Gog Mail — private account access
Information about David Cole's private, single-user Gmail integration.
Purpose
Gog Mail is a private, single-user integration operated by David Cole for access to Google accounts that he owns. It uses the open-source Gog command-line client on his own computer and Google’s Gmail API. It is not offered as a service, does not accept public registrations, and does not allow other people to connect accounts.
Gmail functions
The integration may perform the Gmail actions that David requests, including:
- searching, listing, and reading messages and threads
- retrieving message source and attachments
- creating and managing drafts
- sending, replying to, and forwarding messages
- managing labels, archive state, read state, and Trash
- reading or managing Gmail settings needed for those mailbox functions
Access is limited to a Google account that David explicitly authorizes through Google’s OAuth consent screen.
Access and storage
The OAuth client secret and refresh token are stored locally in the operating system’s desktop Secret Service. They are not stored by multiplicity.dev, exposed in public files, or supplied to an AI provider.
Gmail data is exchanged directly between Google’s API and the local Gog client. Message content, metadata, attachments, or command output may be retained locally only when David deliberately saves them or when they form part of a task record he has chosen to keep.
Agent-assisted use
David may direct a local coding agent to use Gog for a specific mail task. When he does, the query and the selected Gmail data needed for that task may be transmitted to the AI provider processing the agent session, currently OpenAI’s Codex service. This occurs only at David’s direction and is governed by his provider account settings and the provider’s applicable terms. OAuth credentials are not included.
The integration does not sell Google user data or use it for advertising, marketing, generalized profiling, creditworthiness, or surveillance. It does not make Gmail data available to other users.
Google API Limited Use
Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Revoking access and deleting retained data
David can revoke the app’s access at any time through his Google Account’s third-party connections page. He can also remove the locally stored Gog authorization and any deliberately saved local exports or task records. Revocation stops future API access but does not itself delete files that he intentionally retained elsewhere.
Contact and policies
Questions can be sent to hello@multiplicity.dev. See the privacy notice for the corresponding data-handling disclosure and the site terms for general site terms.