Ask your AI assistant where you've been β and where you are right now.
Self-hosted MCP servers that turn your Google Maps Timeline and live location into tools for Claude, ChatGPT, or any MCP client.
Google stopped offering Timeline on the web, and your location history now lives only on your phone (plus an encrypted cloud backup). This project pulls that history back out, keeps it on your own server, and lets an LLM answer questions about it β alongside a separate live feed for "where am I right now?".
"Where was I last Tuesday around 3pm?" β
where_was_ifinds the visit or trip covering that moment.
"How much time did I spend at the gym in September?" β
search_places+time_at_placetotals every visit.
"Summarize my week." β
summarize_weekreturns days, top places, distance, and how you got around.
"When was the last time I went to that taco place downtown?" β
visit_historylists every visit, newest first.
"How far did I drive this month vs. walk?" β
distance_traveledbreaks it down by activity.
"Where am I right now, and have I moved since noon?" β
where_am_i+movement_sincefrom the live feed, with data age shown.
flowchart LR
subgraph google["Google"]
TB[(Timeline<br/>cloud backup)]
LS[(Maps Location<br/>Sharing)]
end
subgraph server["Your server (Docker)"]
TS[timeline-sync<br/><sub>Python Β· every 6 h</sub>]
TJ[/Timeline.json/]
TM[timeline-mcp<br/><sub>13 tools</sub>]
LP[live poller<br/><sub>every 60 s</sub>]
LD[(live.sqlite)]
LM[live-location-mcp<br/><sub>5 tools</sub>]
AUTH{{OAuth 2.1}}
end
TB --> TS --> TJ --> TM
LS --> LP --> LD --> LM
TM & LM --- AUTH
AUTH --> C[Claude]
AUTH --> G[ChatGPT]
History and live are deliberately two separate systems. Timeline is Google's semantic reconstruction (visits, trips, activities, Place IDs) and arrives hours late. Live Location Sharing is raw point observations, seconds old. They live in separate databases behind separate MCP servers and are never merged. The model picks the right tool, and every answer says how old its data is.
| πΊοΈ Full Timeline history | Syncs straight from Google's encrypted Timeline backup (no phone export, no Takeout) and follows every backup corpus, so nothing is cut off. |
| π·οΈ Real place names | Resolves Place IDs to names automatically after each sync. |
| π‘ Live location | Polls Google Maps Location Sharing through a dedicated recipient account. The session refreshes itself with cookie rotation and a persistent browser profile. |
| π Hands-off re-auth | When Google revokes the Timeline token, a persistent browser signs back in. The password is sealed by the host's TPM 2.0 (systemd-creds), so a stolen disk or backup can't use it. It stops and asks for a human on any CAPTCHA or unexpected challenge. |
| π Two auth layers | Google credentials never leave the server. MCP clients get only short-lived, audience-bound OAuth 2.1 tokens (RFC 9728 discovery, PKCE, JWKS verification). |
| ποΈ Precision controls | Three levels with a per-server cap on what an LLM may see: semantic (place names only, no coordinates), approximate (~1 km), or exact. |
| π§Ύ Logs that can't leak | Structured logs with automatic redaction of tokens, cookies, keys, and anything that looks like a coordinate. |
| π§ͺ Synthetic by default | Every test and fixture uses invented coordinates. A leak scanner checks the repo for secrets and real locations. |
π³ One docker compose up |
OAuth server, both MCP servers, the poller, the sync scheduler, and noVNC browser views. Ports bind to 127.0.0.1 only. |
| π¬ ChatGPT without exposure | Optional OpenAI Secure MCP Tunnel services: an outbound-only connection, with nothing published to the internet. |
| timeline-mcp (history) | live-location-mcp (now) | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Every tool is read-only and annotated as such. There is no SQL, file access, or bulk-export tool.
Try it with synthetic data. No Google account needed.
git clone --recurse-submodules https://github.com/blakepennel/location-platform.git
cd location-platform
npm install
cd timeline-sync && python -m venv .venv && .venv/bin/pip install -e ".[dev]" && cd ..
cp .env.example .env
npm run seed # invented Timeline + live observations
npm run dev # OAuth :8700 Β· timeline-mcp :8701 Β· live-location-mcp :8702Point an MCP client at http://localhost:8701/mcp or http://localhost:8702/mcp. It discovers
the OAuth server and opens a sign-in page. For Claude Code, the stdio transport skips OAuth
entirely; see DEVELOPMENT.md.
Running it for real (a home server, your own Google data):
docker compose up -d --buildDOCKER.md walks through the one-time Google steps, the noVNC browser logins, TPM setup for automatic re-auth, and connecting Claude and ChatGPT.
location-platform/
βββ timeline-sync/ Python Β· syncs + decrypts the Timeline backup (wraps arkenoi/timeline-export)
βββ timeline-mcp/ TypeScript Β· historical MCP server over its own SQLite index
βββ live-location-mcp/ TypeScript Β· live poller + MCP server
βββ mcp-auth/ OAuth 2.1 resource-server verifier + local dev authorization server
βββ shared/ logging/redaction, time/geo, sqlite, HTTP host
βββ schemas/ export contract + status JSON schemas
βββ tools/ dev runner, e2e harness, seed data, leak scanner, re-auth driver
βββ docker/ container entrypoints (noVNC, sync loop, Google browser)
npm test # 246 Node + ~125 Python tests
npm run test:e2e # full stack: OAuth + both servers + a real MCP client
npm run leak-scan # secrets and real-coordinate scan| ARCHITECTURE.md | Diagrams and data flow |
| DOCKER.md | Deploying on a server |
| DEVELOPMENT.md | Local setup and real Google onboarding |
| AUTH.md | The two authentication layers |
| SECURITY.md Β· THREAT_MODEL.md | What's protected, and from whom |
| Per-project READMEs | timeline-sync Β· timeline-mcp Β· live-location-mcp |
This is a personal project that reads your own data through undocumented Google endpoints: the Timeline cloud backup via arkenoi/timeline-export (a pinned submodule under its own MIT license), and Maps Location Sharing. Google can change or block them at any time, and using them may conflict with Google's Terms of Service. It is not affiliated with or endorsed by Google. Use it only with accounts you own, at your own risk.