Email access & security

What connecting Gmail actually allows.

Two different Google permissions

Signing in with Google asks only for your name and email address. It does not request any access to your mail, and it does not scan anything.

Connecting a Gmail inbox is a separate, optional step. It asks Google for the gmail.readonly permission. That permission is read-only, and it is broader than receipts alone: it lets an application read any message in the mailbox. We say that plainly because Google's consent screen will, and because you should decide with the whole picture.

What the scan does with it

  • Searches the mailbox for receipts and trial notices within a time window you choose, in bounded batches.
  • Reads the sender, subject, date and the relevant text of matching messages to extract the vendor, dates and price.
  • Lists what it found as suggestions. Nothing is added to your tracker until you open a suggestion, check it and add it.
  • Never sends, modifies, labels or deletes mail. The permission does not allow it, and the code does not try.

What is stored

  • The mailbox address, so the tracker can say which account a trial came from.
  • An encrypted refresh token, so a later scan does not need you to consent again.
  • The extracted details of suggestions (vendor, dates, price, a short snippet) while they await your review, and the details you add.
  • Not stored: message bodies beyond the snippet, attachments, or anything from messages the scan did not match.

Disconnecting

Disconnect from the Inboxes page at any time. That deletes the stored token and asks Google to revoke the grant; if Google does not confirm the revocation, the page tells you so you can finish it under “Third-party apps” in your Google account. Trials you already added stay on your tracker.

Plans

One connected inbox is included free. Connecting a second, different Gmail inbox is part of Tool Tester. Reconnecting an inbox you already connected is never counted as a new one.

Privacy · Help