Google API disclosure
Google data use
Google identity and Gmail access are separate consents, granted through separate OAuth clients in separate Google Cloud projects. Signing in never grants Asterlo access to Gmail.
Identity sign-in
Sign-in requests only openid, email and profile so Asterlo can verify who you are, restore your session, and enforce which organization you belong to. These are non-sensitive scopes. No mailbox permission is requested, and you can use research, generation and review without ever connecting a mailbox.
Gmail connection, and why each scope is needed
Connecting a mailbox is a separate consent screen that you reach deliberately from Workspace settings → Mailbox. It requests exactly two scopes:
gmail.compose— to create a Gmail Draft containing the exact message version you approved, and to send that approved message. Without it Asterlo cannot put a draft in your mailbox or deliver outreach you have approved. We usegmail.composerather thangmail.modifyorhttps://mail.google.com/because Asterlo never needs to alter, label, archive or delete anything else in your mailbox.gmail.readonly— to observe Asterlo-created drafts, actual sent messages (including Gmail-side edits), related replies and delivery notices. This lets Asterlo distinguish a missing draft from an observed send and hold outreach when a conversation needs review. Correlation uses tracked message identifiers; unrelated bodies are discarded after inspection rather than stored or sent to a model.
Human approval before anything reaches your mailbox
Asterlo cannot create a Draft or send a message that a person has not approved. Approval is recorded against an exact, immutable message version — recipient, subject and body. If that version changes afterwards, the approval no longer applies and delivery is blocked until a human approves the new version in Asterlo. You may edit an exported draft and send it manually in Gmail; Asterlo records the observed text separately from the original approval. An in-thread reply draft requires the same exact approval. Connecting Gmail does not send anything by itself.
Limited Use compliance
Asterlo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only for the user-facing features above; it is not used for advertising, not sold, and not used to train generalized AI or machine-learning models. No human at Asterlo reads your Google user data except with your explicit consent, for security purposes such as investigating abuse, to comply with applicable law, or in aggregated and anonymized form.
Optional analysis and writing preferences
Optional AI classification and content/outcome review send related message excerpts, preceding conversation context, task content and observed metrics to the configured model provider (Anthropic or OpenAI). The tracked Gmail view requests confirmation before these paid actions. Synchronization and manual review do not require a model. Separate legacy reply-worker classification uses the configured provider when that worker is enabled. Suggested writing preferences stay inactive until separately approved for this task or your future drafts. Approved preferences are supplied only within that scope; you can retire them. Gmail-derived information is not reusable training data for generalized or cross-customer models. Providers use commercial API terms, with response storage disabled where supported. Uncertain replies remain on hold for review.
What Asterlo does not do
- It requests exactly two Gmail scopes and no others: it does not request
gmail.send,gmail.modify,gmail.labels,gmail.settings.*orhttps://mail.google.com/. - It does not retain or analyze unrelated mail; synchronization may inspect messages to establish whether they relate to tracked outreach.
- It does not send an email merely because Gmail is connected.
- It does not transfer Google user data for advertising, and does not sell it.
- It does not log OAuth tokens or complete email bodies.
Revoking access and deleting data
Disconnecting Gmail in Workspace settings → Mailbox immediately revokes and erases the stored credential, blocks new Draft operations and pauses future outreach. You can also revoke Asterlo directly from your Google Account permissions. After reconnecting, Asterlo resynchronizes from its saved position before any outreach can resume.
To delete everything, a workspace owner can request deletion in Workspace settings → Data and deletion: a 7-day cancellation window, full purge of workspace content by day 30, and expiry of the minimal deletion audit record 90 days after the purge. See the Privacy policy for the full schedule and contact address.