Report security issues through GitHub issues if they do not contain secrets. Do not paste OAuth tokens, client secrets, raw GPS exports or private activity payloads.
- Google Health client secret
- OAuth access and refresh tokens
- Raw activity streams
- GPS coordinates, route maps and polylines
- Private activity metadata
- Tokens stay local under
~/.google-health-mcp/tokens.json. - Local config is written with
0600permissions where supported. - The server is read-only by default.
- GPS/map data is redacted unless explicitly requested.