Minimal access. Maximum control.
Permission inventory
openid, email and profile identify the connected Google account. gmail.readonly allows QuietInbox to read message metadata for classification. No Gmail modification, sending or deletion scope is requested.
Why gmail.readonly is required
QuietInbox needs sender and subject metadata from recent messages to identify intent categories and explain suggestions. Basic Google identity permissions do not provide email metadata, so the read-only Gmail scope is the smallest permission that supports this feature.
Data protection
OAuth credentials are encrypted at rest. User learning records are isolated by account. Message bodies are not stored, and Teach AI records are retained for no more than 180 days.
User controls
Users can disconnect Gmail, revoke Google access and permanently delete all stored QuietInbox data from the Account page.
Incident contact
Security concerns: gleysonp@gmail.com.