKCE、随机
state校验,并且回调只监听本机地址(127.0.0.1)。 - 只申请所需的 Google Tasks 权限,你也可以选择只读权限。
- 本应用不运行公网服务,也不向开发者发送数据,因此不存在可能被攻破的集中式用户数据库。
- 令牌保存在你的用户目录中,受操作系统文件权限保护,本应用不会在输出或日志中包含令牌。请保护好你的电脑和用户账户的安全。
- 本应用源代码公开,任何人都可以检查它如何处理数据。
没有任何存储或传输方式是绝对安全的。如果你认为令牌可能已经泄露,请按第 9 条撤销授权,然后重新授权。
11. 本网站(peqdo.com)
本网站是一个静态说明页面,不使用 Cookie,不使用数据分析、广告或任何第三方脚本、字体和跟踪器。与大多数网站一样,托管服务器会自动记录基本访问日志(IP 地址、时间、访问的页面、浏览器 User-Agent)。这些日志仅用于网站的运行和安全,不会与应用数据关联,并会在 30 天内自动滚动删除。
12. 儿童
本应用不面向儿童,仅供根据相关条款已达到可以拥有自己的 Google 账号和 Claude 账号年龄的用户使用。
13. 政策变更
如果本应用处理数据的方式发生变化,我们会在变化生效前更新本页面及其“最后更新”日期。如果变更会以你未曾同意的方式使用你的数据,我们会事先征得你的同意。
14. 联系我们
如有隐私相关的问题、请求或疑虑,请发邮件至 goushanchao@gmail.com,我们会尽量在 30 天内回复。