How Unified E box uses Gmail data

The short version, in plain language. The Gmail integration page covers the same ground in full technical detail.

Last updated September 21, 2026

What we access

When you connect your Gmail account, you grant Unified E box three permissions through Google’s consent screen:

  • Read and organize mail. Read messages, threads, and mailbox history, and change the labels applied to them. It does not permit permanently deleting messages or bypassing the trash.
  • Send mail. Send mail as the connected account. It grants no read access on its own.
  • Read the account's email address. Read the email address and the stable account identifier of the signed-in Google Account.
  • Show the account's profile photo. Read the basic public profile of the signed-in Google Account: name and profile photo.
  • View and create calendar events. View and edit events on the calendars the signed-in Google Account can access. It does not permit changing calendar settings or sharing.

We request nothing else. In particular we do not request permission to permanently delete your mail, to change your Gmail settings, or to read your contacts.

Why we need it

  • To show your conversations in one workspace alongside your other connected mailboxes.
  • To let you search across those conversations.
  • To keep read and unread state consistent between the workspace and Gmail.
  • To open an attachment when you click it.
  • To send a reply you have written, from your own account, threaded onto the right conversation.

What we store

  • Message content. Subject, snippet, plain-text and HTML bodies, sender and recipient addresses, and timestamps for the messages we sync.
  • Thread metadata. Gmail thread and message identifiers, message counts, read state, and the RFC 5322 headers needed to thread replies correctly.
  • Attachment metadata. File name, MIME type, and size. Attachment bytes are not stored; they are fetched from Gmail on demand when a member opens one.
  • OAuth credentials. The refresh token and the current access token, encrypted at rest with AES-256-GCM, plus the granted scopes and expiry time.
  • Account records. The connected Gmail address, Google's stable account identifier, and the connection status.
  • Audit records. Which member connected or disconnected a mailbox, and when.

What we never do

  • We do not sell Google user data, and we do not transfer it to data brokers or information resellers.
  • We do not use Google user data for advertising of any kind, including retargeting and personalized or interest-based advertising.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not use Gmail message content to train machine learning or AI models, whether ours or a third party's.
  • We do not permanently delete mail from a connected mailbox; the scopes we request do not permit it.
  • We do not read, change, or export a member's Gmail settings, filters, or forwarding rules.
  • We do not allow staff to read message content except in the narrow cases described in our privacy policy.

Limited Use

Unified E box’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Staying in control

  • Disconnect a mailbox from the Accounts page at any time. We revoke the token with Google and delete the stored credentials.
  • Or revoke us directly from your Google Account permissions page.
  • Ask us to erase the stored mail as well, through the data deletion process. Disconnecting alone does not erase it.

Nothing you do in Unified E box deletes mail from Gmail. Your mail stays in your Google account.

More detail

The Gmail integration page lists every API method we call and every scope we declined to request. The privacy policy is the complete legal statement. Questions go to privacy@uniebox.vercel.app.