Workspace tools privacy notice
Updated 17 September 2026. This notice covers Lanterne Workspace MCP and its use by Alex Barnes's private Anvil, Hearth and Workspace assistants. Contact alex@lanterne.ai about access, privacy or removal of stored data.
Data accessed and its purpose
The tools use Google OAuth to identify the connected account and obtain the permissions the account owner approves. They store authorisation credentials to maintain that connection. They do not collect the user's Google password.
- Mail features use message headers and bodies, recipients, attachments, labels, threads, drafts, sending identities, signatures and filter settings. This supports reading, search, composition, sending, filing, rules and scheduled actions.
- Enabled Workspace tools can access calendars and events, contacts, tasks, Drive files, documents, spreadsheets, presentations, Forms and responses, Chat messages and spaces, and Apps Script projects and execution information. This supports the user's requests and explicitly configured workflows.
- Connection status, action identifiers, timestamps and error information help operate the tools, recover drafts and investigate failed actions.
A grant defines what Google permits. Application account lists and assistant tool permissions further restrict which connections each app or assistant can use.
Storage and retention
The private host stores credentials, cached mail, drafts, uploaded files, signatures, scheduled jobs and action receipts. Anvil and Hearth use separate application stores. Access to the mail apps is restricted to the operator's private network and permitted accounts.
Saved data does not disappear merely because a browser tab closes or Google access is revoked. Credentials and saved application data remain until the operator removes them. Recent-mail caches rotate as the tools are used. Assistant conversations and exported results can also contain retrieved data and remain in the relevant assistant or destination service.
Removal requests should identify the account and the copies to remove. The operator will check pending scheduled actions before removing application data. Removing a local copy does not delete the source message or file from Google. Backups and external services can retain separate copies under their own retention settings.
Sharing and assistant processing
Google receives API requests needed to provide the connected features. Sending an email or sharing a file delivers content to the recipients or destination selected by the user.
When a user asks an enabled assistant to read or work with Google data, relevant tool results are sent to that assistant's configured AI provider to perform the request. The assistant account's service terms and data settings govern that processing. Mail reading and composition in the standalone mail component do not themselves call an AI provider.
The operator does not sell Google user data or use it for advertising, data brokerage, credit decisions or training general-purpose AI models. Access is limited to providing the connected features, authorised support and security work, or legal requirements. Google API data use follows the Google API Services User Data Policy , including its Limited Use requirements.
Revoking access and changing permissions
You can remove the connection in your Google Account connections . This stops future authorised API access once the credentials are revoked. Contact the operator separately to remove saved copies or stop scheduled work. A change to the purposes for which Google data is used requires an updated disclosure and consent.
This public website
These public information pages use Firebase Hosting. The hosting service can process request details, including network addresses and browser information, to deliver and secure the website. These pages do not use analytics scripts or advertising cookies. No mailbox contents or OAuth credentials are embedded in these pages.