Minimal access. Maximum control.
Permission inventory
openid, email and profile identify the connected Google account. gmail.readonly allows QuietInbox to read recent message headers and content for classification and user-facing explanations. No Gmail modification, sending or deletion scope is requested.
Why gmail.readonly is required
QuietInbox must analyze both headers and message content to distinguish similar-looking emails, such as a legitimate transaction from a promotion or an urgent account alert from a suspicious request. The narrower Gmail metadata permission excludes message bodies, while basic identity permissions provide no Gmail data. Gmail read-only is therefore the narrowest scope that supports the complete production feature. Content is processed transiently and is not stored.
Data protection
OAuth credentials are encrypted at rest. User learning records are isolated by account. Message bodies are not stored, and Teach AI records are retained for no more than 180 days.
User controls
Users can disconnect Gmail, revoke Google access and permanently delete all stored QuietInbox data from the Account page.
Incident contact
Security concerns: gleysonp@gmail.com.