Permissions

Email tracking that does not need to read your email

Connecting Gmail asks for one permission: send mail from your account. Anything more is asked for on its own screen, the moment a feature needs it, and it shows up on Google's own permissions page in Google's own words.

Onmindo asks for permission to send mail on the day you connect, and nothing else. A feature that needs to read a thread, draft a reply, or check your calendar asks for that permission separately, on its own screen, only when you turn the feature on. Every scope it has ever asked for is listed on Google's own permissions page, not just on this one.

What Onmindo asks for on the day you connect

Connecting Gmail is one consent screen covering two scopes: permission to send mail from your account, which Google's own screen describes as "Send email on your behalf," and permission to see the email address of the account you connected. Onmindo's server holds the token those two grant, to send a message you scheduled and to know which mailbox is attached to your account.

That token has no scope for reading a message, a subject line, or a contact. Google's API refuses a read request on it outright; there is no setting inside Onmindo that could make the answer different.

What each feature asks for, and when

Everything past plain sending falls into one of four asks, and a feature never reaches past the one it actually needs.

Feature Asks for When
Open and click tracking Nothing beyond the send permission Always
Templates, signatures, scheduled sends Nothing beyond the send permission Always
Sequences, reply detection, thread summaries, drafted follow-ups Read and draft (gmail.readonly and gmail.compose) When you switch one on
Naming which recipient of a group email opened The full Gmail permission When you switch it on
Booking page Your calendar's free and busy times, and permission to create the one event a booking becomes When you create a page

How to see what any extension can read

Open myaccount.google.com/permissions and pick any app connected to your account. Google lists what it was granted in plain English, not in scope names.

Two phrases are worth knowing. "Send email on your behalf" is what Onmindo asks for on the day you connect, and it means exactly that: send, not read. "Read, compose, send, and permanently delete all your email from Gmail" is the phrase behind the full Gmail permission, the one Onmindo asks for only when you switch on naming who opened a group email. Google offers no scope between the two.

What is stored on Onmindo's side

Onmindo's server stores who a message went to, when it was sent, and which recipient opened it and in which mail client. It does not store the message body, except a send you scheduled, held only until it goes out, and it never stores an IP address. The privacy page lists every table and every column.

Why one feature is the exception

Naming which recipient of a group email opened it needs the full Gmail permission, the one Google's screen describes as "Read, compose, send, and permanently delete all your email from Gmail." Other tools that offer this ask every user for it, on every tier, whether they use the feature or not. Onmindo asks for it once, from the person who turns the feature on, and nobody else's account carries it. Why the feature needs it is the longer answer, built on Gmail's own limits rather than Onmindo's word for it.

Questions

What Gmail access is asked for, answered

The privacy page is the full account of what is stored and why. [email protected] answers anything this page does not.

What permission does Onmindo ask for when I connect Gmail?

Permission to send mail from your account and to read your email address. That token cannot read a message, a subject line or a contact. It is the smallest set Google offers that still lets a message leave from your own account.

When does it ask for more?

At the moment you switch on a feature that needs it, and on a separate consent screen. Sequences, reply detection, thread summaries and drafted follow-ups ask to read and draft mail. Naming which recipient of a group email opened asks for the full Gmail permission, because Gmail's own submission server accepts no narrower one. The booking page asks to read your calendar's free and busy times and to create the one event a booking becomes. Declining any of them leaves the rest working.

How do I see what an extension can read?

Open myaccount.google.com/permissions and pick the app. Google lists every permission in plain words. "Read, compose, send, and permanently delete all your email from Gmail" is the full mailbox; "Send email on your behalf" is what Onmindo asks for on the day you connect.

What does Onmindo store about my mail?

Who a message went to, when, and which of them opened it and in which app. Not the body, except a scheduled send until it goes out, and never an IP address. The privacy page lists every column.

Can I take a permission back?

Yes, on the same Google page, at any time. Onmindo notices on its next request and turns the dependent feature off rather than failing quietly.

Try it

Connect Gmail, and grant nothing else yet

Signup is free and takes a minute. Connect Gmail on the send-only permission, and turn on anything more only when you decide you want it.