The permissions we ask for
Ṣọ reads email, so it has to ask for access to your mailbox. This page lists every permission we request, what each one is actually used for, and how to take it back. Nothing is requested that is not on this page.
Google Workspace and Gmail
| Permission | Access | What it is for |
|---|---|---|
| userinfo.email | Read only | Identifies which account is signed in. We use the address as your account identifier. |
| userinfo.profile | Read only | Your name and profile picture, shown in the app so you can tell accounts apart. |
| gmail.readonly | Read only | Reads the message you are viewing so it can be analysed. This is the scope that does the actual work. |
| gmail.labels | Read and write | Creates and reads the Ṣọ labels used to mark a verdict on a message. |
| gmail.modify | Read and write | Applies those labels to a message. It does not send mail and we never use it to delete anything. |
| calendar / calendar.events | Read and write | Only used if you turn on the feature that converts an email into a calendar event. Not requested otherwise. |
Microsoft 365 and Outlook
| Permission | Access | What it is for |
|---|---|---|
| User.Read | Read only | Your name and address, to identify the signed-in account. |
| Mail.Read | Read only | Reads the message you are viewing so it can be analysed. |
| Mail.ReadWrite | Read and write | Applies Outlook categories to mark a verdict, and saves drafts you write in the app. |
| Mail.Send | Read and write | Only used when you press send on a message you wrote in the app. Ṣọ never sends mail on its own. |
| Calendars.ReadWrite | Read and write | Only used if you turn on the feature that converts an email into a calendar event. |
What we do not ask for
- We do not request permission to delete your mail.
- We do not request access to Drive, OneDrive, Teams or Chat.
- We do not request admin directory access.
- Calendar permissions are only requested if you turn the calendar feature on. If you do not use it, they are never asked for.
How to revoke access
You can remove our access at any time without contacting us, and it takes effect immediately.
- Google: myaccount.google.com/permissions. Workspace admins can revoke for the whole domain in the Admin console under Security, API controls.
- Microsoft: myapps.microsoft.com. Tenant admins can revoke under Enterprise applications.
Because we do not store your email content, revoking access leaves nothing behind on our side to export or delete. See Trust for what we hold and for how long.