AI Email Security: What to Check Before You Connect an Inbox
Every AI email tool says it is secure. These are the questions that separate the ones that mean it, and Clarity's own answers — including the uncomfortable ones.
The seven questions worth asking
- 1Which model provider sees the content, and under what terms? Almost no AI email tool runs its own model. Your email is being sent to somebody else's API, and that vendor's terms — not the email tool's — govern what happens there.
- 2Is email used to train a model? "We don't sell your data" is not an answer to this. Ask specifically whether content is retained for training, by the tool or by its model provider.
- 3What is stored, and is it encrypted at rest? Many tools store full message bodies to make search fast. That is defensible; storing them in plaintext is not.
- 4What can the tool do without asking? Labelling is reversible. Sending is not. A tool that can send on its own initiative is a different risk category from one that can only draft.
- 5Which scopes does it hold? See the consent screen before you decide, not after. Restricted Gmail scopes require Google verification and an annual security assessment.
- 6What happens when you leave? If disconnecting only stops future access and leaves stored copies, you need to know that, and know how to get them deleted.
- 7Are the security claims specific enough to be wrong? "Bank-grade encryption" and "enterprise-ready" cannot be checked. A named cipher, a named assessment and a named model provider can.
What that actually means
- •Security pages are written to reassure rather than to be verified — abstract claims with no cipher, no provider name, no scope list
- •Certification logos often cover a parent company or an unrelated product, not the app you are connecting
- •"We never train on your data" sometimes means the tool doesn't, while the model API behind it might
- •Nothing on the consent screen tells you whether the app can send mail without asking you first
Clarity's answers, in the same order
- 1Model provider: Google's Gemini API. Message content is sent there to be classified and to draft replies. That is the one place your email content leaves Clarity's own infrastructure.
- 2Training: Clarity does not train any model on customer email. There is no training pipeline in the product. The only model-adjacent artefacts are per-user embeddings used solely to search that same user's own mail.
- 3Storage: message bodies, subjects, sender and recipient addresses, contact records, chat messages and stored draft content are encrypted at rest with AES-256-GCM — a 12-byte random IV and a 16-byte authentication tag per value, key held outside the database. Message IDs, thread IDs, label names and timestamps are stored unencrypted.
- 4Autonomy: actions are risk-classified in code. Labelling, archiving, marking read, starring and creating a draft execute automatically. Sending, replying, forwarding, scheduling a send, deleting and marking spam are classified HIGH and go to an approval queue instead of executing.
- 5Scopes: gmail.modify and gmail.settings.basic on Google; Mail.ReadWrite, Mail.Send and MailboxSettings.ReadWrite on Microsoft. Full-mailbox Gmail access is not requested.
- 6Leaving: disconnecting clears the stored tokens and stops the mailbox watch immediately. It does not delete data already stored — that is done by request to support, and you should also remove the app at myaccount.google.com/connections.
- 7Assessment: CASA Tier 2, completed May 2026, which is the review Google requires for restricted Gmail scopes. Clarity holds no SOC 2, ISO 27001 or HIPAA attestation.
- ✓Every claim on this page names a cipher, a provider, a scope or a file — each one can be checked or contradicted
- ✓The send/label split is enforced by a risk table in code, not by a policy promise
- ✓You are told which fields are not encrypted, not just which are
- ✓The exit path and its limits are written down before you connect, not after you ask
Who asks this
Fractional CTO
Vetting tools for three client companies and needs the scope list and model provider in writing before recommending anything.
M&A adviser
Deal correspondence is confidential to the parties. Needs certainty that no message becomes training data anywhere in the chain.
Practice manager
Cannot approve a tool that could email a client unprompted, and needs the auto-versus-approval split spelled out per action.
Frequently asked questions
Does Clarity train AI models on my email?
No. Clarity has no model training pipeline — the AI is Google's Gemini, called per message through its API. Clarity does generate per-user embeddings so you can search your own mail semantically; those vectors belong to your account, are encrypted at rest, and are not pooled across users.
Where does my email content actually go?
Message content travels from Gmail or Microsoft Graph into Clarity's application, is sent to Google's Gemini API for classification and drafting, and the results are stored in Clarity's Postgres database with the sensitive fields encrypted. Those are the three places it exists outside your mailbox.
What encryption does Clarity use at rest?
AES-256-GCM, applied in the application layer before anything reaches the database, so Postgres stores ciphertext. Each value carries its own 12-byte random IV and 16-byte GCM authentication tag, and the key lives in the environment rather than the database.
Can Clarity send an email without me approving it?
Not by default. Send, reply, forward, scheduled send, delete and mark-spam are classified HIGH risk in the action table and are queued for your approval rather than executed. If you deliberately build a workflow and switch its auto-approve on, it will send — that is a choice you make, and you can turn it off.
Is an AI email assistant more or less risky than a Gmail add-on?
The OAuth risk is the same shape — both hold a scoped token to your mailbox. The difference is that an AI assistant sends content to a model provider, which a filter or a labelling add-on does not. That extra hop is the question worth asking, and the answer here is Google's Gemini API.
Reference: Google API Services User Data Policy (Limited Use)
Related guides
Can AI Read My Emails?
Which emails an AI assistant reads, what leaves your mailbox, and what is kept.
Is It Safe to Connect Gmail to a Third-Party App?
What Gmail access a third-party app really gets, which scope to refuse, and what Clarity requests.
How to Revoke an App's Access to Gmail
The real steps to remove Gmail and Outlook app access — and what revoking does not delete.
What it costs you
Roughly 9.1 hours a week
Estimate2.8 hrs of that we could cover
The rest stays yours — it is not repeatable.
106 hrs
a year, if the low end of the range holds
137
threads went quiet and nothing told you
Last 90 days · your own mail · illustrative figures
Clarity Inbox
Get your free inbox report
An interactive report on your last 90 days: where your hours actually went, what is still waiting on you, and how much of your email could run itself. Free, delivered in minutes.
Get my free reportTakes 2 minutes · No credit card · Nothing is sent without you
.png?token=eyJraWQiOiJzdG9yYWdlLXVybC1zaWduaW5nLWtleV80NzQxMTM1Ny0yOWQ5LTRjYjctYTQ2ZS1iMWRhZTM5MGQxNjQiLCJhbGciOiJIUzI1NiJ9.eyJ1cmwiOiJXZWJzaXRlIEFzc2V0cy9jbGFyaXR5LWluYm94LWxvZ28tKGRhcmstaGlyZXMpLnBuZyIsImlhdCI6MTc3MDY2MjMyOSwiZXhwIjo0ODkyNzI2MzI5fQ.l97-jsT-3RFJHPguXJZtFfhnzBNV69xS0XwfvOXYci0)