What you authorize
Recognize your account
openid · email · profileopenid, email and profile identify the account you connect. They do not grant mailbox access.
Read Gmail messages
https://www.googleapis.com/auth/gmail.readonlygmail.readonly reads messages and metadata to classify them, link them to cases and understand requests. Subjects alone are not enough for these features. No sending or editing permission is requested.
Read Microsoft messages
User.Read · Mail.Read · offline_accessUser.Read identifies the account through its profile. Mail.Read reads messages for the same features. offline_access renews the connection without asking you to sign in for every scan. openid, profile and email provide identification.
IMAP connection
An IMAP connection uses the credentials you provide, stored encrypted. Tamdot reads the mailbox without sending, moving or deleting messages. IMAP does not show an OAuth consent screen.
Suggestions and data
When AI features are enabled, limited context may be sent to OpenAI to classify, summarize and prepare a reply. OAuth tokens are never shared. Attachments are not automatically sent to AI. Analyzing a document you select is a separate action.
You review and send
Review suggestions and drafts. Send replies yourself through your email service. External calendars are not synchronized.
Disconnecting is not deletion
In Connections, select a mailbox and Disconnect to stop its synchronization. You can also revoke access in your Google or Microsoft account. This does not delete cases already created in Tamdot.
Export or request deletion
The workspace owner can request an export or deletion review in Settings, Data and privacy. A deletion request immediately stops connections and automations. Final deletion is reviewed, not instant.