c3
Privacy policy
c3 is a personal desktop app that runs on Matthew McGivney's Mac. This policy describes how that app accesses, uses, stores, and shares Google user data from Gmail. It is the same policy linked from the app's Google sign-in screen and from the c3 homepage.
Who operates c3
Matthew McGivney, matt@mattmcgivney.com. c3 has no other operator and no other users.
Google data c3 requests
Connecting a Gmail account requests one permission:
https://www.googleapis.com/auth/gmail.modify
For an account you connect, that permission lets c3:
- Read messages, including headers, bodies, and attachment metadata.
- Send a reply when you write one and sending is turned on for that account.
- Change labels when you act on a thread: remove Inbox (archive), clear or restore Unread, and add or remove Spam.
c3 does not permanently delete Gmail messages. It does not request a scope that can.
Why c3 requests it
c3 uses Gmail data to show one inbox, to search it, and to apply the actions you take back to Gmail. A spam filter that runs on the Mac scores new mail from strangers. If you turn that mode on, c3 can mark likely spam in Gmail. The filter's word counts stay on the Mac. c3 does not send mail to a hosted spam classifier.
c3 does not use Gmail data for advertising, credit, lending, or to train a model that anyone else can use.
Where it is stored
Message data and the Gmail refresh token are stored only on the Mac where c3 is installed, under that user's application support folder. Token files are readable only by that user. c3 does not copy Gmail data to a server of its own.
When Gmail data leaves the Mac
c3 itself does not send Gmail content to anyone other than Google.
- Sync, sending a reply you wrote, and label changes you chose all talk to Google's Gmail API.
- If you connect an AI agent to c3's local read-only interface and ask it to read your mail, that agent receives the messages you asked about. An agent backed by a cloud model then sends that content to its model provider. This happens only when you ask. c3 does not send mail to a model on its own.
There is no sale of Gmail data, no transfer to advertisers or data brokers, and no one other than you reviews your mail through c3, except an agent you explicitly asked to read it.
How long it is kept
The first sync copies roughly the last 7 days of mail. After that, c3 keeps new and updated mail in the local database. A local copy is removed when Gmail reports that message deleted, or when you delete c3's data folder on the Mac.
You can revoke c3 at any time from your Google Account permissions. Revoking access stops further sync. Mail already stored on the Mac stays until you delete c3's data folder.
Limited Use
c3's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
If c3 starts using Gmail data for a new purpose, this policy will be updated first, and the Gmail account will be asked to connect again before that new use.
This website
These pages are static. They set no cookies and include no analytics. The host may keep ordinary server logs of requests. The c3 app does not use those logs, and it does not send Gmail data to the host.