Security & data processing

Your email is the business.Here's how we treat it.

This page exists for the person whose job is to say no: the founder, the ops lead, the security reviewer. Every claim below is a technical boundary, not a promise.

Permissions

Exactly what we request from Google

Three scopes, and what each one is actually used for. The rest of this table is what we deliberately did not ask for.

gmail.readonlyRequested

What it allows

Read messages and metadata in the connected account

Why

Powers every feature: summaries, categories, priorities, tasks, meeting details, and drafts

gmail.sendRequested

What it allows

Send email as you

Why

Used only when you click Approve & Send on a specific draft, never automatically

gmail.modifyRequested

What it allows

Add and remove labels, including STARRED and UNREAD

Why

Used for one thing: applying a star or read/unread change you make in CevroFlow to the real Gmail message. We never archive, move, or trash mail with it

https://mail.google.com/Not requested

What it allows

Full mailbox control, including permanent deletion

Why

Not requested. Permanently erasing mail is not something CevroFlow can do

CevroFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Practices

Six boundaries, checked before launch.

Sending needs your click

The Gmail scopes we hold cannot permanently erase mail, and cannot send without your explicit approval on each draft. The only write we perform beyond an approved send is a star or read marker. The worst-case failure is a stale summary, never a lost email.

Tokens encrypted at rest

Your Google refresh token is encrypted before it reaches the database and destroyed the moment you disconnect.

Workspace isolation

Every query is scoped to your workspace ID at the data layer. No code path returns another customer's rows.

No model training

Email content generates your results and nothing else. It is never used to train models, ours or our provider's.

Encrypted in transit

All traffic (browser to CevroFlow, CevroFlow to Google, CevroFlow to our AI provider) runs over TLS.

Deletion that means it

Disconnect revokes tokens immediately. Account deletion removes stored email content and AI results with it.

Data lifecycle

The full journey of one email

01

Connect

You approve one consent screen covering both Gmail permissions. Tokens are exchanged server-side and encrypted before storage.

02

Read once

Each message is analyzed in a single AI pass: category, priority, summary, draft. The result is cached; the model never sees the same email twice.

03

Serve

Your dashboard reads the cached results, scoped to your workspace. No repeat processing, no background reuse.

04

Delete

Disconnect and syncing stops with tokens revoked. Delete your account and the stored content goes with it.

Found a vulnerability?

Email security@cevron.in with the details. A person reads it, we respond within two business days, and we credit good-faith reports. We don't take legal action against honest research.

CevroFlow

Stop managing email. Start managing your business.

Connect Gmail and see your first prioritized day in about four minutes.

7-day free trial. No credit card. Connect Gmail in about 4 minutes.