Built for transparent, minimum-scope Gmail access

Manage your connected Gmail accounts from one secure workspace

A centralized email-management platform that helps authorized company members search, read, organize, compose, and send email from their connected Gmail accounts.

Google Gmail integration is provided through Google’s official OAuth and Gmail API services. Unified E box is an independent product and is not endorsed by, certified by, or affiliated with Google.

What the product does

An operations inbox for mailboxes that are already in use

Members of our company work remotely and use their own personal Gmail accounts. This workspace gives them one place to handle that mail, without asking them to move away from Gmail or share their password with anyone.

One workspace, many mailboxes

Each member connects their own Gmail account. Conversations from every connected mailbox appear in a single, consistently ordered list.

Search across conversations

Full-text search over the subjects, participants, and message bodies that have been synced, so finding a thread does not mean opening Gmail.

Read and unread state

Marking a conversation read in the workspace applies the same change in Gmail, so the two never disagree.

Compose and reply

Replies are composed in the workspace and sent through the Gmail API from the member's own connected account, correctly threaded onto the conversation.

Credentials encrypted at rest

OAuth refresh and access tokens are stored using AES-256-GCM authenticated encryption and are never sent to a browser.

Disconnect at any time

Disconnecting revokes our access token with Google and deletes the stored credentials. Access to the mailbox stops immediately.

How Gmail integration works

Every connection starts and ends with the account holder

We never hold Google credentials. Access exists only because a member granted it through Google's own consent flow, and it ends the moment they withdraw it.

  1. 1

    The member chooses Connect Gmail

    Connection always starts with a deliberate action inside the workspace. Nothing happens in the background.

  2. 2

    Google's official consent screen opens

    The member is redirected to Google. We never ask for a Google password, and we never see one.

  3. 3

    Google presents the requested permissions

    Google, not us, describes what access is being requested and which account it applies to.

  4. 4

    The member approves or denies

    The decision belongs to the account holder. Denying returns them to the workspace with nothing connected.

  5. 5

    We receive an authorization grant

    Google issues tokens for the approved scopes only. They are encrypted before they are stored.

  6. 6

    We use the granted scopes for the described features

    Every Gmail API call we make serves a feature the member can see in the interface.

  7. 7

    The member disconnects whenever they choose

    From the workspace, or from their Google Account permissions page. Both revoke our access.

A member can revoke access at any time from their Google Account permissions page, independently of anything we control.

Permissions we request

Three scopes, each tied to a feature you can see

We request the narrowest set of scopes that makes the product work. Where a broader scope would have been simpler for us, we declined it.

gmail.modifyrestricted

Read messages, threads, and mailbox history, and change the labels applied to them. It does not permit permanently deleting messages or bypassing the trash.

  • Fetch the messages and threads that the unified inbox displays.
  • Run an incremental sync so the inbox reflects the mailbox without re-downloading it.
  • Subscribe to mailbox change notifications so new mail appears without constant polling.
gmail.sendsensitive

Send mail as the connected account. It grants no read access on its own.

  • Send a reply or a new message that the member composes in the application.
  • Thread the reply correctly onto the existing conversation in Gmail.
userinfo.emailsensitive

Read the email address and the stable account identifier of the signed-in Google Account.

  • Identify which mailbox just completed the consent flow, so the resulting credentials are bound to the correct account record.
  • Display the connected address on the Accounts page so a member can tell their mailboxes apart.
  • Prevent the same mailbox from being connected twice.
userinfo.profilenon-sensitive

Read the basic public profile of the signed-in Google Account: name and profile photo.

  • Show each connected mailbox's own profile photo in the mailbox list, so a member can tell their mailboxes apart at a glance.
calendar.eventssensitive

View and edit events on the calendars the signed-in Google Account can access. It does not permit changing calendar settings or sharing.

  • Show the connected account's upcoming events on the Calendar page, beside its mail.
  • Create an event, and invite guests to it, when a member schedules one from the Calendar page.
Read the full scope-by-scope justification

Limited use

What we never do with Gmail data

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not sell Google user data, and we do not transfer it to data brokers or information resellers.
  • We do not use Google user data for advertising of any kind, including retargeting and personalized or interest-based advertising.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not use Gmail message content to train machine learning or AI models, whether ours or a third party's.
  • We do not permanently delete mail from a connected mailbox; the scopes we request do not permit it.
  • We do not read, change, or export a member's Gmail settings, filters, or forwarding rules.
  • We do not allow staff to read message content except in the narrow cases described in our privacy policy.