Your email is the business.Here's how we treat it.
This page exists for the person whose job is to say no: the founder, the ops lead, the security reviewer. Every claim below is a technical boundary, not a promise.
Exactly what we request from Google
Two scopes. Everything else on this table is what we deliberately did not ask for.
gmail.readonlyRequestedWhat it allows
Read messages and metadata in the connected account
Why
Powers every feature: summaries, categories, priorities, tasks, meeting details, and drafts
gmail.sendRequestedWhat it allows
Send email as you
Why
Used only when you click Approve & Send on a specific draft, never automatically
gmail.modifyNot requestedWhat it allows
Change labels, archive, or move mail
Why
Not requested. Your inbox stays exactly as you left it
https://mail.google.com/Not requestedWhat it allows
Full mailbox control, including delete
Why
Not requested. Cevron cannot destroy anything
Cevron's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Six boundaries, checked before launch.
Sending needs your click
The Gmail scopes we hold cannot modify or delete mail, and cannot send without your explicit approval on each draft. The worst-case failure is a stale summary, never a lost or unwanted email.
Tokens encrypted at rest
Your Google refresh token is encrypted before it reaches the database and destroyed the moment you disconnect.
Workspace isolation
Every query is scoped to your workspace ID at the data layer. No code path returns another customer's rows.
No model training
Email content generates your results and nothing else. It is never used to train models, ours or our provider's.
Encrypted in transit
All traffic (browser to Cevron, Cevron to Google, Cevron to our AI provider) runs over TLS.
Deletion that means it
Disconnect revokes tokens immediately. Account deletion removes stored email content and AI results with it.
The full journey of one email
Connect
You approve one consent screen covering both Gmail permissions. Tokens are exchanged server-side and encrypted before storage.
Read once
Each message is analyzed in a single AI pass: category, priority, summary, draft. The result is cached; the model never sees the same email twice.
Serve
Your dashboard reads the cached results, scoped to your workspace. No repeat processing, no background reuse.
Delete
Disconnect and syncing stops with tokens revoked. Delete your account and the stored content goes with it.
Found a vulnerability?
Email security@cevron.app with the details. A person reads it, we respond within two business days, and we credit good-faith reports. We don't take legal action against honest research.

Stop managing email. Start managing your business.
Connect Gmail and see your first prioritized day in about four minutes.
7-day free trial. No credit card. Connect Gmail in about 4 minutes.