Asterlo home
Asterlo

Google API disclosure

Google data use

Google identity and Gmail access are separate consents, granted through separate OAuth clients in separate Google Cloud projects. Signing in never grants Asterlo access to Gmail.

Identity sign-in

Sign-in requests only openid, email and profile so Asterlo can verify who you are, restore your session, and enforce which organization you belong to. These are non-sensitive scopes. No mailbox permission is requested, and you can use research, generation and review without ever connecting a mailbox.

Gmail connection, and why each scope is needed

Connecting a mailbox is a separate consent screen that you reach deliberately from Workspace settings → Mailbox. It requests exactly two scopes:

Human approval before anything reaches your mailbox

Asterlo cannot create a Draft or send a message that a person has not approved. Approval is recorded against an exact, immutable message version — recipient, subject and body. If that version changes afterwards, the approval no longer applies and delivery is blocked until a human approves the new version in Asterlo. You may edit an exported draft and send it manually in Gmail; Asterlo records the observed text separately from the original approval. An in-thread reply draft requires the same exact approval. Connecting Gmail does not send anything by itself.

Limited Use compliance

Asterlo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only for the user-facing features above; it is not used for advertising, not sold, and not used to train generalized AI or machine-learning models. No human at Asterlo reads your Google user data except with your explicit consent, for security purposes such as investigating abuse, to comply with applicable law, or in aggregated and anonymized form.

Optional analysis and writing preferences

Optional AI classification and content/outcome review send related message excerpts, preceding conversation context, task content and observed metrics to the configured model provider (Anthropic or OpenAI). The tracked Gmail view requests confirmation before these paid actions. Synchronization and manual review do not require a model. Separate legacy reply-worker classification uses the configured provider when that worker is enabled. Suggested writing preferences stay inactive until separately approved for this task or your future drafts. Approved preferences are supplied only within that scope; you can retire them. Gmail-derived information is not reusable training data for generalized or cross-customer models. Providers use commercial API terms, with response storage disabled where supported. Uncertain replies remain on hold for review.

What Asterlo does not do

Revoking access and deleting data

Disconnecting Gmail in Workspace settings → Mailbox immediately revokes and erases the stored credential, blocks new Draft operations and pauses future outreach. You can also revoke Asterlo directly from your Google Account permissions. After reconnecting, Asterlo resynchronizes from its saved position before any outreach can resume.

To delete everything, a workspace owner can request deletion in Workspace settings → Data and deletion: a 7-day cancellation window, full purge of workspace content by day 30, and expiry of the minimal deletion audit record 90 days after the purge. See the Privacy policy for the full schedule and contact address.

Identity sign-in and mailbox authorization are independent. You can revoke the mailbox without losing your account, and an implemented permission or successful connection does not by itself mean Google has verified the application.