Clarity Inbox
Trust

Is It Safe to Connect Gmail to a Third-Party App?

The honest answer is: it depends entirely on which scope you grant, and almost nobody reads that screen. Here is how to read it, and exactly what Clarity asks for.

Read summarized version withChatGPTChatGPTPerplexityPerplexityGeminiGeminiClaudeClaudeGrokGrok

What you are actually agreeing to

  1. 1The consent screen decides everything. Google grants access by OAuth scope, and the scope name — not the app's marketing — is what determines what it can do. Two apps that both say "we help with email" can hold wildly different power.
  2. 2The scope to be wary of is https://mail.google.com/. That is full mailbox access, including permanently deleting messages while bypassing Trash. If an app asks for it and cannot explain why, that is your answer.
  3. 3A step below is gmail.modify: read every message, read attachments, add and remove labels, create and delete drafts, and send mail. It cannot permanently delete a message — deletions can only go to Trash, where you can recover them.
  4. 4Read-only (gmail.readonly) apps cannot label, draft, or send. Anything that files your mail or writes a reply needs write access; an app claiming to do that on read-only scope is describing something else.
  5. 5The access outlives the browser session. A refresh token keeps working after you close the tab, log out, or change devices. It stops when you revoke it, or when Google expires it.
  6. 6Google requires apps using restricted Gmail scopes to pass verification and an annual third-party security assessment (CASA). It is a real bar, but it is a floor, not a guarantee about any specific app's judgement.

What that actually means

  • The consent screen shows plain-English summaries, not scope names, so "read, compose, send and permanently delete" and "read, compose and send" look nearly identical
  • There is no way to grant Gmail access for a date range or a single label — scope applies to the whole mailbox
  • Granting access to one app does not tell you what it stores, where, or for how long
  • Removing an app from your Google account does not delete data it has already copied

What Clarity requests, and what it does not

  1. 1Clarity requests four Google scopes: openid, email, profile, gmail.modify and gmail.settings.basic. That is the complete list on the Gmail connect flow.
  2. 2gmail.modify is a write scope, and we are not going to pretend otherwise. It is what lets Clarity apply the labels (01. TO RESPOND through 08. MARKETING), create drafts in your Drafts folder, and read message bodies and attachments to decide what an email is.
  3. 3gmail.settings.basic is there for two narrow jobs: reading your send-as aliases and signature so a draft comes from the right address, and registering the Gmail push notification that tells Clarity a new message has arrived.
  4. 4Clarity does not request https://mail.google.com/, so permanent deletion is not technically available to it. It does not request Drive, Contacts or Chat scopes at all.
  5. 5Calendar is a separate, second consent screen requesting calendar.readonly. If you never click it, Clarity has no calendar access; connecting Gmail does not include it.
  6. 6On a fresh account the only rules installed are the eight labelling rules. Sending is not switched on by anything you did not configure.
  • The scope list is short and each entry maps to a feature you can see working
  • Permanent deletion is outside the granted scope, so a bug cannot cause it
  • Calendar access is opt-in on its own screen, not bundled into the mailbox grant
  • Google's restricted-scope review applies, and Clarity completed the CASA Tier 2 assessment in May 2026 — that is not SOC 2 or ISO 27001, and Clarity holds neither

Who asks this

Solicitor

Client correspondence is privileged. Needs to know whether an assistant could delete a thread beyond recovery, and can check that the scope granted makes it impossible.

IT-conscious founder

Reviews every OAuth grant on the company domain quarterly and wants the scope list before, not after, the connect.

Bookkeeper

Handles invoices and bank correspondence for a dozen clients and needs the exact answer to "could this thing send mail as me?" — yes, but only through an action queued for approval.

Frequently asked questions

What is the difference between gmail.modify and full mailbox access?

gmail.modify covers read and write operations except immediate permanent deletion — an app holding it can move a message to Trash but cannot destroy it bypassing Trash. Full access is the https://mail.google.com/ scope, which can. Clarity requests gmail.modify and does not request full access.

Can a connected app read emails I received before I connected it?

Yes. Gmail scopes are not time-limited, so any app with read access can search your whole mailbox history. Clarity reads a bounded sample on setup — roughly 300 sent messages to learn your writing style and 200 inbox messages to label — and then works on new mail as it arrives.

Does connecting Gmail give the app my Google password?

No. OAuth never passes your password to the app. Google authenticates you and hands the app a token limited to the scopes you approved, which is why revoking the token is enough to end access without changing your password.

How do I check what I have already granted?

Go to myaccount.google.com/connections. Every app with account access is listed with the specific permissions it holds and a Remove access button. It is worth reading once a year — old apps you stopped using usually still hold live tokens.

Is Clarity SOC 2 certified?

No. Clarity has completed Google's CASA Tier 2 security assessment, which Google requires annually of apps using restricted Gmail scopes, and encrypts email content at rest with AES-256-GCM. It does not hold SOC 2, ISO 27001 or HIPAA attestation, and we would rather say so than imply otherwise.

Reference: Google: third-party apps with access to your account

Related guides

What it costs you

Roughly 9.1 hours a week

Estimate
Writing replies
6.4
Reading & triage
1.1
Follow-up tracking
0.9
Chasing & state
0.7

2.8 hrs of that we could cover

The rest stays yours — it is not repeatable.

106 hrs

a year, if the low end of the range holds

137

threads went quiet and nothing told you

Last 90 days · your own mail · illustrative figures

Clarity Inbox

Get your free inbox report

An interactive report on your last 90 days: where your hours actually went, what is still waiting on you, and how much of your email could run itself. Free, delivered in minutes.

Get my free report

Takes 2 minutes · No credit card · Nothing is sent without you