Is AI safe for business email?
The questions worth asking before connecting a mailbox to an AI tool, and how to check the answers yourself rather than taking a vendor at its word.
5 min read

Connecting your mailbox to anything is a real decision. Business email holds contracts, payment details, salary conversations and things clients told you in confidence, and handing that to a tool because its landing page said "secure" is not diligence.
The useful move is to stop asking whether a vendor is trustworthy and start asking what it is technically able to do. Trust is a claim. Permissions are a fact, and you can check them.
Ask what it can do, not what it promises
Every product that connects to Gmail requests a set of OAuth scopes. Those scopes are the actual boundary. A vendor can promise it will never delete your mail, but if it requested full mailbox control, the promise is the only thing standing between you and deletion.
Google shows you the scopes on the consent screen. Most people click through. It is worth reading, because it is the one moment where the marketing and the mechanism have to agree.
The distinction that matters is between what a tool chooses not to do and what it cannot do. Full mailbox control is https://mail.google.com/. If a product requests it, permanent deletion is available to that product forever, including by accident, including by a bug. If it does not, deletion is off the table as a category.
The four questions worth asking any vendor
Which scopes do you request, and why each one? A vendor that cannot answer per scope has not thought about it. Watch for tools that request broad access early "to simplify future features."
Is my mail used to train models? Ask specifically whether that includes the model provider, not just the vendor. Answering for yourself while your upstream provider trains on the data is a common evasion.
What happens on disconnect? Tokens should be revoked and destroyed, not merely marked inactive. Ask what remains after you disconnect, and for how long.
Can it send without me? Any product that can send autonomously can send something wrong to a client autonomously. If there is an autopilot mode, ask what stops it.
What honest answers look like
For CevroFlow the answers are: three Gmail scopes, and a fourth non-Gmail one.
gmail.readonly is what everything runs on, because a message has to be read to be sorted. gmail.send exists only so a reply you reviewed can go out from CevroFlow rather than being copied into Gmail. gmail.modify was added later, by explicit decision, for exactly one purpose: making a star or read marker set in CevroFlow apply to the real Gmail message rather than only to our copy. It is never used to archive, move or relabel.
The fourth is openid, which is not a Gmail scope at all. It returns a stable account identifier used to stop one person opening unlimited free trials. It grants no access to mail.
Worth stating plainly: gmail.modify is broader than what we use it for. The scope itself permits label changes we never make. We are telling you this because the honest version of a permissions disclosure includes the gap between what a scope allows and what the product does with it.
Encryption and training, specifically
Your Google refresh token is encrypted before it reaches the database, not after. Disconnect and it is revoked at Google and destroyed here.
On training: your email is read to produce your results and never used to train a model, ours or our provider's. That guarantee has a cost worth naming. It also means the system does not quietly get better at your particular business by reading more of it. Products that improve by training on your data are making a different trade, and they should say so.
Where AI in email is genuinely riskier
Two places, and neither is usually the one people worry about.
The first is autonomous sending. Reading your mail is a confidentiality question with a clear boundary. Sending on your behalf is different, because a wrong send cannot be recalled and lands in someone else's inbox with your name on it. This is why nothing sends without a human click here, enforced at a single code path rather than as a setting.
The second is confident invention. An AI that fills a gap with a plausible figure is more dangerous than one that leaves the gap visible, because a confident wrong number reads as finished and goes out unchecked. Ask any vendor what their tool does when it does not know something. If the answer is that it always produces a complete draft, that is the answer.
You can read the full permissions breakdown on our security page, and AI Reply shows the review step that stands between a draft and a sent message.
